Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin | 3.1.0 ~ 3.1.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0769.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-0657 | 5 Stars Rating Funnel < 1.2.53 - Unauthenticated SQLi | |
| CVE-2022-1396 | Donorbox < 7.1.7 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1392 | Videos sync PDF <= 1.7.4 - Unauthenticated LFI | |
| CVE-2022-1391 | Cab fare calculator < 1.0.4 - Unauthenticated LFI | |
| CVE-2022-1390 | Admin Word Count Column <= 2.2 - Unauthenticated Arbitrary File Read | |
| CVE-2022-1228 | Opensea < 1.0.3 - Admin+ Stored XSS | |
| CVE-2022-1156 | Books & Papers <= 0.20210223 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1153 | LayerSlider < 7.1.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1152 | Menubar < 5.8 - Reflected Cross-Site Scripting | |
| CVE-2022-1094 | Amr Users < 4.59.4 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-1092 | myCred < 2.4.4 - Subscriber+ Import/Export to Email Address Disclosure | |
| CVE-2022-1027 | Page Restriction WordPress < 1.2.7 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0953 | Anti-Malware Security and Brute-Force Firewall < 4.20.96 - Reflected Cross-Site Scripting | |
| CVE-2022-0876 | Social comments by WpDevArt < 2.5.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-0782 | Donations <= 1.8 - Unauthenticated SQLi | |
| CVE-2022-0693 | Master Elements <= 8.0 - Unauthenticated SQLi | |
| CVE-2021-24800 | DW Question & Answer Pro <= 1.3.4 - Arbitrary Comment Edition via IDOR | |
| CVE-2022-0656 | uDraw < 3.3.3 - Unauthenticated Arbitrary File Access | |
| CVE-2022-0634 | ThirstyAffiliates < 3.10.5 - Subscriber+ unauthorized image upload + CSRF | |
| CVE-2022-0541 | Flo Launch < 2.4.1 - Missing Authentication Allow Full Site Takeover |
Showing top 20 of 32 CVEs. View all on vendor page → →
No comments yet