Vulnerabilities (CVE)

Filtered by vendor Strategy11 Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24251 1 Strategy11 1 Business Directory Plugin - Easy Listing Directories 2021-12-08 4.3 MEDIUM 4.3 MEDIUM
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example)
CVE-2021-24608 1 Strategy11 1 Formidable Form Builder 2021-10-27 3.5 LOW 4.8 MEDIUM
The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2021-24249 1 Strategy11 1 Business Directory Plugin - Easy Listing Directories 2021-05-13 4.3 MEDIUM 6.5 MEDIUM
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator export files, which could then be downloaded by the attacker to get access to PII, such as email, home addresses etc
CVE-2021-24250 1 Strategy11 1 Business Directory Plugin - Easy Listing Directories 2021-05-13 3.5 LOW 5.4 MEDIUM
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin.