CVE-2023-3936
- EPSS 0.93%
- Veröffentlicht 21.08.2023 17:15:49
- Zuletzt bearbeitet 23.04.2025 17:16:38
The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2022-3247
- EPSS 0.67%
- Veröffentlicht 25.10.2022 17:15:56
- Zuletzt bearbeitet 09.05.2025 19:15:54
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as ...
CVE-2022-3246
- EPSS 1.06%
- Veröffentlicht 25.10.2022 17:15:56
- Zuletzt bearbeitet 07.05.2025 21:15:56
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscr...
CVE-2021-24956
- EPSS 1.67%
- Veröffentlicht 21.12.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 05:54:04
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
CVE-2021-24137
- EPSS 1.51%
- Veröffentlicht 18.03.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:52:26
Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands.
CVE-2019-17550
- EPSS 1.34%
- Veröffentlicht 13.11.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:32:30
The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the b2s_id parameter. The component is: views/b2s/post.calendar.php. The...
CVE-2019-13572
- EPSS 2.18%
- Veröffentlicht 01.08.2019 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:25:12
The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.
CVE-2019-9576
- EPSS 1.41%
- Veröffentlicht 05.03.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:51:53
The Blog2Social plugin before 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS.