Vulnerabilities (CVE)

Filtered by vendor Private Messages Project Subscribe
Filtered by product Private Messages
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-29442 1 Private Messages Project 1 Private Messages 2024-11-21 3.5 LOW 5.4 MEDIUM
Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress <= 2.1.10 at WordPress.
CVE-2022-29441 1 Private Messages Project 1 Private Messages 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin <= 2.1.10 at WordPress allows attackers to send messages.