Vulnerabilities
Vulnerable Software
Tribulant:  Security Vulnerabilities
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-11-10
The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
CVSS Score
4.8
EPSS Score
0.002
Published
2021-11-23
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.
CVSS Score
7.5
EPSS Score
0.01
Published
2021-01-01
The one-click-ssl plugin before 1.4.7 for WordPress has CSRF.
CVSS Score
8.8
EPSS Score
0.002
Published
2019-08-30
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
CVSS Score
9.8
EPSS Score
0.011
Published
2019-08-22
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.
CVSS Score
8.8
EPSS Score
0.017
Published
2019-08-15
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.
CVSS Score
5.4
EPSS Score
0.003
Published
2019-08-09
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-04-15
SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-04-15
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-04-15


Contact Us

Shodan ® - All rights reserved