never5 CVE Vulnerabilities & CVE List (8)

Products (CPE): — CVEs: 8

never5 vulnerability overview

Aggregates CVE and security vulnerability intelligence across all never5-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting and vendor risk csrf, with potential vendor impact session compromise across vendor surface software deployment and vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 18 of 8 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-0592 The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the handle_create_link() function. This makes it possible for unauthenticated attackers to add related posts to other posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This ultimately makes it possible for attackers to view dra [email protected] 5.4 0.17% 2024-03-13 2026-04-08
CVE-2023-28931 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Never5 Post Connector plugin <= 1.0.9 versions. [email protected] 5.9 0.06% 2023-08-08 2024-11-21
CVE-2022-3506 Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3. [email protected] 5.4 1.73% 2022-10-14 2024-11-21
CVE-2021-24482 The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues. [email protected] 4.8 0.21% 2021-07-19 2024-11-21
CVE-2021-24180 Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL. [email protected] 5.4 0.16% 2021-04-05 2024-11-21
CVE-2015-9362 The Post Connector plugin before 1.0.4 for WordPress has XSS via add_query_arg() and remove_query_arg(). [email protected] 6.1 0.19% 2019-08-28 2024-11-21
CVE-2015-9361 The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg(). [email protected] 6.1 0.19% 2019-08-28 2024-11-21
CVE-2015-9296 The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg. [email protected] 6.1 0.19% 2019-08-13 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence