Total
3 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-36845 | 1 Yithemes | 1 Yith Maintenance Mode | 2024-11-21 | 3.5 LOW | 6.9 MEDIUM |
|
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.8, there are 46 vulnerable parameters that were missed by the vendor while patching the 1.3.7 version to 1.3.8. Vulnerable parameters: 1 - "Newsletter" tab, &yith_maintenance_newsletter_submit_label parameter: payload should start with a single quote (') symbol to break the context, i.e.: NOTIFY ME' autofocus onfocus=alert(/Visse/);// v=' - this payload will be aut ...
Show More |
|||||
| CVE-2021-36841 | 1 Yithemes | 1 Yith Maintenance Mode | 2024-11-21 | 3.5 LOW | 6.9 MEDIUM |
|
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yith_maintenance_newsletter_submit_label. Possible even when unfiltered HTML is disallowed by WordPress configuration.
|
|||||
| CVE-2015-9429 | 1 Yithemes | 1 Yith Maintenance Mode | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter.
|
|||||