← All credits

Lana Codes

335 vulnerability records and advisories credit this contributor.

CVE-2023-4600
The AffiliateWP for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'affwp_activate_addons_page_plugin' function called via an AJAX action in versions up to, and including, 2.14.0. This makes it possib
CVE-2023-2899
Google Map Shortcode <= 3.1.2 - Contributor+ Stored XSS
CVE-2023-2549
The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions starting from 1.0.7 up to, and including, 1.1.1. This is due to missing nonce validation in the 'createTempAccountLink' function. This makes it possible fo
CVE-2023-2547
The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteUser' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated att
CVE-2023-2545
The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticat
CVE-2023-1274
Pricing Tables For WPBakery Page Builder < 3.0 - Subscriber+ LFI
CVE-2023-0812
Active Directory Integration / LDAP Integration < 4.1.1 - Unauthenticated Data Disclosure
CVE-2023-0768
Avirato hotels online booking engine <= 5.0.5 - Subscriber+ SQLi
CVE-2023-0766
Newsletter Popup <= 1.2 - Record Deletion via CSRF
CVE-2023-0733
Newsletter Popup <= 1.2 - Unauthenticated Stored XSS