Filtered by vendor Tipsandtricks-hq Subscriptions
Filtered by product Wp Estore Subscriptions
Total 7 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-6076 1 Tipsandtricks-hq 1 Wp Estore 2024-11-21 6.1 Medium
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-6075 1 Tipsandtricks-hq 1 Wp Estore 2024-11-21 8.8 High
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
CVE-2024-6074 2 Tipsandtricks-hq, Wp Easycart 2 Wp Estore, Shopping Cart And Ecommerce Store 2024-11-21 5.4 Medium
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-6073 1 Tipsandtricks-hq 1 Wp Estore 2024-11-21 6.1 Medium
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-6072 1 Tipsandtricks-hq 1 Wp Estore 2024-11-21 6.1 Medium
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
CVE-2024-6136 1 Tipsandtricks-hq 1 Wp Estore 2024-08-13 5.4 Medium
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
CVE-2024-6133 1 Tipsandtricks-hq 1 Wp Estore 2024-08-13 6.5 Medium
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin