Vulnerabilities
Vulnerable Software
Accessally:  Security Vulnerabilities
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through 2.1.1.
CVSS Score
5.9
EPSS Score
0.001
Published
2024-06-03
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through 2.1.1.
CVSS Score
5.9
EPSS Score
0.001
Published
2024-04-26
Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0.
CVSS Score
4.3
EPSS Score
0.001
Published
2024-03-26
In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the [accessally_order_form] shortcode, no login or administrator role is required.
CVSS Score
7.5
EPSS Score
0.254
Published
2021-04-12


Contact Us

Shodan ® - All rights reserved