Vulnerabilities (CVE)

Filtered by vendor Creativethemes Subscribe
Filtered by product Blocksy Companion
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-23898 1 Creativethemes 1 Blocksy Companion 2024-11-21 N/A 5.5 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions.
CVE-2023-1911 1 Creativethemes 1 Blocksy Companion 2024-11-21 N/A 4.3 MEDIUM
The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example