Skip to main content

Vendor archive

tipsandtricks-hq CVEs

Beta · best-effort

75 CVEs tagged to vendor tipsandtricks-hq4 Critical, 13 High, 58 Medium, 0 Low, 0 Unrated.

CVE-2024-5076

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attac…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5075

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which cou…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5074

Published Jul 13, 2024

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which cou…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4749

Published Jun 4, 2024

The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripti…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-47588

Published Nov 3, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Peter Petreski Simple Photo Gallery simple-photo-gallery…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1469

Published Mar 17, 2023

The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pec_coupon[code]’ parameter in versions up to, and including, 2.2.8 due to insuf…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-1431

Published Mar 16, 2023

The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart dat…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-0275

Published Feb 13, 2023

The Easy Accept Payments for PayPal WordPress plugin before 4.9.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4542

Published Jan 23, 2023

The Compact WP Audio Player WordPress plugin before 1.9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4465

Published Jan 16, 2023

The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3898

Published Nov 29, 2022

The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to missing or incorrect nonce valid…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3897

Published Nov 29, 2022

The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 6.3.9 due to insufficient inpu…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3896

Published Nov 29, 2022

The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and including, 6.3.9 due to insuffici…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3822

Published Nov 28, 2022

The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cr…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2189

Published Jul 25, 2022

The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2194

Published Jul 17, 2022

The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scri…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24692

Published Mar 14, 2022

The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24696

Published Jan 24, 2022

The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to explo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 75 CVEsPage 2 of 3