« Back to list

Wpleadplus

Wpleadplus WP Lead Plus X: vulnerabilities and CVEs

Wpleadplus WP Lead Plus X has 3 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs3
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-36839High (8.3)0.27%—Oct 16, 2024
The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.99. This is due to missing or incorrect nonce validation on several functions. This makes it…
CVE-2020-11509Medium (6.1)1.9%—Apr 7, 2020
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import_template admin-post action (which will…
CVE-2020-11508Medium (5.4)0.78%—Apr 7, 2020
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbitrary JavaScript via…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1185 Browser Session Hijacking1
  2. T1203 Exploitation for Client Execution1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.