Unknown Socialdriver-Framework vulnerabilities
4 known vulnerabilities affecting unknown/socialdriver-framework.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2024-2872MEDIUMCVSS 4.8fixed in 2024.04.302024-08-01
CVE-2024-2872 [MEDIUM] CWE-79 CVE-2024-2872: The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of i
The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
cvelistv5nvd
CVE-2024-2870MEDIUMCVSS 6.1fixed in 2024.04.302024-07-13
CVE-2024-2870 [MEDIUM] CWE-79 CVE-2024-2870: The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a paramet
The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
cvelistv5nvd
CVE-2024-2696MEDIUMCVSS 4.8fixed in 2024.04.302024-07-12
CVE-2024-2696 [MEDIUM] CWE-79 CVE-2024-2696: The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of i
The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
cvelistv5nvd
CVE-2024-2697MEDIUMCVSS 6.5fixed in 2024.0.02024-05-17
CVE-2024-2697 [MEDIUM] CWE-79 CVE-2024-2697: The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its
The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
cvelistv5nvd