Filtered by vendor Ays-pro
Subscriptions
Total
58 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-33587 | 1 Ays-pro | 1 Secure Copy Content Protection And Content Locking | 2024-11-21 | 5.3 Medium |
Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 3.9.0. | ||||
CVE-2024-22027 | 1 Ays-pro | 1 Quiz Maker | 2024-11-21 | 6.5 Medium |
Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack against external services. | ||||
CVE-2024-1079 | 1 Ays-pro | 1 Quiz Maker | 2024-11-21 | 5.3 Medium |
The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all versions up to, and including, 6.5.2.4. This makes it possible for unauthenticated attackers to fetch arbitrary quiz results which can contain PII. | ||||
CVE-2024-1078 | 1 Ays-pro | 1 Quiz Maker | 2024-11-21 | 4.3 Medium |
The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions in all versions up to, and including, 6.5.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary quizzes. | ||||
CVE-2023-6591 | 1 Ays-pro | 1 Popup Box | 2024-11-21 | 4.8 Medium |
The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | ||||
CVE-2023-6166 | 1 Ays-pro | 1 Quiz Maker | 2024-11-21 | 6.1 Medium |
The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting | ||||
CVE-2023-6155 | 1 Ays-pro | 1 Quiz Maker | 2024-11-21 | 5.3 Medium |
The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses. | ||||
CVE-2023-5809 | 1 Ays-pro | 1 Popup Box | 2024-11-21 | 4.8 Medium |
The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
CVE-2023-5343 | 1 Ays-pro | 1 Popup Box | 2024-11-21 | 4.8 Medium |
The Popup box WordPress plugin before 3.7.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. | ||||
CVE-2023-4390 | 1 Ays-pro | 1 Popup Box | 2024-11-21 | 4.8 Medium |
The Popup box WordPress plugin before 3.7.2 does not sanitize and escape some Popup fields, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup). | ||||
CVE-2023-47526 | 1 Ays-pro | 1 Chartify | 2024-11-21 | 5.9 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team Chartify – WordPress Chart Plugin allows Stored XSS.This issue affects Chartify – WordPress Chart Plugin: from n/a through 2.0.6. | ||||
CVE-2023-41871 | 1 Ays-pro | 1 Poll Maker | 2024-11-21 | 7.1 High |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Poll Maker Team Poll Maker plugin <= 4.7.0 versions. | ||||
CVE-2023-39917 | 1 Ays-pro | 1 Photo Gallery | 2024-11-21 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.2.6 versions. | ||||
CVE-2023-32498 | 1 Ays-pro | 1 Easy Form | 2024-11-21 | 5.9 Medium |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Easy Form team Easy Form by AYS plugin <= 1.2.0 versions. | ||||
CVE-2023-32107 | 1 Ays-pro | 1 Photo Gallery | 2024-11-21 | 7.1 High |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.1.3 versions. | ||||
CVE-2023-27414 | 1 Ays-pro | 1 Popup Box | 2024-11-21 | 7.1 High |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Popup Box Team Popup box plugin <= 3.4.4 versions. | ||||
CVE-2022-1456 | 1 Ays-pro | 1 Poll Maker | 2024-11-21 | 4.8 Medium |
The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed | ||||
CVE-2022-1013 | 1 Ays-pro | 1 Personal Dictionary | 2024-11-21 | 9.8 Critical |
The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability. | ||||
CVE-2022-0641 | 1 Ays-pro | 1 Popup Like Box | 2024-11-21 | 6.1 Medium |
The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | ||||
CVE-2021-34635 | 1 Ays-pro | 1 Poll Maker | 2024-11-21 | 6.1 Medium |
The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/admin/partials/settings/poll-maker-settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.8. |