Tipsandtricks-hq
Tipsandtricks-hq WP Estore: vulnerabilidades y CVE
Tipsandtricks-hq WP Estore tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-6136 | Media (5.4) | 0.23% | — | 12 ago 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks |
| CVE-2024-6134 | Media (5.4) | 0.40% | — | 12 ago 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high… |
| CVE-2024-6133 | Media (6.5) | 0.45% | — | 12 ago 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high… |
| CVE-2024-6076 | Media (6.1) | 0.42% | — | 15 jul 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high… |
| CVE-2024-6075 | Alta (8.8) | 0.37% | — | 15 jul 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks |
| CVE-2024-6074 | Media (6.1) | 0.34% | — | 15 jul 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high… |
| CVE-2024-6073 | Media (6.1) | 0.32% | — | 15 jul 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high… |
| CVE-2024-6072 | Media (6.1) | 0.33% | — | 15 jul 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old… |
Otros productos de Tipsandtricks-hq
WP Affiliate Platform · 11WP Emember · 11ALL IN ONE WP Security & Firewall · 11Simple Download Monitor · 9Wordpress Simple Paypal Shopping Cart · 7Compact WP Audio Player · 6WP Video Lightbox · 4WP Express Checkout · 4Category Specific RSS Feed Subscription · 3Software License Manager · 3Simple Photo Gallery · 1Donations VIA Paypal · 1