Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress wordpress 1.2.1 vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2023-5177
The Vrm 360 3D Model Viewer WordPress plugin up to and including 1.2.1 exposes the full path of a file when putting in a non-existent file in a parameter of the shortcode.
Maurice Vrm360
NA
CVE-2014-4517
Cross-site scripting (XSS) vulnerability in getNetworkSites.php in the CBI Referral Manager plugin 1.2.1 and previous versions for WordPress allows remote malicious users to inject arbitrary web script or HTML via the searchString parameter.
Cbi Referral Manager Project Cbi Referral Manager
8.8
CVSSv3
CVE-2022-2245
The Counter Box WordPress plugin prior to 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow malicious users to make a logged in admin perform such actions via CSRF attacks
Wow-company Counter Box
6.1
CVSSv3
CVE-2017-9420
Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin prior to 3.3.0 for WordPress allows remote malicious users to inject arbitrary JavaScript via the yr parameter.
Sunnythemes Spiffy Calendar 3.0.8
Sunnythemes Spiffy Calendar 3.0.7
Sunnythemes Spiffy Calendar 3.0.0
Sunnythemes Spiffy Calendar 2.1.3
Sunnythemes Spiffy Calendar 1.2.0
Sunnythemes Spiffy Calendar 1.1.8
Sunnythemes Spiffy Calendar 1.1.2
Sunnythemes Spiffy Calendar 1.1.1
Sunnythemes Spiffy Calendar 3.1.3
Sunnythemes Spiffy Calendar 3.1.2
Sunnythemes Spiffy Calendar 3.0.4
Sunnythemes Spiffy Calendar 3.0.3
Sunnythemes Spiffy Calendar 2.1.0
Sunnythemes Spiffy Calendar 2.0.1
Sunnythemes Spiffy Calendar 1.1.5
Sunnythemes Spiffy Calendar 2.0.0
Sunnythemes Spiffy Calendar 1.0.3
Sunnythemes Spiffy Calendar 1.0.1
Sunnythemes Spiffy Calendar 3.1.1
Sunnythemes Spiffy Calendar 3.1.0
Sunnythemes Spiffy Calendar 3.0.2
Sunnythemes Spiffy Calendar 3.0.1
9.8
CVSSv3
CVE-2015-7670
Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin prior to 1.2.1 for WordPress allow remote malicious users to execute arbitrary SQL commands via the (1) user or (2) id parameter.
Support Ticket System Project Support Ticket System
4.3
CVSSv3
CVE-2022-1760
The Core Control WordPress plugin up to and including 1.2.1 does not have CSRF check in place when updating its settings, which could allow malicious users to make a logged in admin change them via a CSRF attack
Dd32 Core Control
NA
CVE-2024-3756
The MF Gig Calendar WordPress plugin up to and including 1.2.1 does not have CSRF checks in some places, which could allow malicious users to make logged in Contributors and above delete arbitrary events via a CSRF attack
4.8
CVSSv3
CVE-2022-3220
The Advanced Comment Form WordPress plugin prior to 1.2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Webgilde Advanced Comment Form
5.4
CVSSv3
CVE-2023-4460
The Uploading SVG, WEBP and ICO files WordPress plugin up to and including 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
Uploading Svg\\, Webp And Ico Files Project Uploading Svg\\, Webp And Ico Files
6.1
CVSSv3
CVE-2023-2654
The Conditional Menus WordPress plugin prior to 1.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Themify Conditional Menus
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSRF
CVE-2023-52162
CVE-2024-23670
CVE-2024-5404
man-in-the-middle
CVE-2024-5214
CVE-2024-4358
CVE-2024-20696
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »