Vulnerabilities (CVE)

Filtered by vendor Dianakcury Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-3918 1 Dianakcury 1 Pet Manager 2025-05-21 N/A 4.8 MEDIUM
The Pet Manager WordPress plugin through 1.4 does not sanitise and escape some of its Pet settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks.
CVE-2024-3917 1 Dianakcury 1 Pet Manager 2025-05-21 N/A 6.1 MEDIUM
The Pet Manager WordPress plugin through 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin