Search Results (43 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-10939 1 Stellarwp 1 Image Widget 2025-05-14 4.8 Medium
The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-6203 1 Stellarwp 1 The Events Calendar 2024-11-21 7.5 High
The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request
CVE-2019-15109 1 Stellarwp 1 The Events Calendar 2024-11-21 N/A
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.