Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium3
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2024-11-21

CVE-2024-5861 - Wp Easypay Plugin

The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3. This makes it possible for unauthenticated attackers to disconnect square.

PLUGIN Wp Easypay

CVE-2024-5861

MEDIUM CVSS 5.3 2024-07-24
Threat Entry Updated 2025-05-05

CVE-2023-1465 - Wp Easypay Plugin

The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin

PLUGIN Wp Easypay

CVE-2023-1465

MEDIUM CVSS 6.1 2023-08-16
Threat Entry Updated 2026-04-08

CVE-2021-4411 - Wp Easypay Plugin

The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the wpep_download_transaction_in_excel() function. This makes it possible for unauthenticated attackers to trigger a transactions download via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Easypay

CVE-2021-4411

MEDIUM CVSS 4.3 2023-07-12
Scroll to top