← Back

Status301

status301

2 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Easy Fancybox
easy_fancybox
Coolclock
coolclock

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Status301
1Coolclock
Jun 17, 2026
Sep 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks
1Status301
1Easy Fancybox
Jun 17, 2026
Sep 26, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters....Show more
The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.Show less