← Back

Wow Company

wow-company

43 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Modal Window
modal_window
Counter Box
counter_box
Wp Coder
wp_coder
Herd Effects
herd_effects
Bubble Menu
bubble_menu
Float Menu
float_menu
Popup Box
popup_box
Viral Signup
viral_signup
Wow Forms
wow_forms
Wpcalc
wpcalc
Wow Countdowns
wow_countdowns
Hover Effects
hover_effects

CVEs (43)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wow Company
1Button Generator
Nov 21, 2024
Jan 10, 2022
N/A· v4
8.8 HIGH· v3
5.1 MEDIUM· v2
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
1Wow Company
1Modal Window
Nov 21, 2024
Jan 10, 2022
N/A· v4
8.8 HIGH· v3
5.1 MEDIUM· v2
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
1Wow Company
1Wow Forms
Nov 21, 2024
Nov 8, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL statement, when deleting a form in the admin dashboard, leading to an authenticated SQL injection