Vulnerabilities (CVE)

Filtered by vendor Radiustheme Subscribe
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-3635 1 Radiustheme 1 The Post Grid 2024-10-02 N/A 4.8 MEDIUM
The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-7888 1 Radiustheme 1 Classified Listing - Classified Ads \& Business Directory 2024-09-27 N/A 4.3 MEDIUM
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(), import_forms(), update_fb_options(), and many more in all versions up to, and including, 3.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify forms and various other settings.