Blocksera Image Hover Effects vulnerabilities
2 known vulnerabilities affecting blocksera/image_hover_effects.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-36888P1CRITICALCVSS 9.8ExploitedPoCfixed in 9.6.12021-12-15
CVE-2021-36888 [CRITICAL] CWE-284 CVE-2021-36888: Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.
nvd
CVE-2021-24264P4MEDIUMCVSS 5.4fixed in 1.3.42021-05-05
CVE-2021-24264 [MEDIUM] CWE-79 CVE-2021-24264: The “Image Hover Effects – Elementor Addon” WordPress Plugin before 1.3.4 has a widget that is vulne
The “Image Hover Effects – Elementor Addon” WordPress Plugin before 1.3.4 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
nvd