Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Coming Soon Page plugin <= 1.0.7.3 versions.
CVSS
5.9
MEDIUM
Published
Apr 7, 2023
Vendor coverage
Track published CVEs, severity trends, and remediation context for snapcreek products.
Search results
Showing 1-3 of 3 vulnerabilities.
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Coming Soon Page plugin <= 1.0.7.3 versions.
CVSS
5.9
MEDIUM
Published
Apr 7, 2023
installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly.
CVSS
6.1
MEDIUM
Published
Nov 14, 2017
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
CVSS
8.2
HIGH
Published
Aug 7, 2017