Ultimatelysocial
ultimatelysocial
6 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ultimatelysocial 1Social Media Share Buttons & Social Sharing Icons Apr 8, 2026 Oct 20, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on...Show more |
1Ultimatelysocial 1Social Media Share Buttons & Social Sharing Icons Apr 8, 2026 Oct 20, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscri...Show more |
1Ultimatelysocial 1Social Media Share Buttons & Social Sharing Icons Nov 21, 2024 Sep 27, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UltimatelySocial Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.3 versions. |
5Backupbliss Copy Delete PostsInisev+2 more10Backup Migration CloneDuplicate Post+7 moreApr 8, 2026 Jul 28, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_...Show more |
6Backupbliss Copy Delete PostsInisev+3 more11Backup Migration CloneDuplicate Post+8 moreApr 8, 2026 Jul 28, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton...Show more |
The USM-Premium WordPress plugin before 16.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered...Show more |