Skip to main content

Vendor archive

awplife CVEs

Beta · best-effort

22 CVEs tagged to vendor awplife1 Critical, 3 High, 18 Medium, 0 Low, 0 Unrated.

CVE-2024-11396

Published Jan 14, 2025

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5059

Published Jun 21, 2024

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Event Management Tickets Booking.This issue affects Event Management Tickets Booking: from n/…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35722

Published Jun 10, 2024

Missing Authorization vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow.This issue affects Slider Responsive Slideshow – Image slider, Galle…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35721

Published Jun 10, 2024

Missing Authorization vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery.This issue affects Image Gallery – Lightbox Gallery, R…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35720

Published Jun 10, 2024

Missing Authorization vulnerability in A WP Life Album Gallery – WordPress Gallery.This issue affects Album Gallery – WordPress Gallery: from n/a through 1.5.7.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35717

Published Jun 10, 2024

Missing Authorization vulnerability in A WP Life Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow.This issue affects Media Slider – Photo Sleder, Video S…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5638

Published Jun 8, 2024

The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'ti_customizer_notify_dismiss_recommended_plugins' AJAX action in all…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5613

Published Jun 8, 2024

The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'quality_customizer_notify_dismiss_action' AJAX action in all version…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1895

Published Apr 30, 2024

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.9 via de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1401

Published Mar 19, 2024

The Profile Box Shortcode And Widget WordPress plugin before 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perfo…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1859

Published Mar 1, 2024

The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8 via deseri…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1475

Published Feb 29, 2024

The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the REST API. This makes it p…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47525

Published Dec 21, 2023

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Event Monster – Event Management, Tickets Booking, Upcoming Event a…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-5291

Published Oct 4, 2023

The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in versions up to, and including, 1.5.3 due to insufficient input…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-5295

Published Sep 30, 2023

The Comments by Startbit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vivafbcomment' shortcode in versions up to, and including, 1.4 due to insufficient…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-23646

Published Jul 17, 2023

Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-3720

Published Nov 21, 2022

The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3336

Published Nov 21, 2022

The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24709

Published Oct 11, 2021

The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored C…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24683

Published Oct 11, 2021

The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cr…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24529

Published Aug 23, 2021

The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard,…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17072

Published Oct 10, 2019

The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1