Skip to main content

Vendor/product archive

wpvar / wp_shamsi CVEs

Beta · best-effort

3 CVEs tagged to wpvar / wp_shamsi0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2023-0335

Published Mar 27, 2023

The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-4555

Published Dec 16, 2022

The WP Shamsi plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the deactivate() function hooked via init() in versions up to, and in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38058

Published Sep 9, 2022

Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin <= 4.1.1 at WordPress.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1