Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Gowebsolutions Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24296 1 Gowebsolutions 1 Wp Customer Reviews 2021-05-28 3.5 LOW 4.8 MEDIUM
The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled
CVE-2021-24135 1 Gowebsolutions 1 Wp Customer Reviews 2021-03-24 4.3 MEDIUM 6.1 MEDIUM
Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML.
CVE-2016-10902 1 Gowebsolutions 1 Wp Customer Reviews 2019-08-22 6.8 MEDIUM 8.8 HIGH
The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
CVE-2016-10901 1 Gowebsolutions 1 Wp Customer Reviews 2019-08-21 4.3 MEDIUM 6.1 MEDIUM
The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.