Search Results (22 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-45082 1 Oxilab 1 Accordions 2024-11-21 3.4 Low
Multiple Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabilities in Accordions plugin <= 2.0.3 on WordPress via &addons-style-name and &accordions_or_faqs_license_key.
CVE-2021-25031 1 Oxilab 1 Image Hover Effects Ultimate 2024-11-21 6.1 Medium
The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting