Skip to content
Noroxi

essentialplugin records

12 published records for vendor essentialplugin.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
41.7%
Median publish → KEV
No record has entered KEV

All records

12 records
  • WordPress Popup Anything Plugin <= 2.2.1 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    essentialplugin · popup anythingMar 29, 2023

  • CVE-2024-4194
    29Monitor

    Album and Image Gallery plus Lightbox <= 2.0 - Unauthenticated Arbitrary Shortcode Execution

    HighCVSS 7.3No exploitEPSS 0%

    essentialplugin · album and image gallery plus lightboxJun 5, 2024

  • CVE-2022-2115
    24Monitor

    Popup Anything < 2.1.7 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    essentialplugin · popup anythingJul 25, 2022

  • Popup Anything < 2.0.4 - Contributor+ Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 1%

    essentialplugin · popup anythingNov 29, 2021

  • CVE-2022-4747
    21Monitor

    Post Category Image With Grid and Slider < 1.4.8 - Contributor+ Stored XSS via Shortcode

    MediumCVSS 5.4No exploitEPSS 1%

    essentialplugin · download post category image with grid and sliderFeb 6, 2023

  • CVE-2022-4824
    21Monitor

    WP Blog and Widget < 2.3.1 - Contributor+ Stored XSS via Shortcode

    MediumCVSS 5.4No exploitEPSS 1%

    essentialplugin · wp blog and widgetFeb 6, 2023

  • WordPress Meta slider and carousel with lightbox plugin <= 1.6.2 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 1%

    wp onlinesupport, essential plugin · meta slider and carousel with lightboxDec 9, 2024

  • WordPress Preloader for Website plugin <= 1.2.2 - Unauthenticated Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 1%

    wp onlinesupport, essential plugin · preloader for websiteJun 11, 2024

  • CVE-2022-4791
    21Monitor

    Product Slider and Carousel with Category for WooCommerce < 2.8 - Contributor+ Stored XSS via Shortcode

    MediumCVSS 5.4No exploitEPSS 0%

    essentialplugin · product slider and carousel with category with woocommerceFeb 21, 2023

  • WordPress Featured Post Creative plugin <= 1.2.7 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    wp onlinesupport, essential plugin · featured post creativeDec 9, 2024

  • WordPress Audio Player with Playlist Ultimate Plugin <= 1.2.2 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    essentialplugin · audio player with playlist ultimateSep 3, 2023

  • WordPress Hero Banner Ultimate Plugin <= 1.3.4 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    essentialplugin · hero banner ultimateMay 4, 2023