Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.5
CVE-2026-66456
- EPSS 0.21%
- Veröffentlicht 13.08.2026 13:36:59
- Zuletzt bearbeitet 14.08.2026 19:09:20
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
5.3
CVE-2023-4469
- EPSS 0.47%
- Veröffentlicht 06.10.2023 10:15:18
- Zuletzt bearbeitet 08.04.2026 18:18:14
The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function in versions up to, and including, 1.2.7. This makes it possible for un...
1