essentialplugin records
12 published records for vendor essentialplugin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 41.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-862 Missing Authorization3
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-38077No exploit | WordPress Popup Anything Plugin <= 2.2.1 is vulnerable to Cross Site Request Forgery (CSRF)essentialplugin · popup anything · CWE-352 | High8.8 | — | 0.3% | Mar 29, 2023 |
29Monitor | CVE-2024-4194No exploit | Album and Image Gallery plus Lightbox <= 2.0 - Unauthenticated Arbitrary Shortcode Executionessentialplugin · album and image gallery plus lightbox · CWE-94 | High7.3 | — | 0.5% | Jun 5, 2024 |
24Monitor | CVE-2022-2115No exploit | Popup Anything < 2.1.7 - Reflected Cross-Site Scriptingessentialplugin · popup anything · CWE-79 | Medium6.1 | — | 0.7% | Jul 25, 2022 |
21Monitor | CVE-2021-24883No exploit | Popup Anything < 2.0.4 - Contributor+ Stored Cross-Site Scriptingessentialplugin · popup anything · CWE-79 | Medium5.4 | — | 0.8% | Nov 29, 2021 |
21Monitor | CVE-2022-4747No exploit | Post Category Image With Grid and Slider < 1.4.8 - Contributor+ Stored XSS via Shortcodeessentialplugin · download post category image with grid and slider · CWE-79 | Medium5.4 | — | 0.7% | Feb 6, 2023 |
21Monitor | CVE-2022-4824No exploit | WP Blog and Widget < 2.3.1 - Contributor+ Stored XSS via Shortcodeessentialplugin · wp blog and widget · CWE-79 | Medium5.4 | — | 0.6% | Feb 6, 2023 |
21Monitor | CVE-2023-25703No exploit | WordPress Meta slider and carousel with lightbox plugin <= 1.6.2 - Broken Access Control vulnerabilitywp onlinesupport, essential plugin · meta slider and carousel with lightbox · CWE-862 | Medium5.3 | — | 0.5% | Dec 9, 2024 |
21Monitor | CVE-2023-48273No exploit | WordPress Preloader for Website plugin <= 1.2.2 - Unauthenticated Broken Access Control vulnerabilitywp onlinesupport, essential plugin · preloader for website · CWE-862 | Medium5.3 | — | 0.5% | Jun 11, 2024 |
21Monitor | CVE-2022-4791No exploit | Product Slider and Carousel with Category for WooCommerce < 2.8 - Contributor+ Stored XSS via Shortcodeessentialplugin · product slider and carousel with category with woocommerce · CWE-79 | Medium5.4 | — | 0.5% | Feb 21, 2023 |
21Monitor | CVE-2023-30488No exploit | WordPress Featured Post Creative plugin <= 1.2.7 - Broken Access Control vulnerabilitywp onlinesupport, essential plugin · featured post creative · CWE-862 | Medium5.3 | — | 0.4% | Dec 9, 2024 |
21Monitor | CVE-2023-38516No exploit | WordPress Audio Player with Playlist Ultimate Plugin <= 1.2.2 is vulnerable to Cross Site Scripting (XSS)essentialplugin · audio player with playlist ultimate · CWE-79 | Medium5.4 | — | 0.4% | Sep 3, 2023 |
21Monitor | CVE-2022-45818No exploit | WordPress Hero Banner Ultimate Plugin <= 1.3.4 is vulnerable to Cross Site Scripting (XSS)essentialplugin · hero banner ultimate · CWE-79 | Medium5.4 | — | 0.4% | May 4, 2023 |
- CVE-2022-3807735Monitor
WordPress Popup Anything Plugin <= 2.2.1 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%essentialplugin · popup anythingMar 29, 2023
- CVE-2024-419429Monitor
Album and Image Gallery plus Lightbox <= 2.0 - Unauthenticated Arbitrary Shortcode Execution
HighCVSS 7.3No exploitEPSS 0%essentialplugin · album and image gallery plus lightboxJun 5, 2024
- CVE-2022-211524Monitor
Popup Anything < 2.1.7 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%essentialplugin · popup anythingJul 25, 2022
- CVE-2021-2488321Monitor
Popup Anything < 2.0.4 - Contributor+ Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%essentialplugin · popup anythingNov 29, 2021
- CVE-2022-474721Monitor
Post Category Image With Grid and Slider < 1.4.8 - Contributor+ Stored XSS via Shortcode
MediumCVSS 5.4No exploitEPSS 1%essentialplugin · download post category image with grid and sliderFeb 6, 2023
- CVE-2022-482421Monitor
WP Blog and Widget < 2.3.1 - Contributor+ Stored XSS via Shortcode
MediumCVSS 5.4No exploitEPSS 1%essentialplugin · wp blog and widgetFeb 6, 2023
- CVE-2023-2570321Monitor
WordPress Meta slider and carousel with lightbox plugin <= 1.6.2 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 1%wp onlinesupport, essential plugin · meta slider and carousel with lightboxDec 9, 2024
- CVE-2023-4827321Monitor
WordPress Preloader for Website plugin <= 1.2.2 - Unauthenticated Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 1%wp onlinesupport, essential plugin · preloader for websiteJun 11, 2024
- CVE-2022-479121Monitor
Product Slider and Carousel with Category for WooCommerce < 2.8 - Contributor+ Stored XSS via Shortcode
MediumCVSS 5.4No exploitEPSS 0%essentialplugin · product slider and carousel with category with woocommerceFeb 21, 2023
- CVE-2023-3048821Monitor
WordPress Featured Post Creative plugin <= 1.2.7 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%wp onlinesupport, essential plugin · featured post creativeDec 9, 2024
- CVE-2023-3851621Monitor
WordPress Audio Player with Playlist Ultimate Plugin <= 1.2.2 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%essentialplugin · audio player with playlist ultimateSep 3, 2023
- CVE-2022-4581821Monitor
WordPress Hero Banner Ultimate Plugin <= 1.3.4 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%essentialplugin · hero banner ultimateMay 4, 2023