Known Vulnerabilities for products from 2code
Listed below are 13 of the newest known vulnerabilities associated with the vendor "2code".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-3688 json | The WPQA Builder WordPress plugin before 5.9 does not have CSRF check when following and unfollowing users, which could allow... | 8.8 - HIGH | 2022-11-21 | 2023-11-07 |
| CVE-2022-3343 json | The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer Discy WordPress themes)... | 3.5 - LOW | 2023-01-09 | 2023-11-07 |
| CVE-2022-2198 json | The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorizati... | 4.3 - MEDIUM | 2022-08-22 | 2022-08-25 |
| CVE-2022-1598 json | The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API... | 5.3 - MEDIUM | 2022-06-08 | 2023-11-07 |
| CVE-2022-1597 json | The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape a pa... | 6.1 - MEDIUM | 2022-06-08 | 2022-06-14 |
| CVE-2022-1425 json | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate t... | 4.3 - MEDIUM | 2022-05-16 | 2022-05-24 |
| CVE-2022-1424 json | The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to tri... | 6.5 - MEDIUM | 2022-06-08 | 2022-06-14 |
| CVE-2022-1422 json | The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attac... | 6.5 - MEDIUM | 2022-06-08 | 2022-06-14 |
| CVE-2022-1421 json | The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin c... | 4.3 - MEDIUM | 2022-06-08 | 2022-06-14 |
| CVE-2022-1349 json | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate t... | 4.3 - MEDIUM | 2022-05-16 | 2023-07-24 |
| CVE-2022-1323 json | The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options act... | 6.5 - MEDIUM | 2022-08-08 | 2023-11-07 |
| CVE-2022-1241 json | The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page,... | 6.1 - MEDIUM | 2022-06-08 | 2022-06-14 |
| CVE-2022-1051 json | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise a... | 5.4 - MEDIUM | 2022-05-16 | 2022-05-24 |