Skip to content
Noroxi

goldplugins records

12 published records for vendor goldplugins.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
8.3%
Median publish → KEV
No record has entered KEV

All records

12 records
  • CVE-2017-9418
    36Monitor

    SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands

    HighCVSS 8.8Proof of conceptEPSS 2%

    goldplugins · testimonials plugin easy testimonialsJun 12, 2017

  • Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress.

    MediumCVSS 6.1No exploitEPSS 1%

    goldplugins · easy testimonialsNov 26, 2018

  • The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonial

    MediumCVSS 6.1No exploitEPSS 1%

    goldplugins · easy testimonialsAug 1, 2017

  • CVE-2024-8799
    24Monitor

    Custom Banners <= 3.3 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    goldplugins · custom bannersOct 1, 2024

  • Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script

    MediumCVSS 5.4No exploitEPSS 1%

    goldplugins · easy testimonialsJun 21, 2020

  • CVE-2022-4577
    21Monitor

    Easy Testimonials < 3.9.3 - Contributor+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    goldplugins · easy testimonialsFeb 6, 2023

  • WordPress Locations Plugin <= 4.0 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    goldplugins · locationsOct 2, 2023

  • CVE-2024-2337
    21Monitor

    Easy Testimonials <= 3.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    MediumCVSS 5.4No exploitEPSS 0%

    goldplugins · easy testimonialsJul 19, 2024

  • Easy Testimonials <= 3.6.1 - Cross-Site Request Forgery Bypass

    MediumCVSS 4.3No exploitEPSS 0%

    goldplugins · easy testimonialsJul 1, 2023

  • CVE-2021-4394
    17Monitor

    Locations <= 3.2.1 - Cross-Site Request Forgery Bypass

    MediumCVSS 4.3No exploitEPSS 0%

    goldplugins · locationsJul 1, 2023

  • CVE-2021-4397
    17Monitor

    Staff Directory Plugin <= 3.6 - Cross-Site Request Forgery Bypass

    MediumCVSS 4.3No exploitEPSS 0%

    goldplugins · staff directory pluginJul 1, 2023

  • CVE-2021-4407
    17Monitor

    Custom Banners <= 3.2.2 - Cross-Site Request Forgery Bypass

    MediumCVSS 4.3No exploitEPSS 0%

    goldplugins · custom bannersJul 12, 2023