Vulnerabilities (CVE)

Filtered by vendor Tipsandtricks-hq Subscribe
Filtered by product Wp Estore
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-6076 1 Tipsandtricks-hq 1 Wp Estore 2024-11-21 N/A 6.1 MEDIUM
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-6075 1 Tipsandtricks-hq 1 Wp Estore 2024-11-21 N/A 8.8 HIGH
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
CVE-2024-6074 1 Tipsandtricks-hq 1 Wp Estore 2024-11-21 N/A 6.1 MEDIUM
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-6073 1 Tipsandtricks-hq 1 Wp Estore 2024-11-21 N/A 6.1 MEDIUM
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-6072 1 Tipsandtricks-hq 1 Wp Estore 2024-11-21 N/A 6.1 MEDIUM
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers