Skip to main content

Vendor archive

wpwebinfotech CVEs

Beta · best-effort

9 CVEs tagged to vendor wpwebinfotech0 Critical, 4 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2024-49272

Published Oct 20, 2024

Cross-Site Request Forgery (CSRF) vulnerability in wpweb Social Auto Poster social-auto-poster allows Cross Site Request Forgery.This issue affects Social Auto Poster: from n/a th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47369

Published Oct 5, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweb Social Auto Poster social-auto-poster allows Reflected XSS.This issue a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6756

Published Jul 24, 2024

The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all ver…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6755

Published Jul 24, 2024

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_mult…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6754

Published Jul 24, 2024

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ functio…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6753

Published Jul 24, 2024

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX functio…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6752

Published Jul 24, 2024

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6751

Published Jul 24, 2024

The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing or incorrect nonce validat…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6750

Published Jul 24, 2024

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all ver…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1