Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 3.2 vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2023-7151
The Product Enquiry for WooCommerce WordPress plugin prior to 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Piwebsolution Product Enquiry For Woocommerce
4.8
CVSSv3
CVE-2023-5911
The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin up to and including 3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability...
Hamidrezasepehr Wp Custom Cursors \\| Wordpress Cursor Plugin
8.8
CVSSv3
CVE-2023-32739
Cross-Site Request Forgery (CSRF) vulnerability in Web_Trendy WP Custom Cursors | WordPress Cursor Plugin plugin < 3.2 versions.
Hamidrezasepehr Custom Cursors
5.4
CVSSv3
CVE-2023-5565
The Shortcode Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortmenu' shortcode in versions up to, and including, 3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...
Shortcode Menu Project Shortcod Menu
8.8
CVSSv3
CVE-2022-45823
Cross-Site Request Forgery (CSRF) vulnerability in GalleryPlugins Video Contest WordPress plugin <= 3.2 versions.
Video Contest Wordpress Project Video Contest Wordpress
4.3
CVSSv3
CVE-2021-4390
The Contact Form 7 Style plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2. This is due to missing or incorrect nonce validation on the manage_wp_posts_be_qe_save_post() function. This makes it possible for unauthenticated mali...
Cf7style Contact Form 7 Style
7.2
CVSSv3
CVE-2023-2221
The WP Custom Cursors WordPress plugin prior to 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.
Wp Custom Cursors Project Wp Custom Cursors
5.4
CVSSv3
CVE-2022-4749
The Posts List Designer by Category WordPress plugin prior to 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which ...
Infornweb Posts List Designer
7.2
CVSSv3
CVE-2022-3150
The WP Custom Cursors WordPress plugin prior to 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin
Wp Custom Cursors Project Wp Custom Cursors
6.1
CVSSv3
CVE-2018-19564
Stored XSS exists in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.
Goldplugins Easy Testimonials 3.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-30310
CVE-2024-21683
CVE-2024-22187
chrome
deserialization
XPath injection
CVE-2024-27842
denial of service
CVE-2024-24851
google
CVE-2024-35400
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »