Skip to main content

Vendor archive

welaunch CVEs

Beta · best-effort

5 CVEs tagged to vendor welaunch1 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-11069

Published Nov 19, 2024

The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'WordPress_GDPR_Data_Delete::check_action' function in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10388

Published Nov 19, 2024

The WordPress GDPR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_firstname' and 'gdpr_lastname' parameters in all versions up to, and including,…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28290

Published Apr 25, 2022

Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector p…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0220

Published Feb 1, 2022

The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data wit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24814

Published Feb 1, 2022

The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data wit…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1