plugin

Relevant Vulnerabilities

8 known security issues reported for the Relevant WordPress plugin. Most recent disclosed May 29, 2023.

2 medium

Running Relevant on your site? Check whether your installed version is affected.

Scan your site free

Relevant &#8211; Related, Featured, Latest, and Popular Posts by BestWebSoft [relevant] < 1.0.8

unknown

[en] A vulnerability classified as problematic was found in Bestwebsoft Relevant Plugin up to 1.0.7 on WordPress. Affected by this vulnerability is an unknown functionality of the component Thumbnail Handler. The manipulation leads to information disclosure. The attack can be launched remotely. Upgrading to version 1.0...

Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
May 29, 2023

CVE-2014-125102 on NVD →

Relevant &#8211; Related, Featured, Latest, and Popular Posts by BestWebSoft [relevant] < 1.0.8

unknown

[en] The relevant plugin before 1.0.8 for WordPress has XSS.

Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Sep 20, 2019

CVE-2015-9384 on NVD →

Relevant &#8211; Related, Featured, Latest, and Popular Posts by BestWebSoft [relevant] < 1.2.0

unknown

[en] Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,...

Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
May 22, 2017

CVE-2017-2171 on NVD →

Relevant – Related, Featured, Latest, and Popular Posts by BestWebSoft < 1.2.0 - Reflected Cross-Site Scripting

medium

The Relevant – Related, Featured, Latest, and Popular Posts by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in versions before 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

CVSS:
6.1
Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Apr 12, 2017

Relevant &#8211; Related, Featured, Latest, and Popular Posts by BestWebSoft [relevant] < 1.2.0

unknown

The Relevant – Related, Featured, Latest, and Popular Posts by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in versions before 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Apr 12, 2017

Relevant – Related, Featured, Latest, and Popular Posts by BestWebSoft <= 1.0.7 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Relevant Related Posts plugin up to and including version 1.0.7 for WordPress is vulnerable to stored cross-site scripting via the rltdpstsplgn_options parameter. This makes it possible for authenticated attackers, with administrator-level permissions, to inject arbitrary web scripts in pages that will execute when...

CVSS:
5.5
Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Oct 3, 2015

CVE-2015-9384 on NVD →

Relevant &#8211; Related, Featured, Latest, and Popular Posts by BestWebSoft [relevant] < 1.0.8

unknown

This plugin is prone to a cross site scripting vulnerability via "rltdpstsplgn_options[head]" and "rltdpstsplgn_options[no_post" parameters. Update the plugin.

Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Oct 3, 2015

Relevant &#8211; Related, Featured, Latest, and Popular Posts by BestWebSoft [relevant] < 1.2.0

unknown
Affected:
up to 1.2.0
Fixed in:
1.2.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database