Vulnerabilities (CVE)

Filtered by vendor G5plus Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6141 1 G5plus 1 Essential Real Estate 2024-01-11 N/A 5.4 MEDIUM
The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks.
CVE-2023-6139 1 G5plus 1 Essential Real Estate 2024-01-11 N/A 6.5 MEDIUM
The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.