goldplugins
Web & CMS Pluginscommercial
Top products
Latest CVEs
The 12 most recently published vulnerabilities affecting goldplugins.
- CVE-2024-8799Custom Banners <= 3.3 - Reflected Cross-Site Scripting6.1
- CVE-2024-2337Easy Testimonials <= 3.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode6.4
- CVE-2023-41797WordPress Locations Plugin <= 4.0 is vulnerable to Cross Site Scripting (XSS)6.5
- CVE-2021-4407Custom Banners <= 3.2.2 - Cross-Site Request Forgery Bypass4.3
- CVE-2020-36749Easy Testimonials <= 3.6.1 - Cross-Site Request Forgery Bypass4.3
- CVE-2021-4397Staff Directory Plugin <= 3.6 - Cross-Site Request Forgery Bypass4.3
- CVE-2021-4394Locations <= 3.2.1 - Cross-Site Request Forgery Bypass8.8
- CVE-2022-4577Easy Testimonials < 3.9.3 - Contributor+ Stored XSS5.4
- CVE-2020-14959Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the wp-admin/post.php Client Name, Position, ...5.4
- CVE-2018-19564Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.6.1
- CVE-2017-12131The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonials Width, View More Testimonials Link, and Testimonial Exc...6.1
- CVE-2017-9418SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the testid parameter to wp-admin/admin.php.8.8