WordPress Popular Posts Project WordPress Popular Posts 1.3 for WordPress

CPE Details

WordPress Popular Posts Project WordPress Popular Posts 1.3 for WordPress
1.3
2021-09-28
15h12 +00:00
2021-09-28
15h29 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:wordpress_popular_posts_project:wordpress_popular_posts:1.3:*:*:*:*:wordpress:*:*

Informations

Vendor

wordpress_popular_posts_project

Product

wordpress_popular_posts

Version

1.3

Target Software

wordpress

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-45607 2023-10-18 13h13 +00:00 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Hector Cabrera WordPress Popular Posts plugin <= 6.3.2 versions.
6.5
Medium
CVE-2022-43468 2022-12-06 23h00 +00:00 External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input.
7.5
High
CVE-2021-42362 2021-11-17 17h44 +00:00 The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.
8.8
High
CVE-2021-36872 2021-09-23 15h00 +00:00 Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type].
5.5
Medium
CVE-2021-20746 2021-06-27 22h50 +00:00 Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
5.4
Medium