Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Antony Garand

#20394of 53,633
12.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-11708
7.2
2021-12-01
WordPress · Events Manager · CVE-2020-35012
Name of the Vulnerable Software and Affected Versions: Events Manager WordPress plugin versions prior to 5.9.8 Description: The issue is related to an SQL Injection. The problem arises because a parameter is not properly sanitised and escaped before being used in a SQL statement. Recommendations: For versions prior to 5.9.8, update to version 5.9.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin until the update is applied.
PT-2019-14046
5.4
2019-08-22
Givewp · Givewp · CVE-2019-15317
**Name of the Vulnerable Software and Affected Versions** give plugin versions prior to 2.4.7 **Description** The issue allows for XSS via a donor name. **Recommendations** For versions prior to 2.4.7, update to version 2.4.7 or later to resolve the issue.