CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a malicious command from the Zingbox cloud, or if the Zingbox Inspector were tampered with to connect to an attacker's cloud endpoint.
The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.
The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.
The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.
