VendorsOxilabimage_hover_effects_ultimateany version
Vulnerabilities

Oxilab Image Hover Effects Ultimate any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2022-42459
WordPress Image Hover Effects Ultimate plugin <= 9.7.1 - Auth. WordPress Options Change vulnerability
Published 2022-11-18 · Modified
7.2EPSS 0.009
CVE-2022-2936
Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Video Link
Published 2022-09-06 · Modified
6.4EPSS 0.006
CVE-2022-2937
Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Title & Description
Published 2022-09-23 · Modified
6.4EPSS 0.006
CVE-2022-2935
Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Media URL
Published 2022-09-06 · Modified
6.4EPSS 0.006
CVE-2021-25031
Image Hover Effects Ultimate < 9.7.1 - Reflected Cross-Site Scripting
Published 2022-01-24 · Modified
6.1EPSS 0.009
CVE-2022-4207
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, the plugin only allows administrators access to edit Image Hovers, however, if a site admin makes the plugin's features available to lower privileged users through the 'Who Can Edit?' setting then this can be exploited by those users.
Published 2022-12-13 · Modified
5.5EPSS 0.006
CVE-2022-29424
WordPress Image Hover Effects Ultimate plugin <= 9.7.1 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
Published 2022-05-20 · Modified
4.8EPSS 0.005