Lucene search

K

HasThemes Security Vulnerabilities

cve
cve

CVE-2024-35699

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes HT Feed allows Stored XSS.This issue affects HT Feed: from n/a through...

6.5CVSS

6.5AI Score

0.0004EPSS

2024-06-08 03:15 PM
20
cve
cve

CVE-2024-34767

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes ShopLentor allows Stored XSS.This issue affects ShopLentor: from n/a through...

6.5CVSS

7AI Score

0.0004EPSS

2024-06-03 12:15 PM
25
cve
cve

CVE-2024-32782

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HasThemes HT Mega.This issue affects HT Mega: from n/a through...

4.3CVSS

6.7AI Score

0.0004EPSS

2024-04-24 08:15 AM
30
cve
cve

CVE-2024-29102

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes Extensions For CF7 allows Stored XSS.This issue affects Extensions For CF7: from n/a through...

7.1CVSS

9.1AI Score

0.0004EPSS

2024-03-19 04:15 PM
32
cve
cve

CVE-2024-29094

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) allows Stored XSS.This issue affects HT Easy GA4 ( Google Analytics 4 ): from n/a through...

7.1CVSS

9.1AI Score

0.0004EPSS

2024-03-19 05:15 PM
34
cve
cve

CVE-2023-37999

Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through...

9.8CVSS

6.9AI Score

0.0004EPSS

2024-05-17 07:15 AM
24
cve
cve

CVE-2024-30182

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega allows Stored XSS.This issue affects HT Mega: from n/a through...

6.5CVSS

9.1AI Score

0.0004EPSS

2024-03-27 12:15 PM
26
cve
cve

CVE-2024-29926

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WC Builder allows Stored XSS.This issue affects WC Builder: from n/a through...

6.5CVSS

7AI Score

0.0004EPSS

2024-03-27 08:15 AM
29
cve
cve

CVE-2023-51529

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Mega – Absolute Addons For Elementor.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through...

4.3CVSS

4.6AI Score

0.0004EPSS

2024-02-29 05:15 AM
67
cve
cve

CVE-2023-51372

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HashBar – WordPress Notification Bar allows Stored XSS.This issue affects HashBar – WordPress Notification Bar: from n/a through...

5.9CVSS

5.4AI Score

0.0004EPSS

2023-12-29 11:15 AM
44
cve
cve

CVE-2023-50901

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega – Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through...

7.1CVSS

6.5AI Score

0.0005EPSS

2023-12-29 11:15 AM
9
cve
cve

CVE-2022-46798

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings...

5.4CVSS

5.5AI Score

0.0005EPSS

2023-03-01 03:15 PM
15
cve
cve

CVE-2023-23899

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Extensions For CF7 plugin <= 2.0.8 versions leads to arbitrary plugin...

4.3CVSS

4.9AI Score

0.0005EPSS

2023-02-17 03:15 PM
19
cve
cve

CVE-2023-23801

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6...

8.8CVSS

8.8AI Score

0.001EPSS

2023-04-06 01:15 PM
19
cve
cve

CVE-2023-1086

The Preview Link Generator WordPress plugin before 1.0.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
21
cve
cve

CVE-2023-0495

The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
23
cve
cve

CVE-2023-1087

The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
19
cve
cve

CVE-2023-0505

The Ever Compare WordPress plugin through 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
20
cve
cve

CVE-2023-0503

The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
25
cve
cve

CVE-2023-0496

The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
20
cve
cve

CVE-2023-0231

The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting...

5.4CVSS

5.3AI Score

0.001EPSS

2023-02-21 09:15 AM
26
cve
cve

CVE-2023-0504

The HT Politic WordPress plugin before 2.3.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
23
cve
cve

CVE-2023-1088

The WP Plugin Manager WordPress plugin before 1.1.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
28
cve
cve

CVE-2023-1089

The Coupon Zen WordPress plugin before 1.0.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
23
cve
cve

CVE-2023-0502

The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

6.5CVSS

6.3AI Score

0.001EPSS

2023-03-27 04:15 PM
28
cve
cve

CVE-2023-0498

The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
23
cve
cve

CVE-2022-4650

The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting...

5.4CVSS

5.3AI Score

0.001EPSS

2023-01-23 03:15 PM
28
cve
cve

CVE-2023-0500

The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

6.5CVSS

6.3AI Score

0.001EPSS

2023-03-27 04:15 PM
28
cve
cve

CVE-2023-0501

The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

6.5CVSS

6.3AI Score

0.001EPSS

2023-03-27 04:15 PM
18
cve
cve

CVE-2023-0497

The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
25
cve
cve

CVE-2023-0499

The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
23
cve
cve

CVE-2023-0484

The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF...

4.3CVSS

4.6AI Score

0.001EPSS

2023-03-27 04:15 PM
25
cve
cve

CVE-2023-0232

The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object...

9.8CVSS

9.4AI Score

0.002EPSS

2023-02-21 09:15 AM
29
cve
cve

CVE-2023-32962

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in HasTheme WishSuite – Wishlist for WooCommerce plugin <= 1.3.4...

5.9CVSS

4.8AI Score

0.0004EPSS

2023-08-30 12:15 PM
11
cve
cve

CVE-2022-47172

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.6.2...

8.8CVSS

8.8AI Score

0.001EPSS

2023-07-17 03:15 PM
19
cve
cve

CVE-2023-23803

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes JustTables plugin <= 1.4.9...

8.8CVSS

8.8AI Score

0.001EPSS

2023-07-11 07:15 AM
11
cve
cve

CVE-2023-23791

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Menu plugin <= 1.2.1...

8.8CVSS

8.8AI Score

0.001EPSS

2023-07-11 07:15 AM
11
cve
cve

CVE-2023-23792

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Swatchly plugin <= 1.2.0...

8.8CVSS

8.7AI Score

0.001EPSS

2023-07-11 06:15 AM
7
cve
cve

CVE-2023-23731

Cross-Site Request Forgery (CSRF) vulnerability in HasTheme WishSuite plugin <= 1.3.3...

8.8CVSS

8.8AI Score

0.001EPSS

2023-07-11 08:15 AM
8
cve
cve

CVE-2023-23804

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Feed plugin <= 1.2.7...

8.8CVSS

8.8AI Score

0.001EPSS

2023-07-10 04:15 PM
10
cve
cve

CVE-2023-23802

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6...

8.8CVSS

8.8AI Score

0.001EPSS

2023-06-15 01:15 PM
16
cve
cve

CVE-2021-24261

The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar...

5.4CVSS

5.2AI Score

0.001EPSS

2021-05-05 07:15 PM
36
cve
cve

CVE-2021-24262

The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar...

5.4CVSS

5.2AI Score

0.001EPSS

2021-05-05 07:15 PM
33