← Back

Mndpsingh287

mndpsingh287

6 CVEs • 3 products

Products (3)

Click to collapse
Toggle

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mndpsingh287
1Newsletter Popup
Jun 17, 2026
May 16, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfil...Show more
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Mndpsingh287
1Newsletter Popup
Jun 17, 2026
May 16, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack
1Mndpsingh287
1Newsletter Popup
Jun 17, 2026
May 16, 2024
N/A· v4
6.9 MEDIUM· v3
N/A· v2
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack
1Mndpsingh287
1Newsletter Popup
Jun 17, 2026
May 16, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins
1Mndpsingh287
1Advanced Search
Jun 17, 2026
Apr 15, 2024
N/A· v4
8.7 HIGH· v3
N/A· v2
The Advanced Search WordPress plugin through 1.1.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
1Mndpsingh287
1File Manager
Jun 17, 2026
Mar 13, 2024
N/A· v4
9.9 CRITICAL· v3
N/A· v2
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_...Show more
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file manager to be embedded via a shortcode and also allows admins to grant file handling privileges to other user levels, which could lead to this vulnerability being exploited by lower-level users.Show less