biplob018 Vulnerabilities and Affected Products
Vulnerabilities associated with Image Hover Effects Ultimate.
Products
Clear product- Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier)3 vulnerabilities
- Image Hover Effects for Elementor with Lightbox and Flipbox2 vulnerabilities
- Shortcode Addons2 vulnerabilities
- Shortcode Addons (WordPress plugin)2 vulnerabilities
- Image Hover Effects - Caption Hover with Carousel1 vulnerability
- Image Hover Effects Ultimate1 vulnerability
- Team Showcase and Slider – Team Members Builder1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-2937MEDIUM | Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Title & DescriptionThe Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Description values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, the plugin only allows administrators access to edit Image Hovers… CWE-79Sep 23, 2022 | CVSS6.4v3.1 | EPSS0.508% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |