CVE-2025-22738
- EPSS 0.06%
- Veröffentlicht 15.01.2025 16:15:36
- Zuletzt bearbeitet 03.03.2025 17:42:59
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TechnoWich WP ULike allows Stored XSS.This issue affects WP ULike: from n/a through 4.7.6.
CVE-2024-7879
- EPSS 0.08%
- Veröffentlicht 06.11.2024 06:15:03
- Zuletzt bearbeitet 11.04.2025 15:06:02
The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2024-9649
- EPSS 0.04%
- Veröffentlicht 16.10.2024 02:15:07
- Zuletzt bearbeitet 27.02.2025 18:47:11
The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7.4. This is due to missing or incorrect nonce validation on the wp_ulike_delete_hist...
CVE-2024-6792
- EPSS 0.08%
- Veröffentlicht 06.09.2024 06:15:02
- Zuletzt bearbeitet 11.04.2025 15:12:26
The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public page.
CVE-2024-1797
- EPSS 0.51%
- Veröffentlicht 02.05.2024 17:15:13
- Zuletzt bearbeitet 05.03.2025 15:11:27
The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'status' and 'id' attributes of the 'wp_ulike_counter' and 'wp_ulike' shortcodes in all versions up to, and including, 4.6.9 due to i...
CVE-2024-1759
- EPSS 0.2%
- Veröffentlicht 02.05.2024 17:15:12
- Zuletzt bearbeitet 05.03.2025 15:11:27
The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escapin...
CVE-2024-1572
- EPSS 0.23%
- Veröffentlicht 02.05.2024 17:15:11
- Zuletzt bearbeitet 05.03.2025 15:11:27
The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_ulike' shortcode in all versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping on the user supplied 'wrapper_...