plugin

Clio Grow Form Vulnerabilities

6 known security issues reported for the Clio Grow Form WordPress plugin. Most recent disclosed Oct 17, 2024.

3 medium

Running Clio Grow Form on your site? Check whether your installed version is affected.

Scan your site free

Clio Grow Form [clio-grow-form] < 1.0.3

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themis Solutions, Inc. Clio Grow allows Reflected XSS.This issue affects Clio Grow: from n/a through 1.0.2.

Affected:
up to 1.0.3
Fixed in:
1.0.3
Disclosed:
Oct 17, 2024

CVE-2024-49276 on NVD →

Clio Grow <= 1.0.2 - Reflected Cross-Site Scripting

medium

The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 1.0.2
Fixed in:
1.0.3
Disclosed:
Oct 15, 2024

CVE-2024-49276 on NVD →

Clio Grow Form [clio-grow-form] < 1.0.3

unknown

[en] The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

Affected:
up to 1.0.3
Fixed in:
1.0.3
Disclosed:
Oct 4, 2024

CVE-2024-8802 on NVD →

Clio Grow <= 1.0.2 - Reflected Cross-Site Scripting

medium

The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...

CVSS:
6.1
Affected:
up to 1.0.2
Fixed in:
1.0.3
Disclosed:
Oct 3, 2024

CVE-2024-8802 on NVD →

Clio Grow Form [clio-grow-form] < 1.0.1

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themis Solutions, Inc. Clio Grow plugin <= 1.0.0 versions.

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
May 3, 2023

CVE-2023-22683 on NVD →

Clio Grow <= 1.0.0 - Authenticated (Admin+) Stored Cross Site Scripting

medium

The Clio Grow plugin for WordPress is vulnerable to Stored Cross-Site Scripting up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will e...

CVSS:
4.4
Affected:
up to 1.0.0
Fixed in:
1.0.1
Disclosed:
Feb 20, 2023

CVE-2023-22683 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database