Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 1.5.2 vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2021-24765
The Perfect Survey WordPress plugin up to and including 1.5.2 does not validate and escape the X-Forwarded-For header value before outputting it in the statistic page when the Anonymize IP setting of a survey is turned off, leading to a Stored Cross-Site Scripting issue
Getperfectsurvey Perfect Survey
8.8
CVSSv3
CVE-2021-24190
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin prior to 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activat...
Wp-buy Conditional Marketing Mailer
9.8
CVSSv3
CVE-2021-24215
An Improper Access Control vulnerability exists in the Controlled Admin Access WordPress plugin prior to 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a comple...
Wpruby Controlled Admin Access
8.8
CVSSv3
CVE-2020-28649
The orbisius-child-theme-creator plugin prior to 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file.
Orbisius Child Theme Creator
6.1
CVSSv3
CVE-2011-4595
Pretty-Link WordPress plugin 1.5.2 has XSS
Caseproof Pretty Link 1.5.2
1 EDB exploit
6.1
CVSSv3
CVE-2017-18582
The time-sheets plugin prior to 1.5.2 for WordPress has multiple XSS issues.
Time Sheets Project Time Sheets
9.8
CVSSv3
CVE-2018-16613
An issue exists in the update function in the wpForo Forum plugin prior to 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction.
Gvectors Wpforo Forum
6.1
CVSSv3
CVE-2015-4557
Cross-site scripting (XSS) vulnerability in the new_Twitter_sign_button function in nextend-Twitter-connect.php in the Nextend Twitter Connect plugin prior to 1.5.2 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the redirect_to parameter. N...
Nextendweb Nextend Twitter Connect
6.1
CVSSv3
CVE-2017-15867
Multiple cross-site scripting (XSS) vulnerabilities in the user-login-history plugin up to and including 1.5.2 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, (3) user_id, (4) username, (5) country_name, (6) br...
User-login-history Project User-login-history
5.4
CVSSv3
CVE-2017-1002011
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database.
Anblik Image-gallery-with-slideshow 1.5.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »