CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Accesspressthemes 93Accessbuddy Accesspress LiteAccesspress Mag+90 moreNov 21, 2024 Feb 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those ho...Show more |
1Accesspressthemes 1Accesspress Social Icons Nov 21, 2024 Mar 18, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections. |