Stylishpricelist
Stylishpricelist Stylish Price List: vulnerabilidades y CVE
Stylishpricelist Stylish Price List tiene 6 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-66122 | Media (5.3) | 0.38% | — | 16 dic 2025 | Missing Authorization vulnerability in Design Stylish Price List stylish-price-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stylish Price List: from n/a through <=… |
| CVE-2024-7758 | Media (4.8) | 0.31% | — | 15 may 2025 | The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor and above to perform Stored Cross-Site Scripting attacks even… |
| CVE-2024-10472 | Media (5.9) | 0.32% | — | 25 mar 2025 | The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even… |
| CVE-2023-51673 | Crítica (9.8) | 0.25% | — | 5 ene 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Designful Stylish Price List – Price Table Builder & QR Code Restaurant Menu.This issue affects Stylish Price List – Price Table Builder & QR Code Restaurant Menu: from… |
| CVE-2021-24770 | Media (6.5) | 0.85% | — | 1 nov 2021 | The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow any authenticated users, such as… |
| CVE-2021-24757 | Media (5.3) | 1.1% | — | 1 nov 2021 | The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow… |