CVE-2023-23887
- EPSS 0.15%
- Veröffentlicht 09.12.2024 13:15:21
- Zuletzt bearbeitet 09.12.2024 13:15:21
Missing Authorization vulnerability in Shaon Easy Google Analytics for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Google Analytics for WordPress: from n/a through 1.6.0.
CVE-2023-23893
- EPSS 0.15%
- Veröffentlicht 09.12.2024 13:15:21
- Zuletzt bearbeitet 09.12.2024 13:15:21
Missing Authorization vulnerability in Igor Benic Simple Giveaways allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Giveaways: from n/a through 2.48.0.
CVE-2023-31086
- EPSS 0.1%
- Veröffentlicht 09.11.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:01:23
Cross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways – Grow your business, email lists and traffic with contests plugin <= 2.46.0 versions.
CVE-2023-1122
- EPSS 0.11%
- Veröffentlicht 10.04.2023 14:15:09
- Zuletzt bearbeitet 11.02.2025 16:15:31
The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its Giveaways options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabili...
CVE-2023-1120
- EPSS 0.12%
- Veröffentlicht 10.04.2023 14:15:08
- Zuletzt bearbeitet 11.02.2025 22:15:25
The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis...
CVE-2023-1121
- EPSS 0.11%
- Veröffentlicht 10.04.2023 14:15:08
- Zuletzt bearbeitet 11.02.2025 22:15:25
The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis...
CVE-2021-24298
- EPSS 13.94%
- Veröffentlicht 24.05.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:52:47
The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS