|
222761
|
6.1 |
MEDIUM
Network
|
codepeople
|
appointment_booking_calendar
|
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14791
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222762
|
6.1 |
MEDIUM
Network
|
foliovision
|
fv_flowplayer_video_player
|
The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14799
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222763
|
6.5 |
MEDIUM
Network
|
metabox
|
meta_box
|
The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=rwmb_delete_file attachment_id parameter.
|
CWE-862
Missing Authorization
|
CVE-2019-14793
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222764
|
5.4 |
MEDIUM
Network
|
codecabin
|
wp_go_maps
|
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14792
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222765
|
5.4 |
MEDIUM
Network
|
tribulant
|
newsletters
|
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14787
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222766
|
5.4 |
MEDIUM
Network
|
codepeople
|
cp_contact_form_with_paypal
|
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id paramete…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14785
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222767
|
5.5 |
MEDIUM
Local
|
google
|
android
|
On Samsung mobile devices with N(7.x), and O(8.x), P(9.0) software, FotaAgent allows a malicious application to create privileged files. The Samsung ID is SVE-2019-14764.
|
NVD-CWE-noinfo
|
CVE-2019-14783
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222768
|
6.1 |
MEDIUM
Network
|
getwooplugins
|
woo-variation-swatches
|
The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14774
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222769
|
7.5 |
HIGH
Network
|
webcraftic
|
woody_ad_snippets
|
admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion.
|
NVD-CWE-noinfo
|
CVE-2019-14773
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222770
|
5.7 |
MEDIUM
Network
|
codection
|
import_users_from_csv_with_meta
|
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-14683
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|