Wp-Useronline Project Wp-Useronline vulnerabilities
2 known vulnerabilities affecting wp-useronline_project/wp-useronline.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2022-2941P4MEDIUMCVSS 4.8PoCfixed in 2.88.12022-09-06
CVE-2022-2941 [MEDIUM] CWE-79 CVE-2022-2941: The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in v
The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0. This is due to the fact that all fields in the "Naming Conventions" section do not properly sanitize user input, nor escape it on output. This makes it possible for authenticated attackers, with administrative privile
nvd
CVE-2022-2473P4MEDIUMCVSS 4.8≤ 2.87.62022-09-06
CVE-2022-2473 [MEDIUM] CWE-79 CVE-2022-2473: The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templat
The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][text]' parameter in versions up to, and including, 2.87.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative capabilities and above to inject arbitrary web s
nvd