goldplugins records
12 published records for vendor goldplugins.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 8.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2017-9418Proof of concept | SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commandsgoldplugins · testimonials plugin easy testimonials · CWE-89 | High8.8 | — | 2.4% | Jun 12, 2017 |
24Monitor | CVE-2018-19564No exploit | Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress.goldplugins · easy testimonials · CWE-79 | Medium6.1 | — | 0.9% | Nov 26, 2018 |
24Monitor | CVE-2017-12131No exploit | The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonialgoldplugins · easy testimonials · CWE-79 | Medium6.1 | — | 0.8% | Aug 1, 2017 |
24Monitor | CVE-2024-8799No exploit | Custom Banners <= 3.3 - Reflected Cross-Site Scriptinggoldplugins · custom banners · CWE-79 | Medium6.1 | — | 0.3% | Oct 1, 2024 |
21Monitor | CVE-2020-14959No exploit | Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script goldplugins · easy testimonials · CWE-79 | Medium5.4 | — | 0.9% | Jun 21, 2020 |
21Monitor | CVE-2022-4577No exploit | Easy Testimonials < 3.9.3 - Contributor+ Stored XSSgoldplugins · easy testimonials · CWE-79 | Medium5.4 | — | 0.6% | Feb 6, 2023 |
21Monitor | CVE-2023-41797No exploit | WordPress Locations Plugin <= 4.0 is vulnerable to Cross Site Scripting (XSS)goldplugins · locations · CWE-79 | Medium5.4 | — | 0.4% | Oct 2, 2023 |
21Monitor | CVE-2024-2337No exploit | Easy Testimonials <= 3.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodegoldplugins · easy testimonials · CWE-79 | Medium5.4 | — | 0.4% | Jul 19, 2024 |
17Monitor | CVE-2020-36749No exploit | Easy Testimonials <= 3.6.1 - Cross-Site Request Forgery Bypassgoldplugins · easy testimonials · CWE-352 | Medium4.3 | — | 0.5% | Jul 1, 2023 |
17Monitor | CVE-2021-4394No exploit | Locations <= 3.2.1 - Cross-Site Request Forgery Bypassgoldplugins · locations · CWE-352 | Medium4.3 | — | 0.5% | Jul 1, 2023 |
17Monitor | CVE-2021-4397No exploit | Staff Directory Plugin <= 3.6 - Cross-Site Request Forgery Bypassgoldplugins · staff directory plugin · CWE-352 | Medium4.3 | — | 0.4% | Jul 1, 2023 |
17Monitor | CVE-2021-4407No exploit | Custom Banners <= 3.2.2 - Cross-Site Request Forgery Bypassgoldplugins · custom banners · CWE-352 | Medium4.3 | — | 0.4% | Jul 12, 2023 |
- CVE-2017-941836Monitor
SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands
HighCVSS 8.8Proof of conceptEPSS 2%goldplugins · testimonials plugin easy testimonialsJun 12, 2017
- CVE-2018-1956424Monitor
Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress.
MediumCVSS 6.1No exploitEPSS 1%goldplugins · easy testimonialsNov 26, 2018
- CVE-2017-1213124Monitor
The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonial
MediumCVSS 6.1No exploitEPSS 1%goldplugins · easy testimonialsAug 1, 2017
- CVE-2024-879924Monitor
Custom Banners <= 3.3 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%goldplugins · custom bannersOct 1, 2024
- CVE-2020-1495921Monitor
Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script
MediumCVSS 5.4No exploitEPSS 1%goldplugins · easy testimonialsJun 21, 2020
- CVE-2022-457721Monitor
Easy Testimonials < 3.9.3 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%goldplugins · easy testimonialsFeb 6, 2023
- CVE-2023-4179721Monitor
WordPress Locations Plugin <= 4.0 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%goldplugins · locationsOct 2, 2023
- CVE-2024-233721Monitor
Easy Testimonials <= 3.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 0%goldplugins · easy testimonialsJul 19, 2024
- CVE-2020-3674917Monitor
Easy Testimonials <= 3.6.1 - Cross-Site Request Forgery Bypass
MediumCVSS 4.3No exploitEPSS 0%goldplugins · easy testimonialsJul 1, 2023
- CVE-2021-439417Monitor
Locations <= 3.2.1 - Cross-Site Request Forgery Bypass
MediumCVSS 4.3No exploitEPSS 0%goldplugins · locationsJul 1, 2023
- CVE-2021-439717Monitor
Staff Directory Plugin <= 3.6 - Cross-Site Request Forgery Bypass
MediumCVSS 4.3No exploitEPSS 0%goldplugins · staff directory pluginJul 1, 2023
- CVE-2021-440717Monitor
Custom Banners <= 3.2.2 - Cross-Site Request Forgery Bypass
MediumCVSS 4.3No exploitEPSS 0%goldplugins · custom bannersJul 12, 2023