← Back

Bestwebsoft

bestwebsoft

75 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Contact Form
contact_form
Captcha
captcha
Gallery
gallery
Htaccess
htaccess
Pagination
pagination
Pdf & Print
pdf_&_print
Portfolio
portfolio
Post To Csv
post_to_csv
Smtp
smtp
User Role
user_role
Car Rental
car_rental
Custom Search
custom_search
Google Maps
google_maps
Job Board
job_board
Linkedin
linkedin
Pinterest
pinterest
Promobar
promobar
Realty
realty
Sender
sender
Subscriber
subscriber
Testimonials
testimonials
Timesheet
timesheet
Updater
updater
Rating
rating
Relevant
relevant
Twitter
twitter
Google Captcha
google_captcha
Donate
donate
Email Queue
email_queue
Featured Posts
featured_posts
Google +1
google_+1
Google Adsense
google_adsense
Google Sitemap
google_sitemap
Latest Posts
latest_posts
Multilanguage
multilanguage
Popular Posts
popular_posts
Profile Extra
profile_extra
Re Attacher
re-attacher
Social Login
social_login
Pluscaptcha
pluscaptcha
Like & Share
like_&_share

CVEs (75)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bestwebsoft
1Gallery
Feb 6, 2025
Apr 17, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges...Show more
The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.Show less
1Bestwebsoft
1Car Rental
Nov 21, 2024
Apr 16, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Car Rental by BestWebSoft plugin <= 1.1.2 versions.
1Bestwebsoft
1Facebook Button
Nov 21, 2024
Apr 10, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected is the function fcbkbttn_settings_page of the file facebook-button-plugin.php. The manipulation lea...Show more
A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected is the function fcbkbttn_settings_page of the file facebook-button-plugin.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.34 is able to address this issue. The patch is identified as b766da8fa100779409a953f0e46c2a2448cbe99c. It is recommended to upgrade the affected component. VDB-225354 is the identifier assigned to this vulnerability.Show less
1Bestwebsoft
1Facebook Button
Nov 21, 2024
Apr 10, 2023
N/A· v4
8.8 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been found in BestWebSoft Facebook Like Button up to 2.13 and classified as problematic. Affected by this vulnerability is the function fcbk_bttn_plgn_settings_page of the file facebook-button-plugin....Show more
A vulnerability has been found in BestWebSoft Facebook Like Button up to 2.13 and classified as problematic. Affected by this vulnerability is the function fcbk_bttn_plgn_settings_page of the file facebook-button-plugin.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The patch is named 33144ae5a45ed07efe7fceca901d91365fdbf7cb. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-225355.Show less
1Bestwebsoft
1Contact Form
Nov 21, 2024
Apr 9, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected by this issue is the function bws_add_menu_render of the file bws_menu/bws_menu.php. The manipulatio...Show more
A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected by this issue is the function bws_add_menu_render of the file bws_menu/bws_menu.php. The manipulation of the argument bwsmn_form_email leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.3.7 is able to address this issue. The name of the patch is 4d531f74b4a801c805dc80360d4ea1312e9a278f. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-225320.Show less
1Bestwebsoft
1Contact Form
Nov 21, 2024
Apr 9, 2023
N/A· v4
8.8 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was found in BestWebSoft Contact Form 3.21. It has been classified as problematic. This affects the function cntctfrm_settings_page of the file contact_form.php. The manipulation leads to cross-site reque...Show more
A vulnerability was found in BestWebSoft Contact Form 3.21. It has been classified as problematic. This affects the function cntctfrm_settings_page of the file contact_form.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.22 is able to address this issue. The identifier of the patch is 8398d96ff0fe45ec9267d7259961c2ef89ed8005. It is recommended to upgrade the affected component. The identifier VDB-225321 was assigned to this vulnerability.Show less
1Bestwebsoft
1Contact Form
Nov 21, 2024
Apr 5, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress. Affected by this issue is the function cntctfrm_display_form/cntctfrm_check_form of the file cont...Show more
A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress. Affected by this issue is the function cntctfrm_display_form/cntctfrm_check_form of the file contact_form.php. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 3.52 is able to address this issue. The patch is identified as 642ef1dc1751ab6642ce981fe126325bb574f898. It is recommended to upgrade the affected component. VDB-225002 is the identifier assigned to this vulnerability.Show less
1Bestwebsoft
1User Role
Feb 14, 2025
Apr 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.
1Bestwebsoft
1Post To Csv
May 7, 2025
Oct 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection
1Bestwebsoft
1Rating
Nov 21, 2024
Jun 20, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service on the post/page when a user submit such rating
1Bestwebsoft
1Contact Form
Nov 21, 2024
Jun 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate t...Show more
A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.0.2 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Bestwebsoft
1Error Log Viewer
Nov 21, 2024
Mar 14, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folde...Show more
The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folderShow less
1Bestwebsoft
1Error Log Viewer
Nov 21, 2024
Feb 1, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary...Show more
The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary text files on the web server.Show less
1Bestwebsoft
1Visitors Online
Nov 21, 2024
Jun 14, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. The plugin would display the user's user agent string without validation or encoding within the...Show more
The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. The plugin would display the user's user agent string without validation or encoding within the WordPress admin panel.Show less
1Bestwebsoft
1Htaccess
Nov 21, 2024
Feb 6, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not valida...Show more
The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.Show less
1Bestwebsoft
1Quotes And Tips
Nov 21, 2024
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The quotes-and-tips plugin before 1.20 for WordPress has XSS.
1Bestwebsoft
1Relevant
Nov 21, 2024
Sep 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The relevant plugin before 1.0.8 for WordPress has XSS.
1Bestwebsoft
1Timesheet
Nov 21, 2024
Aug 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
1Bestwebsoft
1Limit Attempts
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.
1Bestwebsoft
1Contact Form
Nov 21, 2024
Aug 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.