← Back

Tournamatch

tournamatch

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Tournamatch
tournamatch

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tournamatch
1Tournamatch
Jun 17, 2026
May 23, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Tournamatch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trn-ladder-registration-button' shortcode in all versions up to, and including, 4.6.1 due to insufficient input sanitiza...Show more
The Tournamatch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trn-ladder-registration-button' shortcode in all versions up to, and including, 4.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Tournamatch
1Tournamatch
Jun 17, 2026
Jul 13, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltere...Show more
The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Tournamatch
1Tournamatch
Jun 17, 2026
Jul 13, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks.