Skip to main content

Vendor archive

tipsandtricks-hq CVEs

Beta · best-effort

75 CVEs tagged to vendor tipsandtricks-hq4 Critical, 13 High, 58 Medium, 0 Low, 0 Unrated.

CVE-2024-6136

Published Aug 12, 2024

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actio…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6134

Published Aug 12, 2024

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Sc…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6133

Published Aug 12, 2024

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Sc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5081

Published Aug 5, 2024

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5285

Published Jul 29, 2024

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change del…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6076

Published Jul 15, 2024

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Sc…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6075

Published Jul 15, 2024

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6074

Published Jul 15, 2024

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Sc…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6073

Published Jul 15, 2024

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Sc…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6072

Published Jul 15, 2024

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5744

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5715

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which cou…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5287

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5286

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5284

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to ma…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5283

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5282

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5281

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5280

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to ma…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5080

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5079

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Sit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5077

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 75 CVEsPage 1 of 3