plugin

Foxyshop Vulnerabilities

6 known security issues reported for the Foxyshop WordPress plugin. Most recent disclosed Jul 11, 2022.

2 medium

Running Foxyshop on your site? Check whether your installed version is affected.

Scan your site free

FoxyShop [foxyshop] < 4.8.2

unknown

[en] The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

Affected:
up to 4.8.2
Fixed in:
4.8.2
Disclosed:
Jul 11, 2022

CVE-2022-1220 on NVD →

FoxyShop <= 4.8.1 - Reflected Cross-Site Scripting

medium

The FoxyShop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in versions up to, and including, 4.8.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can successfu...

CVSS:
6.1
Affected:
up to 4.8.1
Fixed in:
4.8.2
Disclosed:
Jun 16, 2022

CVE-2022-1220 on NVD →

FoxyShop [foxyshop] < 4.6.1

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 4.6.1
Fixed in:
4.6.1
Disclosed:
May 14, 2015

PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

CVSS:
6.1
Affected:
up to 4.6.1
Fixed in:
4.6.1
Disclosed:
Aug 1, 2014

CVE-2013-6837 on NVD →

FoxyShop [foxyshop] < 4.6.1

unknown

[en] Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

Affected:
up to 4.6.1
Fixed in:
4.6.1
Disclosed:
Dec 19, 2013

CVE-2013-6837 on NVD →

FoxyShop [foxyshop] < 4.6.1

unknown

The jQuery prettyPhoto library bundled with many plugins was found to be vulnerable to DOM Cross-Site Scripting (XSS).

Affected:
up to 4.6.1
Fixed in:
4.6.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database