Lucene search

K

YITH Maintenance Mode (WordPress Plugin) Security Vulnerabilities

cve
cve

CVE-2021-36841

Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yith_maintenance_newsletter_submit_label. Possible even when unfiltered HTML is disallowed by WordPress...

6.9CVSS

5.2AI Score

0.001EPSS

2021-09-27 04:15 PM
18
cve
cve

CVE-2021-36845

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.8, there are 46 vulnerable parameters that were missed by the vendor while patching the 1.3.7 version to 1.3.8. Vulnerable parameters: 1 - "Newsletter" tab,...

6.9CVSS

5AI Score

0.001EPSS

2021-09-27 04:15 PM
18
cve
cve

CVE-2015-9429

The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page...

6.5CVSS

6.2AI Score

0.002EPSS

2019-09-26 01:15 AM
116