Vulnerabilities (CVE)

Filtered by vendor Xwp Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-43450 1 Xwp 1 Stream 2024-02-05 N/A 6.5 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2.
CVE-2022-43490 1 Xwp 1 Stream 2024-02-04 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in XWP Stream plugin <= 3.9.2 versions.
CVE-2021-24772 1 Xwp 1 Stream 2024-02-04 6.5 MEDIUM 8.8 HIGH
The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.