Author: Angelo Barbosa

CVE-2023-47779 | CRM Perks Integration for Constant Contact and Contact Form 7 Plugin redirect

A vulnerability classified as problematic was found in CRM Perks Integration for Constant Contact and Contact Form 7 Plugin, WPForms Plugin, Elementor Plugin and Ninja Forms Plugin up to 1.1.4 on WordPress. This vulnerability affects unknown code. The manipulation leads to open redirect. This vulnerability was named CVE-2023-47779. The attack can be initiated remotely. There is no exploit...

Read More

CVE-2023-41804 | Brainstorm Force Starter Templates Plugin up to 3.2.4 on WordPress server-side request forgery

A vulnerability classified as critical has been found in Brainstorm Force Starter Templates Plugin up to 3.2.4 on WordPress. This affects an unknown part. The manipulation leads to server-side request forgery. This vulnerability is uniquely identified as CVE-2023-41804. It is possible to initiate the attack remotely. There is no exploit...

Read More

CVE-2023-48839 | Appointment Scheduler 3.0 cross site scripting (ID 176055)

A vulnerability has been found in Appointment Scheduler 3.0 and classified as problematic. This vulnerability affects unknown code. The manipulation of the argument name/plugin_sms_api_key/plugin_sms_country_code/calendar_id/title/country name/customer_name leads to cross site scripting. This vulnerability was named CVE-2023-48839. The attack can be initiated remotely. There is no exploit...

Read More

CVE-2023-48838 | Appointment Scheduler 3.0 MS API Key/Default Country Code cross site scripting (ID 176054)

A vulnerability, which was classified as problematic, was found in Appointment Scheduler 3.0. This affects an unknown part. The manipulation of the argument MS API Key/Default Country Code leads to basic cross site scripting. This vulnerability is uniquely identified as CVE-2023-48838. It is possible to initiate the attack remotely. There is no exploit...

Read More