Skip to main content

Vendor/product archive

webcraftic / woody_ad_snippets CVEs

Beta · best-effort

3 CVEs tagged to webcraftic / woody_ad_snippets0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2019-16289

Published Sep 13, 2019

The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15858

Published Sep 3, 2019

admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS paylo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14773

Published Aug 8, 2019

admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1