CVE-2023-25462
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP htaccess Control plugin <=Â 3.5.1 versions.
Source: CVE-2023-25462
CVE-2023-25462
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP htaccess Control plugin <=Â 3.5.1 versions.
Source: CVE-2023-25462
CVE-2023-32801
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Composite Products plugin <=Â 8.7.5 versions.
Source: CVE-2023-32801
CVE-2023-32802
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <=Â 1.9.0 versions.
Source: CVE-2023-32802
CVE-2023-4600
The AffiliateWP for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ‘affwp_activate_addons_page_plugin’ function called via an AJAX action in versions up to, and including, 2.14.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to activate arbitrary plugins.
Source: CVE-2023-4600
CVE-2023-32962
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in HasTheme WishSuite – Wishlist for WooCommerce plugin <= 1.3.4 versions.
Source: CVE-2023-32962
CVE-2023-32793
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <=Â 2.0.0 versions.
Source: CVE-2023-32793
CVE-2023-32746
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Brands plugin <=Â 1.6.45 versions.
Source: CVE-2023-32746
CVE-2023-32742
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in VeronaLabs WP SMS plugin <=Â 6.1.4 versions.
Source: CVE-2023-32742
CVE-2023-25019
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premio Chaty plugin <=Â 3.0.9 versions
Source: CVE-2023-25019
CVE-2023-32597
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Video Gallery plugin <=Â 1.0.10 versions.
Source: CVE-2023-32597