← Back

Webfactoryltd

webfactoryltd

27 CVEs • 14 products

Products (14)

Click to collapse
Toggle

CVEs (27)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webfactoryltd
1301 Redirects
Nov 21, 2024
Mar 18, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL i...Show more
Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.Show less
1Webfactoryltd
1Wp Database Reset
Nov 21, 2024
Jan 16, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in tha...Show more
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a wp-admin/admin-post.php?db-reset-tables[]=comments URI.Show less
1Webfactoryltd
1Wp Database Reset
Nov 21, 2024
Jan 16, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate...Show more
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate their privileges to administrator while dropping all other users from the table.Show less
1Webfactoryltd
1Minimal Coming Soon & Maintenance Mode
Nov 21, 2024
Jan 9, 2020
N/A· v4
7.6 HIGH· v3
6.5 MEDIUM· v2
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidenti...Show more
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).Show less
1Webfactoryltd
1Minimal Coming Soon & Maintenance Mode
Nov 21, 2024
Jan 9, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
1Webfactoryltd
1Minimal Coming Soon & Maintenance Mode
Nov 21, 2024
Jan 9, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.
1Webfactoryltd
1301 Redirects
Nov 21, 2024
Dec 19, 2019
N/A· v4
9.0 CRITICAL· v3
6.0 MEDIUM· v2
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=...Show more
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in a loss of site availability, malicious redirects, and user infections. This could also be exploited via CSRF.Show less