wptaskforce CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

wptaskforce vulnerability overview

Aggregates CVE and security vulnerability intelligence across all wptaskforce-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk sql injection and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-44004 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2. [email protected] 9.3 0.38% 2024-09-17 2026-04-23
CVE-2022-1436 The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number parameter before outputting it back in the page, which could allow attackers to perform reflected Cross-Site Scripting attacks. [email protected] 6.1 0.76% 2022-05-16 2024-11-21
CVE-2022-1435 The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. [email protected] 4.8 0.56% 2022-05-16 2024-11-21
CVE-2021-25003 The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE [email protected] 9.8 56.15% 2022-03-14 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence