The visitors-online plugin before 1.0.0 for WordPress has multiple XSS issues.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NBestwebsoft Visitors Online
APPBestwebsoft< 1.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
Related vulnerabilities
CVE-2015-9325CRITICAL9.8PL ✓same product
SQL injection w pluginie Visitors Online dla WordPress
CVE-2021-24350MEDIUM6.1same product
The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) ...
CVE-2017-2171MEDIUM6.1same product
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Conta...
CVE-2022-3393CRITICAL9.8PL ✓same vendor
CSV Injection w pluginie Post To CSV by BestWebSoft dla WordPress
CVE-2015-9335CRITICAL9.8PL ✓same vendor
SQL injection w pluginie Limit Attempts dla WordPress (obsługa adresu IP)