CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Stylishpricelist 1Stylish Price List Jun 4, 2025 May 15, 2025 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor and above to perform Stored Cross-Site Scripting attacks even...Show more |
1Stylishpricelist 1Stylish Price List May 15, 2025 Mar 25, 2025 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even whe...Show more |
1Stylishpricelist 1Stylish Price List Apr 28, 2026 Jan 5, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in Designful Stylish Price List – Price Table Builder & QR Code Restaurant Menu.This issue affects Stylish Price List – Price Table Builder & QR Code Restaurant Menu: from...Show more |
1Stylishpricelist 1Stylish Price List Nov 21, 2024 Nov 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow any authenticated users, such as subscri...Show more |
1Stylishpricelist 1Stylish Price List Nov 21, 2024 Nov 1, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated...Show more |