Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WOOCS – Currency Switcher for WooCommerce. Professional and Free multi currency plugin – Pay in selected currency | 1.3.7.5 ~ 1.3.7.5 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress WOOCS plugin before 1.3.7.5 is susceptible to cross-site scripting. The plugin does not sanitize and escape the woocs_in_order_currency parameter of the woocs_get_products_price_html AJAX action, available to both unauthenticated and authenticated users, before outputting it back in the response. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0234.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-4208 | ExportFeed <= 2.0.1.0 - Admin+ SQL Injection | |
| CVE-2022-0313 | Float Menu < 4.3.1 - Arbitrary Menu Deletion via CSRF | |
| CVE-2022-0288 | Ad Inserter < 2.7.10 - Reflected Cross-Site Scripting | |
| CVE-2022-0279 | AnyComment < 0.2.18 - Comment Rating Increase/Decrease via Race Condition | |
| CVE-2022-0255 | Database Backup for WordPress < 2.5.1 - Admin+ SQL Injection | |
| CVE-2022-0252 | Give < 2.17.3 - Reflected Cross-Site Scripting via Import Tool | |
| CVE-2022-0228 | Popup Builder < 4.0.7 - Admin+ SQL Injection | |
| CVE-2022-0211 | Shield Security < 13.0.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0199 | Coming soon and Maintenance mode < 3.6.8 - Arbitrary Email Sending to Subscribed Users via | |
| CVE-2022-0186 | Image Photo Gallery Final Tiles Grid < 3.5.3 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2022-0164 | Coming soon and Maintenance mode < 3.6.7 - Subscriber+ Arbitrary Email Sending to Subscrib | |
| CVE-2022-0134 | AnyComment < 0.2.18 - Arbitrary HyperComments Import/Revert via CSRF | |
| CVE-2021-24921 | Advanced Database Cleaner < 3.0.4 - Reflected Cross-Site Scripting | |
| CVE-2021-25101 | Anti-Malware Security and Brute-Force Firewall < 4.20.94 - Admin+ Reflected Cross-Site Scr | |
| CVE-2021-25100 | Give < 2.17.3 - Reflected Cross-Site Scripting via Donation Forms Dashboard | |
| CVE-2021-25099 | Give < 2.17.3 - Unauthenticated Reflected Cross-Site Scripting | |
| CVE-2021-25082 | Popup Builder < 4.0.7 - LFI to RCE | |
| CVE-2021-25075 | Duplicate Page or Post < 1.5.1 - Arbitrary Settings Update to Stored XSS | |
| CVE-2021-25069 | WordPress Download Manager < 3.2.34 - Authenticated SQL Injection to Reflected XSS | |
| CVE-2021-25060 | Five Star Business Profile and Schema < 2.1.7 - Subscriber+ Page Creation & Settings Updat |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet