Stylishpricelist

Stylish Price List

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 15.05.2025 20:15:56
  • Zuletzt bearbeitet 04.06.2025 20:09:05

The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capa...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 25.03.2025 06:00:04
  • Zuletzt bearbeitet 15.05.2025 19:24:43

The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabili...

  • EPSS 0.05%
  • Veröffentlicht 05.01.2024 10:15:12
  • Zuletzt bearbeitet 21.11.2024 08:38:34

Cross-Site Request Forgery (CSRF) vulnerability in Designful Stylish Price List – Price Table Builder & QR Code Restaurant Menu.This issue affects Stylish Price List – Price Table Builder & QR Code Restaurant Menu: from n/a through 7.0.17.

Exploit
  • EPSS 0.46%
  • Veröffentlicht 01.11.2021 09:15:09
  • Zuletzt bearbeitet 21.11.2024 05:53:42

The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 01.11.2021 09:15:09
  • Zuletzt bearbeitet 21.11.2024 05:53:43

The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow any authenticated users, such as subscriber, to upload arbitrary image...