Filtered by vendor Wpdeveloper Subscriptions
Filtered by product Embedpress Subscriptions
Total 26 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-5750 1 Wpdeveloper 1 Embedpress 2024-11-21 6.1 Medium
The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2023-5749 1 Wpdeveloper 1 Embedpress 2024-11-21 6.1 Medium
The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2023-51375 1 Wpdeveloper 1 Embedpress 2024-11-21 4.3 Medium
Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3.
CVE-2024-50461 1 Wpdeveloper 1 Embedpress 2024-11-13 6.5 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress: from n/a through 4.0.14.
CVE-2024-43936 1 Wpdeveloper 1 Embedpress 2024-09-03 6.5 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress: from n/a through 4.0.8.
CVE-2024-43328 1 Wpdeveloper 1 Embedpress 2024-08-20 8.3 High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a through 4.0.9.