Known Vulnerabilities for products from Wpbrigade
Listed below are 9 of the newest known vulnerabilities associated with the vendor "Wpbrigade".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-5845 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.3 - MEDIUM | 2023-11-27 | 2023-12-01 |
| CVE-2022-41839 json | Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-I... | 5.3 - MEDIUM | 2022-11-18 | 2022-11-22 |
| CVE-2022-4625 json | The Login Logout Menu WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outp... | 5.4 - MEDIUM | 2023-01-23 | 2023-11-07 |
| CVE-2022-4622 json | The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes before out... | 5.4 - MEDIUM | 2023-02-21 | 2023-11-07 |
| CVE-2022-0347 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2022-03-07 | 2022-03-11 |
| CVE-2021-24656 json | The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputtin... | 4.8 - MEDIUM | 2021-10-11 | 2021-10-15 |
| CVE-2021-24486 json | The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align ... | 5.4 - MEDIUM | 2021-08-23 | 2023-11-07 |
| CVE-2019-15872 json | The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings. | 9.8 - CRITICAL | 2019-09-03 | 2019-09-05 |
| CVE-2019-15871 json | The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings. | 4.3 - MEDIUM | 2019-09-03 | 2020-08-24 |
Known software with vulnerabilities from Wpbrigade
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Wpbrigade | Loginpress | - |