Wpdeveloper

Embedpress

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 03.01.2024 07:15:07
  • Zuletzt bearbeitet 21.11.2024 08:44:58

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's embed_oembed_html shortcode in all versio...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 11.12.2023 20:15:07
  • Zuletzt bearbeitet 21.11.2024 08:42:24

The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected Cross-Site Scripting which could be used against high privilege users su...

Exploit
  • EPSS 1.46%
  • Veröffentlicht 11.12.2023 20:15:07
  • Zuletzt bearbeitet 21.11.2024 08:42:24

The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • EPSS 0.09%
  • Veröffentlicht 10.08.2023 12:15:12
  • Zuletzt bearbeitet 21.11.2024 08:34:47

The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. T...

  • EPSS 0.07%
  • Veröffentlicht 10.08.2023 12:15:12
  • Zuletzt bearbeitet 21.11.2024 08:34:47

The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and including, 3.8.2. This makes it possible for authen...

  • EPSS 0.44%
  • Veröffentlicht 27.06.2023 02:15:09
  • Zuletzt bearbeitet 21.11.2024 08:17:07

The User Registration plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including, 3.7.3. This makes it ...