Filtered by vendor Tipsandtricks-hq
Subscriptions
Filtered by product Wp Estore
Subscriptions
Total
7 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-6076 | 1 Tipsandtricks-hq | 1 Wp Estore | 2024-11-21 | 6.1 Medium |
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | ||||
CVE-2024-6075 | 1 Tipsandtricks-hq | 1 Wp Estore | 2024-11-21 | 8.8 High |
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | ||||
CVE-2024-6074 | 2 Tipsandtricks-hq, Wp Easycart | 2 Wp Estore, Shopping Cart And Ecommerce Store | 2024-11-21 | 5.4 Medium |
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | ||||
CVE-2024-6073 | 1 Tipsandtricks-hq | 1 Wp Estore | 2024-11-21 | 6.1 Medium |
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | ||||
CVE-2024-6072 | 1 Tipsandtricks-hq | 1 Wp Estore | 2024-11-21 | 6.1 Medium |
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | ||||
CVE-2024-6136 | 1 Tipsandtricks-hq | 1 Wp Estore | 2024-08-13 | 5.4 Medium |
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | ||||
CVE-2024-6133 | 1 Tipsandtricks-hq | 1 Wp Estore | 2024-08-13 | 6.5 Medium |
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin |
Page 1 of 1.