Cozmoslabs
cozmoslabs
37 CVEs • 7 products
Products (7)
Click to collapseToggle
Products (7)
Click to collapse
CVEs (37)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to ins...Show more |
1Cozmoslabs 1Custom Post Types And Custom Fields Creator Apr 4, 2025 Jan 16, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting...Show more |
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on. |
The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in th...Show more |
The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unf...Show more |
The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallb...Show more |
The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags...Show more |
1Cozmoslabs 1Membership & Content Restriction Paid Member Subscriptions Nov 21, 2024 Sep 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenti...Show more |
1Cozmoslabs 1Profile Builder Nov 21, 2024 Aug 16, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way th...Show more |
1Cozmoslabs 1User Profile Picture Nov 21, 2024 Aug 2, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pictures of other users...Show more |
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in...Show more |
1Cozmoslabs 1User Profile Picture Nov 21, 2024 Apr 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included passwor...Show more |
The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX. |
1Cozmoslabs 1Profile Builder Nov 21, 2024 Aug 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues. |
The profile-builder plugin before 2.2.5 for WordPress has XSS. |
1Cozmoslabs 1Profile Builder Nov 21, 2024 Aug 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms. |
Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site...Show more |