Search Results (25 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-7759 1 Magazine3 1 Pwa For Wp \& Amp 2025-06-11 4.8 Medium
The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-7082 1 Magazine3 1 Easy Table Of Contents 2025-05-28 6.1 Medium
The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.
CVE-2024-6334 1 Magazine3 1 Easy Table Of Contents 2025-05-21 6.1 Medium
The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2024-5573 1 Magazine3 1 Easy Table Of Contents 2025-05-19 5.9 Medium
The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2018-20838 1 Magazine3 1 Amp For Wp 2024-11-21 N/A
ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS.