Tipsandtricks-hqCVEs & Vulnerabilities

75 CVEs affecting Tipsandtricks-hq products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

wordpress simple paypal shopping cart 31wp affiliate platform 11all in one wp security \& firewall 10wp emember 10simple download monitor 9wp estore 8category specific rss feed subscription 3compact wp audio player 3
CVE-2021-24692MEDIUM

The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.

14 Mar 2022
6.5
CVSS
CVE-2021-24696HIGH

The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads

24 Jan 2022
8.8
CVSS
CVE-2021-24694MEDIUM

The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode.

24 Jan 2022
5.4
CVSS
CVE-2021-24698MEDIUM

The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.

8 Nov 2021
4.3
CVSS
CVE-2021-24697MEDIUM

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

8 Nov 2021
6.1
CVSS
CVE-2021-24695HIGH

The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames

8 Nov 2021
7.5
CVSS
CVE-2021-24693CRITICAL

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review state, contributor could make JavaScript code execute in a context of a reviewer such as admin and make them create a rogue admin account, or install a malicious plugin

8 Nov 2021
9.0
CVSS
CVE-2021-24799MEDIUM

The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

1 Nov 2021
4.3
CVSS
CVE-2021-24735MEDIUM

The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack.

18 Oct 2021
6.5
CVSS
CVE-2021-24734MEDIUM

The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

18 Oct 2021
5.4
CVSS
CVE-2021-24711HIGH

The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack

11 Oct 2021
8.8
CVSS
CVE-2021-24560MEDIUM

The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

13 Sep 2021
6.1
CVSS
CVE-2021-24665MEDIUM

The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks

30 Aug 2021
5.4
CVSS
CVE-2021-20782HIGH

Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

14 Jul 2021
8.8
CVSS
CVE-2020-29171MEDIUM

Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.

10 Feb 2021
6.1
CVSS
CVE-2020-5651HIGH

SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL.

21 Oct 2020
8.8
CVSS
CVE-2020-5650MEDIUM

Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

21 Oct 2020
6.1
CVSS
CVE-2019-5993HIGH

Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

12 Sep 2019
8.8
CVSS
CVE-2016-10888CRITICAL

The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.

14 Aug 2019
9.8
CVSS
CVE-2016-10887CRITICAL

The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.

14 Aug 2019
9.8
CVSS
CVE-2015-9310CRITICAL

The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.

14 Aug 2019
9.8
CVSS
CVE-2016-10867MEDIUM

The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.

13 Aug 2019
6.1
CVSS
CVE-2016-10866MEDIUM

The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.

13 Aug 2019
6.1
CVSS
CVE-2016-10868MEDIUM

The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.

13 Aug 2019
6.1
CVSS
CVE-2015-9294MEDIUM

The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.

13 Aug 2019
6.1
CVSS
CVE-2015-9293MEDIUM

The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.

13 Aug 2019
6.1
CVSS
CVE-2013-2705MEDIUM

Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings.

13 May 2014
6.8
CVSS
← PrevPage 2 / 2Next →
Tipsandtricks-hq CVEs & Vulnerabilities — 75 Tracked — Page 2