Skip to main content

Vendor archive

liquidweb CVEs

Beta · best-effort

10 CVEs tagged to vendor liquidweb0 Critical, 3 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2025-14844

Published Jan 16, 2026

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup…

CVSS 8.2 · High
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2024-13457

Published Jan 30, 2025

The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id paramete…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11090

Published Jan 26, 2025

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core s…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1319

Published Mar 4, 2024

The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of stat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1316

Published Mar 4, 2024

The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1053

Published Feb 22, 2024

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47668

Published Nov 23, 2023

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-3182

Published Jul 17, 2023

The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which coul…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-45825

Published Mar 28, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16120

Published Sep 8, 2019

CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1