VendorsCoolPluginscryptocurrency_widgetsall versions
Vulnerabilities

CoolPlugins Cryptocurrency Widgets

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-0709
The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Published 2024-02-05 · Analyzed
9.8EPSS 0.009
CVE-2023-36681
WordPress Cryptocurrency Widgets – Price Ticker & Coins List plugin <= 2.6.2 - Broken Access Control vulnerability
Published 2024-12-13 · Modified
9.8EPSS 0.009
CVE-2022-4950
Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activation
Published 2023-06-07 · Modified
8.8EPSS 0.014
CVE-2024-43304
WordPress Cryptocurrency Widgets plugin <= 2.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-08-18 · Analyzed
7.1EPSS 0.003
CVE-2024-27953
WordPress Cryptocurrency Widgets – Price Ticker & Coins List Plugin <= 2.6.8 is vulnerable to Broken Access Control
Published 2024-03-13 · Modified
4.7EPSS 0.004