Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP TripAdvisor Review Slider | 0 ~ 10.8 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress WP TripAdvisor Review Slider plugin before 10.8 is susceptible to authenticated SQL injection. The plugin does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber. This can lead, in turn, to obtaining sensitive information, modifying data, and/or executing unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0261.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-0220 | Pinpoint Booking System < 2.9.9.2.9 - Subscriber+ SQLi | |
| CVE-2023-0099 | Simple URLs < 115 - Multiple Reflected XSS | |
| CVE-2022-4628 | Easy PayPal Buy Now Button < 1.7.4 - Contributor+ Stored XSS in Shortcode | |
| CVE-2023-0362 | Themify Portfolio Post < 1.2.2 - Contributor+ Stored XSS | |
| CVE-2022-4445 | FL3R FeelBox <= 8.1 - Unauthenticated SQLi | |
| CVE-2022-4783 | Youtube Channel Gallery <= 2.4 - Contributor+ Stored XSS via Shortcode | |
| CVE-2022-4473 | Widget Shortcode <= 0.3.5 - Contributor+ Stored XSS | |
| CVE-2023-0379 | Spotlight Social Feeds < 1.4.3 - Contributor+ Stored XSS | |
| CVE-2023-0270 | YaMaps for WordPress Plugin < 0.6.26 - Contributor+ Stored XSS | |
| CVE-2022-4678 | TemplatesNext ToolKit < 3.2.8 - Contributor+ Stored XSS via Shortcode | |
| CVE-2023-0060 | Responsive Gallery Grid < 2.3.9 - Contributor+ Stored XSS | |
| CVE-2022-4551 | Rich Table of Contents < 1.3.9 - Contributor+ Stored XSS | |
| CVE-2023-0373 | Lightweight Accordion < 1.5.15 - Contributor+ Stored XSS | |
| CVE-2022-4458 | Amr Shortcode Any Widget <= 4.0 - Contributor+ Stored XSS | |
| CVE-2023-0169 | Zoho Forms < 3.0.1 - Contributor+ Stored XSS | |
| CVE-2023-0260 | WP Review Slider < 12.2 - Subscriber+ SQLi | |
| CVE-2023-0333 | TemplatesNext ToolKit < 3.2.9 - Contributor+ Stored XSS | |
| CVE-2022-4546 | Mapwiz <= 1.0.1 - Admin+ SQLi | |
| CVE-2023-0061 | Judge.me Product Reviews for WooCommerce < 1.3.21 - Contributor+ Stored XSS | |
| CVE-2023-0098 | Simple URLs < 115 - Subscriber+ SQLi |
Showing top 20 of 47 CVEs. View all on vendor page → →
No comments yet