Vulnerabilities
Email Encoder Vulnerability – Protect Email Addresses and Phone Numbers – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7070 |WordPress Plugin Vulnerability Report
Plugin Name: Email Encoder – Protect Email Addresses and Phone Numbers Key Information: Software Type: Plugin Software Slug: email-encoder-bundle Software Status: Active Software Author: ironikus Software Downloads: 996,589 Active Installs: 80,000 Last Updated: January 9, 2024 Patched Versions: 2.1.10 Affected Versions: <= 2.1.9 Vulnerability Details: Name: Email Encoder <= 2.1.9 Title: Authenticated (Contributor+) Stored Cross-Site…
Essential Blocks Vulnerability – Page Builder Gutenberg Blocks, Patterns & Templates – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7071 | WordPress Plugin Vulnerability Report
Plugin Name: Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Key Information: Software Type: Plugin Software Slug: essential-blocks Software Status: Active Software Author: wpdevteam Software Downloads: 2,305,018 Active Installs: 100,000 Last Updated: January 9, 2024 Patched Versions: 4.4.7 Affected Versions: <= 4.4.6 Vulnerability Details: Name: Essential Blocks <= 4.4.6 Title: Authenticated (Contributor+) Stored…
Happy Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting |WordPress Plugin Vulnerability Report
Plugin Name: Happy Addons for Elementor Key Information: Software Type: Plugin Software Slug: happy-elementor-addons Software Status: Active Software Author: thehappymonster Software Downloads: 5,771,889 Active Installs: 400,000 Last Updated: January 9, 2024 Patched Versions: 3.10.1 Affected Versions: <= 3.10.0 Vulnerability Details: Name: Happy Elementor Addons <= 3.10.0 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE:…
OneClick Chat to Order Vulnerability – Authenticated Stored Cross-Site Scripting via Shortcode | WordPress Plugin Vulnerability Report
Plugin Name: OneClick Chat to Order Key Information: Software Type: Plugin Software Slug: oneclick-whatsapp-order Software Status: Active Software Author: walterpinem Software Downloads: 205,924 Active Installs: 30,000 Last Updated: January 8, 2024 Patched Versions: 1.0.6 Affected Versions: <= 1.0.5 Vulnerability Details: Name: OneClick Chat to Order <= 1.0.5 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode…
ElementsKit Vulnerability – Unauthenticated Sensitive Information Exposure – CVE-2023-6582 | WordPress Plugin Vulnerability Report
Plugin Name: ElementsKit Elementor addons Key Information: Software Type: Plugin Software Slug: elementskit-lite Software Status: Active Software Author: xpeedstudio Software Downloads: 15,802,981 Active Installs: 1,000,000 Last Updated: January 9, 2024 Patched Versions: 3.0.4 Affected Versions: <= 3.0.3 Vulnerability Details: Name: ElementsKit Lite <= 3.0.3 Title: Unauthenticated Sensitive Information Exposure Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE: CVE-2023-6582 CVSS Score:…
Download Monitor Vulnerability – Authenticated (Admin+) SQL Injection | WordPress Plugin Vulnerability Report
Plugin Name: Download Monitor Key Information: Software Type: Plugin Software Slug: download-monitor Software Status: Active Software Author: wpchill Software Downloads: 4,783,527 Active Installs: 100,000 Last Updated: January 8, 2024 Patched Versions: 4.9.5 Affected Versions: < 4.9.5 Vulnerability Details: Name: Download Monitor <= 4.9.4 Title: Authenticated (Admin+) SQL Injection Type: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE: NA CVSS Score: 7.2…
Formidable Forms Vulnerability – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder – Authenticated (Administrator+) Stored Cross-Site Scripting – CVE-2023-6842 | WordPress Plugin Vulnerability Report
Plugin Name: Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Key Information: Software Type: Plugin Software Slug: formidable Software Status: Active Software Author: sswells Software Downloads: 19,370,348 Active Installs: 300,000 Last Updated: January 8, 2024 Patched Versions: 6.7.1 Affected Versions: <= 6.7 Vulnerability Details: Name: Formidable Forms <= 6.7…
Gallery Plugin for WordPress – Envira Photo Gallery – Missing Authorization to Gallery Modification via envira_gallery_insert_images – CVE-2023-6742 | WordPress Plugin Vulnerability Report
Plugin Name: Gallery Plugin for WordPress – Envira Photo Gallery Key Information: Software Type: Plugin Software Slug: envira-gallery-lite Software Status: Active Software Author: smub Software Downloads: 5,197,570 Active Installs: 100,000 Last Updated: January 8, 2024 Patched Versions: 1.8.7.3 Affected Versions: <= 1.8.7.2 Vulnerability Details: Name: Envira Gallery Lite <= 1.8.7.2 Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVE: CVE-2023-6742 CVSS…