Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Social Share, Social Login and Social Comments Plugin | 0 ~ 7.13.52 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-2779.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-2600 | Custom Base Terms < 1.0.3 - Admin+ Stored XSS | |
| CVE-2023-2684 | File Renaming on Upload < 2.5.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2023-2811 | AI ChatBot < 4.5.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2023-2221 | WP Custom Cursors < 3.2 - Admin+ SQLi | |
| CVE-2023-2719 | SupportCandy < 3.1.7 - Subscriber+ SQLi | |
| CVE-2023-2742 | AI ChatBot < 4.5.5 - Admin+ Stored Cross-Site Scripting | |
| CVE-2023-2492 | QueryWall: Plug'n Play Firewall <= 1.1.1 - Admin+ SQLi | |
| CVE-2023-2899 | Google Map Shortcode <= 3.1.2 - Contributor+ Stored XSS | |
| CVE-2023-2401 | Qubotchat < 1.1.6 – Admin+ Stored XSS | |
| CVE-2023-2812 | Ultimate Dashboard < 3.7.6 - Admin+ Stored XSS | |
| CVE-2023-0368 | Responsive Tabs For WPBakery Page Builder <= 1.1 - Contributor+ Stored XSS | |
| CVE-2023-2359 | Revolution Slider <= 6.6.12 - Author+ Remote Code Execution | |
| CVE-2023-0489 | SlideOnline <= 1.2.1 - Contributor+ Stored XSS | |
| CVE-2023-2527 | Integration for Contact Form 7 and Zoho CRM, Bigin < 1.2.4 - Admin+ SQLi | |
| CVE-2023-2399 | qubotchat < 1.1.6 - Unauthenticated Stored XSS | |
| CVE-2023-2751 | Upload Resume <= 1.2.0 - Captcha Bypass | |
| CVE-2023-2654 | Conditional Menus < 1.2.1 - Reflected XSS | |
| CVE-2023-2805 | SupportCandy < 3.1.7 - Admin+ SQLi |
No comments yet