oxilab Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with oxilab products.
Products
- accordions1 vulnerability
- Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )1 vulnerability
- Image Hover Effects Ultimate (WordPress plugin)1 vulnerability
- Product Layouts for WooCommerce1 vulnerability
- Shortcode Addons Plugin1 vulnerability
- shortcode_addons1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-13362MEDIUM | Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url ParameterMultiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CWE-79May 1, 2026 | CVSS6.1v3.1 | EPSS0.276% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-5092MEDIUM | Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript LibraryMultiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Nov 20, 2025 | CVSS6.4v3.1 | EPSS0.233% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-31114CRITICAL | WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in biplob018 Shortcode Addons.This issue affects Shortcode Addons: from n/a through 3.2.5. CWE-434Mar 31, 2024 | CVSS9.1v3.1 | EPSS1.35% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-34487CRITICAL | WordPress Shortcode Addons plugin <= 3.0.2 - Unauthenticated Arbitrary Option Update vulnerabilityUnauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress. | CVSS9.8v3.1 | EPSS3.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-33198CRITICAL | WordPress Accordions plugin <= 2.0.2 - Unauthenticated WordPress Options Change vulnerabilityUnauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress. | CVSS9.8v3.1 | EPSS3.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-36888CRITICAL | WordPress Image Hover Effects Ultimate plugin <= 9.6.1 - Unauthenticated Arbitrary Options Update leading to full website compromiseUnauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin. | CVSS9.8v3.1 | EPSS6.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |