Vulnerabilities (CVE)

Filtered by vendor Ays-pro Subscribe
Total 84 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10921 1 Ays-pro 1 Photo Gallery 2024-11-21 7.5 HIGH 9.8 CRITICAL
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
CVE-2024-6888 1 Ays-pro 1 Secure Copy Content Protection And Content Locking 2024-10-07 N/A 4.8 MEDIUM
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-6889 1 Ays-pro 1 Secure Copy Content Protection And Content Locking 2024-10-07 N/A 4.8 MEDIUM
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-7714 1 Ays-pro 1 Chatgpt Assistant 2024-10-07 N/A 7.5 HIGH
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'