Tipsandtricks Hq
tipsandtricks-hq
75 CVEs • 18 products
Products (18)
Click to collapseToggle
Products (18)
Click to collapse
CVEs (75)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tipsandtricks Hq 1Wp Affiliate Platform Apr 8, 2026 Nov 29, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This...Show more |
1Tipsandtricks Hq 1Wp Affiliate Platform Apr 8, 2026 Nov 29, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escapin...Show more |
1Tipsandtricks Hq 1Donations Via Paypal Apr 25, 2025 Nov 28, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the...Show more |
1Tipsandtricks Hq 1All In One Wp Security & Firewall Apr 28, 2026 Nov 22, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress. |
1Tipsandtricks Hq 1Wp Video Lightbox Nov 21, 2024 Jul 25, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers |
1Tipsandtricks Hq 1Accept Stripe Nov 21, 2024 Jul 17, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_ht...Show more |
1Tipsandtricks Hq 1Wp Simple Adsense Insertion Nov 21, 2024 Jun 8, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via...Show more |
1Tipsandtricks Hq 1All In One Wp Security & Firewall Nov 21, 2024 May 2, 2022 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute,...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Mar 14, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector. |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Jan 24, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerabilit...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Jan 24, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcod...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Nov 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download. |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Nov 8, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, lead...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Nov 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the log...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Nov 21, 2024 Nov 8, 2021 N/A· v4 9.0 CRITICAL· v3 6.0 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cro...Show more |
1Tipsandtricks Hq 1Far Future Expiry Header Nov 21, 2024 Nov 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. |
1Tipsandtricks Hq 1Compact Wp Audio Player Nov 21, 2024 Oct 18, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack. |
1Tipsandtricks Hq 1Compact Wp Audio Player Nov 21, 2024 Oct 18, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. |
1Tipsandtricks Hq 1Software License Manager Nov 21, 2024 Oct 11, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack |
1Tipsandtricks Hq 1Software License Manager Nov 21, 2024 Sep 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting i...Show more |