Product Catalog Feed by PixelYourSite [product-catalog-feed] < 2.2.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite Product Catalog Feed by PixelYourSite.This issue affects Product Catalog Feed by PixelYourSite: from n/a through 2.1.1.
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Dec 17, 2023
CVE-2023-49824 on NVD →
Product Catalog Feed by PixelYourSite <= 2.1.1 - Cross-Site Request Forgery
medium
The Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the set_disable_status(), set_wpwoof_schedule() and check_feed_name() functions. This makes it possible for unauthen...
- CVSS:
- 4.3
- Affected:
- up to 2.1.1
- Fixed in:
- 2.2.0
- Disclosed:
- Dec 5, 2023
CVE-2023-49824 on NVD →
Product Catalog Feed by PixelYourSite [product-catalog-feed] < 2.1.1
unknown
[en] The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- May 2, 2023
CVE-2023-1805 on NVD →
Product Catalog Feed by PixelYourSite [product-catalog-feed] < 2.1.1
unknown
[en] The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- May 2, 2023
CVE-2023-1804 on NVD →
Product Catalog Feed by PixelYourSite <= 2.1.0 - Reflected Cross-Site Scripting via 'page'
medium
The Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.1
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Apr 10, 2023
CVE-2023-1805 on NVD →
Product Catalog Feed by PixelYourSite <= 2.1.0 - Reflected Cross-Site Scripting via 'edit'
medium
The Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'edit' parameter in versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.1
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Apr 10, 2023
CVE-2023-1804 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database