biplob018 Vulnerabilities and Affected Products
Vulnerabilities associated with Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier).
Products
Clear product- Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier)3 vulnerabilities
- Image Hover Effects for Elementor with Lightbox and Flipbox2 vulnerabilities
- Shortcode Addons2 vulnerabilities
- Shortcode Addons (WordPress plugin)2 vulnerabilities
- Image Hover Effects - Caption Hover with Carousel1 vulnerability
- Image Hover Effects Ultimate1 vulnerability
- Team Showcase and Slider – Team Members Builder1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-4207MEDIUM | The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, the plugin only allows administrators access to edit Image Hovers, however, if a site admin ma… CWE-79Dec 13, 2022 | CVSS5.5v3.1 | EPSS0.526% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-2935MEDIUM | Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Media URLThe Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media Image URL value that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, the plugin only allows administrators access to edit Image Hovers, how… CWE-79Sep 6, 2022 | CVSS6.4v3.1 | EPSS0.513% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-2936MEDIUM | Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Video LinkThe Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Video Link values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, the plugin only allows administrators access to edit Image Hovers, however, if… CWE-79Sep 6, 2022 | CVSS6.4v3.1 | EPSS0.526% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |