Accesspressthemes
accesspressthemes
18 CVEs • 109 products
Products (109)
Click to collapseToggle
Products (109)
Click to collapse
CVEs (18)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Accesspressthemes 1Social Auto Poster Nov 21, 2024 Nov 22, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes Social Auto Poster plugin <= 2.1.4 versions. |
Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes WP TFeed plugin <= 1.6.9 versions. |
1Accesspressthemes 1Frontend Post Wordpress Plugin Jan 8, 2025 Jun 5, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/p...Show more |
The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the get_popup_data action. |
1Accesspressthemes 1Smart Logo Showcase Lite Feb 26, 2025 Mar 20, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which c...Show more |
1Accesspressthemes 1Access Demo Importer Nov 21, 2024 Apr 18, 2022 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (posts / pages / media). |
1Accesspressthemes 1Access Demo Importer Nov 21, 2024 Apr 18, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin. |
1Accesspressthemes 1Ap Mega Menu Nov 21, 2024 Mar 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Accesspressthemes 1Ap Custom Testimonial Nov 21, 2024 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting |
1Accesspressthemes 1Ap Custom Testimonial Nov 21, 2024 Feb 28, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection |
1Accesspressthemes 93Accessbuddy Accesspress LiteAccesspress Mag+90 moreNov 21, 2024 Feb 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those ho...Show more |
1Accesspressthemes 1Form Store To Db Nov 21, 2024 Feb 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back in the created entry, allowing unauthenticated attacker to perform Cross-Site Scripting attacks aga...Show more |
1Accesspressthemes 1Wp Cookie User Info Nov 21, 2024 Jan 24, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to...Show more |
1Accesspressthemes 43Access Demo Importer Accesspress LiteAccesspress Mag+40 moreNov 21, 2024 Oct 11, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offlin...Show more |
1Accesspressthemes 1Accesspress Social Icons Nov 21, 2024 Mar 18, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections. |
1Accesspressthemes 1Wp Floating Menu Nov 21, 2024 Sep 14, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Wordpress Plugin Store / AccessPress Themes WP Floating Menu V1.3.0 is affected by: Cross Site Scripting (XSS) via the id GET parameter. |
1Accesspressthemes 1Anonymous Post Pro May 13, 2026 Dec 19, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the settings for allowed file extensions and upload...Show more |
1Accesspressthemes 1Ultimate Form Builder Lite May 13, 2026 Oct 26, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php. |