Skip to main content

Vendor archive

ultimatelysocial CVEs

Beta · best-effort

6 CVEs tagged to vendor ultimatelysocial0 Critical, 1 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2023-3977

Published Jul 28, 2023

Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installatio…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-0958

Published Jul 28, 2023

Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-1166

Published Jun 27, 2023

The USM-Premium WordPress plugin before 16.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site S…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1