Filtered by vendor Awplife Subscriptions
Total 26 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-35717 1 Awplife 1 Media Slider 2024-11-21 4.3 Medium
Missing Authorization vulnerability in A WP Life Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow.This issue affects Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow: from n/a through 1.3.9.
CVE-2023-23646 1 Awplife 1 Album Gallery 2024-11-21 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.
CVE-2021-24709 1 Awplife 1 Weather Effect 2024-11-21 4.8 Medium
The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting issues
CVE-2021-24683 1 Awplife 1 Weather Effect 2024-11-21 5.4 Medium
The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.
CVE-2021-24529 1 Awplife 1 Grid Gallery 2024-11-21 5.4 Medium
The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.
CVE-2019-17072 1 Awplife 1 Contact Form Widget 2024-11-21 9.8 Critical
The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.