Filtered by vendor Wpexperts
Subscribe
Total
49 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-1625 | 1 Wpexperts | 1 New User Approve | 2026-06-17 | 4.3 MEDIUM | 4.3 MEDIUM |
| The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided restrictions) and to change plugin settings by tricking admin users into visiting specially crafted websites. | |||||
| CVE-2022-1589 | 1 Wpexperts | 1 All In One Login | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector | |||||
| CVE-2022-1301 | 1 Wpexperts | 1 Wp Contact Slider | 2026-06-17 | 3.5 LOW | 4.8 MEDIUM |
| The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | |||||
| CVE-2022-1092 | 1 Wpexperts | 1 Mycred | 2026-06-17 | 4.0 MEDIUM | 4.3 MEDIUM |
| The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog | |||||
| CVE-2022-0363 | 1 Wpexperts | 1 Mycred | 2026-06-17 | 4.0 MEDIUM | 4.3 MEDIUM |
| The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating arbitrary posts. | |||||
| CVE-2022-0287 | 1 Wpexperts | 1 Mycred | 2026-06-17 | 4.0 MEDIUM | 4.3 MEDIUM |
| The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog | |||||
| CVE-2021-4422 | 1 Wpexperts | 1 Post Smtp | 2026-06-17 | N/A | 4.3 MEDIUM |
| The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.20. This is due to missing or incorrect nonce validation on the handleCsvExport() function. This makes it possible for unauthenticated attackers to trigger a CSV export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
| CVE-2021-24755 | 1 Wpexperts | 1 Mycred | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user | |||||
| CVE-2019-25150 | 1 Wpexperts | 1 Email Templates | 2026-06-17 | N/A | 8.8 HIGH |
| The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers to present phishing forms or conduct cross-site request forgery attacks against site administrators. | |||||
