Vulnerabilities (CVE)

Filtered by vendor Wpglobus Subscribe
Filtered by product Wpglobus
Total 7 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-5367 1 Wpglobus 1 Wpglobus 2024-11-21 3.5 LOW 4.8 MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][post] parameter to wp-admin/options.php.
CVE-2018-5366 1 Wpglobus 1 Wpglobus 2024-11-21 3.5 LOW 4.8 MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.php.
CVE-2018-5365 1 Wpglobus 1 Wpglobus 2024-11-21 3.5 LOW 4.8 MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[selector_wp_list_pages][show_selector] parameter to wp-admin/options.php.
CVE-2018-5364 1 Wpglobus 1 Wpglobus 2024-11-21 3.5 LOW 4.8 MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] parameter to wp-admin/options.php.
CVE-2018-5363 1 Wpglobus 1 Wpglobus 2024-11-21 3.5 LOW 4.8 MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enabled_languages][fr] (or any other language) parameter to wp-admin/options.php.
CVE-2018-5362 1 Wpglobus 1 Wpglobus 2024-11-21 3.5 LOW 4.8 MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][page] parameter to wp-admin/options.php.
CVE-2018-5361 1 Wpglobus 1 Wpglobus 2024-11-21 6.8 MEDIUM 8.8 HIGH
The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php.