Filtered by vendor Essentialplugin Subscriptions
Total 12 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-13847 1 Essentialplugin 1 Portfolio And Projects 2025-03-28 4.9 Medium
The Portfolio and Projects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
CVE-2022-4824 1 Essentialplugin 1 Wp Blog And Widget 2025-03-26 5.4 Medium
The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
CVE-2022-4747 1 Essentialplugin 1 Download Post Category Image With Grid And Slider 2025-03-25 5.4 Medium
The Post Category Image With Grid and Slider WordPress plugin before 1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
CVE-2022-4791 1 Essentialplugin 1 Product Slider And Carousel With Category With Woocommerce 2025-03-14 5.4 Medium
The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
CVE-2023-38516 1 Essentialplugin 1 Audio Player With Playlist Ultimate 2025-02-19 6.5 Medium
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Audio Player with Playlist Ultimate plugin <= 1.2.2 versions.
CVE-2022-38077 1 Essentialplugin 1 Popup Anything 2025-01-10 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin <= 2.2.1 versions.
CVE-2022-45818 1 Essentialplugin 1 Hero Banner Ultimate 2025-01-09 6.5 Medium
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner Ultimate plugin <= 1.3.4 versions.
CVE-2023-30488 1 Essentialplugin 1 Featured Post Creative 2024-12-09 5.3 Medium
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7.
CVE-2023-25703 1 Essentialplugin 1 Meta Slider And Carousel With Lightbox 2024-12-09 5.3 Medium
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Meta slider and carousel with lightbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta slider and carousel with lightbox: from n/a through 1.6.2.
CVE-2024-4194 1 Essentialplugin 1 Album And Image Gallery Plus Lightbox 2024-11-21 6.5 Medium
The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
CVE-2022-2115 1 Essentialplugin 1 Popup Anything 2024-11-21 6.1 Medium
The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting
CVE-2021-24883 1 Essentialplugin 1 Popup Anything 2024-11-21 5.4 Medium
The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks