Lucene search

K

Infographic Maker Security Vulnerabilities

cve
cve

CVE-2022-0747

The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

9.8CVSS

9.7AI Score

0.029EPSS

2022-03-21 07:15 PM
67
cve
cve

CVE-2024-5858

The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the qcld_openai_title_generate_desc AJAX action in all versions up to, and including, 4.7.4. This makes it possible for authenticated attackers, with Subscriber-leve...

4.3CVSS

4.5AI Score

0.001EPSS

2024-06-15 09:15 AM
30