Web-Settler records
11 published records for vendor web-settler.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-23796No exploit | WordPress Form Builder Plugin <= 1.9.9.0 is vulnerable to CSV Injectionweb-settler · form builder · CWE-1236 | Critical9.8 | — | 0.6% | Nov 7, 2023 |
35Monitor | CVE-2023-23795No exploit | WordPress Form Builder Plugin <= 1.9.9.0 is vulnerable to Cross Site Request Forgery (CSRF)web-settler · form builder · CWE-352 | High8.8 | — | 0.3% | Jun 22, 2023 |
26Monitor | CVE-2023-23671No exploit | WordPress Layer Slider Plugin <= 1.1.9.7 is vulnerable to Cross Site Request Forgery (CSRF)web-settler · layer slider · CWE-352 | Medium6.5 | — | 0.3% | Jul 11, 2023 |
21Monitor | CVE-2021-24513No exploit | Form Builder < 1.9.8.4 - Authenticated Stored Cross-Site Scriptingweb-settler · form builder · CWE-79 | Medium5.4 | — | 0.6% | Sep 6, 2021 |
21Monitor | CVE-2021-36851No exploit | WordPress Testimonial Slider plugin <= 3.5.8.3 - Cross-Site Scripting (XSS) vulnerabilityweb-settler · testimonial slider · CWE-79 | Medium5.4 | — | 0.6% | Apr 4, 2022 |
21Monitor | CVE-2023-5661No exploit | Social Feed <= 1.5.4.6 - Authenticated (Author+) Stored Cross-Site Scripting via Shortcodeweb-settler · social feed · CWE-79 | Medium5.4 | — | 0.5% | Nov 7, 2023 |
21Monitor | CVE-2023-23798No exploit | WordPress Layer Slider Plugin <= 1.1.9.7 is vulnerable to Cross Site Scripting (XSS)web-settler · layer slider · CWE-79 | Medium5.4 | — | 0.4% | Aug 10, 2023 |
19Monitor | CVE-2023-47228No exploit | WordPress Layer Slider Plugin <= 1.1.9.7 is vulnerable to Cross Site Scripting (XSS)web-settler · layer slider · CWE-79 | Medium4.8 | — | 0.4% | Nov 8, 2023 |
19Monitor | CVE-2023-47227No exploit | WordPress Social Feed | All social media in one place Plugin <= 1.5.4.6 is vulnerable to Cross Site Scripting (XSS)web-settler · social feed \| all social media in one place · CWE-79 | Medium4.8 | — | 0.4% | Nov 8, 2023 |
19Monitor | CVE-2023-24412No exploit | WordPress Image Social Feed Plugin Plugin <= 1.7.6 is vulnerable to Cross Site Scripting (XSS)web-settler · image social feed · CWE-79 | Medium4.8 | — | 0.4% | Sep 1, 2023 |
19Monitor | CVE-2022-46861No exploit | WordPress Login Page Styler Plugin <= 6.2 is vulnerable to Cross Site Scripting (XSS)web-settler · custom login page styler · CWE-79 | Medium4.8 | — | 0.4% | May 10, 2023 |
- CVE-2023-2379639Monitor
WordPress Form Builder Plugin <= 1.9.9.0 is vulnerable to CSV Injection
CriticalCVSS 9.8No exploitEPSS 1%web-settler · form builderNov 7, 2023
- CVE-2023-2379535Monitor
WordPress Form Builder Plugin <= 1.9.9.0 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%web-settler · form builderJun 22, 2023
- CVE-2023-2367126Monitor
WordPress Layer Slider Plugin <= 1.1.9.7 is vulnerable to Cross Site Request Forgery (CSRF)
MediumCVSS 6.5No exploitEPSS 0%web-settler · layer sliderJul 11, 2023
- CVE-2021-2451321Monitor
Form Builder < 1.9.8.4 - Authenticated Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%web-settler · form builderSep 6, 2021
- CVE-2021-3685121Monitor
WordPress Testimonial Slider plugin <= 3.5.8.3 - Cross-Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 1%web-settler · testimonial sliderApr 4, 2022
- CVE-2023-566121Monitor
Social Feed <= 1.5.4.6 - Authenticated (Author+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 0%web-settler · social feedNov 7, 2023
- CVE-2023-2379821Monitor
WordPress Layer Slider Plugin <= 1.1.9.7 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%web-settler · layer sliderAug 10, 2023
- CVE-2023-4722819Monitor
WordPress Layer Slider Plugin <= 1.1.9.7 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%web-settler · layer sliderNov 8, 2023
- CVE-2023-4722719Monitor
WordPress Social Feed | All social media in one place Plugin <= 1.5.4.6 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%web-settler · social feed \| all social media in one placeNov 8, 2023
- CVE-2023-2441219Monitor
WordPress Image Social Feed Plugin Plugin <= 1.7.6 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%web-settler · image social feedSep 1, 2023
- CVE-2022-4686119Monitor
WordPress Login Page Styler Plugin <= 6.2 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%web-settler · custom login page stylerMay 10, 2023