Skip to main content

Vendor/product archive

wow-company / wp_coder CVEs

Beta · best-effort

5 CVEs tagged to wow-company / wp_coder0 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-2578

Published Mar 21, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder allows Stored XSS.This issue affects WP Coder: from n/a thro…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2362

Published Jun 12, 2023

The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-0895

Published Feb 17, 2023

The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in versions up to, and including, 2.5.3 due t…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-2388

Published Aug 22, 2022

The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25053

Published Jan 10, 2022

The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protoco…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1