Sydney Toolbox [sydney-toolbox] < 1.32
unknown
[en] The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri...
- Affected:
- up to 1.32
- Fixed in:
- 1.32
- Disclosed:
- May 14, 2024
CVE-2024-4473 on NVD →
Sydney Toolbox <= 1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via aThemes: Portfolio Widget
medium
The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor...
- CVSS:
- 6.4
- Affected:
- up to 1.31
- Fixed in:
- 1.32
- Disclosed:
- May 13, 2024
CVE-2024-4473 on NVD →
Sydney Toolbox [sydney-toolbox] < 1.31
unknown
[en] The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in all versions up to, and including, 1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitr...
- Affected:
- up to 1.31
- Fixed in:
- 1.31
- Disclosed:
- May 2, 2024
CVE-2024-4036 on NVD →
Sydney Toolbox <= 1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in all versions up to, and including, 1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 1.30
- Fixed in:
- 1.31
- Disclosed:
- May 1, 2024
CVE-2024-4036 on NVD →
Sydney Toolbox [sydney-toolbox] < 1.29
unknown
[en] The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 1.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- Affected:
- up to 1.29
- Fixed in:
- 1.29
- Disclosed:
- Apr 9, 2024
CVE-2024-3208 on NVD →
Sydney Toolbox <= 1.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery
medium
The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 1.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with cont...
- CVSS:
- 6.4
- Affected:
- up to 1.28
- Fixed in:
- 1.29
- Disclosed:
- Apr 5, 2024
CVE-2024-3208 on NVD →
Sydney Toolbox [sydney-toolbox] < 1.27
unknown
[en] The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in all versions up to, and including, 1.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribut...
- Affected:
- up to 1.27
- Fixed in:
- 1.27
- Disclosed:
- Mar 29, 2024
CVE-2024-2936 on NVD →
Sydney Toolbox <= 1.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via _id
medium
The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in all versions up to, and including, 1.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-le...
- CVSS:
- 6.4
- Affected:
- up to 1.26
- Fixed in:
- 1.27
- Disclosed:
- Mar 28, 2024
CVE-2024-2936 on NVD →
Sydney Toolbox [sydney-toolbox] < 1.26
unknown
[en] The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aThemes Slider button element in all versions up to, and including, 1.25 due to insufficient input sanitization and output escaping on user supplied link. This makes it possible for authenticated attackers with co...
- Affected:
- up to 1.26
- Fixed in:
- 1.26
- Disclosed:
- Feb 20, 2024
CVE-2024-1447 on NVD →
Sydney Toolbox <= 1.25 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aThemes Slider button element in all versions up to, and including, 1.25 due to insufficient input sanitization and output escaping on user supplied link. This makes it possible for authenticated attackers with contrib...
- CVSS:
- 6.4
- Affected:
- up to 1.25
- Fixed in:
- 1.26
- Disclosed:
- Feb 14, 2024
CVE-2024-1447 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database