cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forenhanced-tooltipglossary enhanced-tooltipglossary

Direction: ascending
Jun 07, 2024

CM Tooltip Glossary – Powerful Glossary Plugin # CVE-2016-1000132

CVE, Research URL

CVE-2016-1000132

Date
Oct 11, 2016
Research Description
Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8
Affected versions
Min -, max -.
Status
vulnerable

CM Tooltip Glossary – Powerful Glossary Plugin # CVE-2024-4086

CVE, Research URL

CVE-2024-4086

Date
May 02, 2024
Research Description
The CM Tooltip Glossary – Powerful Glossary Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.11. This is due to missing or incorrect nonce validation when saving settings. This makes it possible for unauthenticated attackers to change the plugin's settings or reset them via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable

CM Tooltip Glossary – Powerful Glossary Plugin # CVE-2021-24678

CVE, Research URL

CVE-2021-24678

Date
Oct 04, 2021
Research Description
The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks
Affected versions
Min -, max -.
Status
vulnerable
Aug 12, 2024

CM Tooltip Glossary – Powerful Glossary Plugin # CVE-2024-43149

CVE, Research URL

CVE-2024-43149

Date
Aug 13, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Tooltip Glossary allows Stored XSS.This issue affects CM Tooltip Glossary: from n/a through 4.3.7.
Affected versions
Min -, max -.
Status
vulnerable
Oct 13, 2024

CM Tooltip Glossary – Powerful Glossary Plugin # CVE-2024-48041

CVE, Research URL

CVE-2024-48041

Date
Oct 12, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Tooltip Glossary allows Stored XSS.This issue affects CM Tooltip Glossary: from n/a through 4.3.9.
Affected versions
Min -, max -.
Status
vulnerable
Nov 26, 2024

CM Tooltip Glossary – Powerful Glossary Plugin # CVE-2024-11202

CVE, Research URL

CVE-2024-11202

Date
Nov 26, 2024
Research Description
Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Feb 16, 2025

CM Tooltip Glossary – Powerful Glossary Plugin # CVE-2025-24758

CVE, Research URL

CVE-2025-24758

Date
Mar 03, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows Reflected XSS. This issue affects CM Map Locations: from n/a through 2.0.8.
Affected versions
Min -, max -.
Status
vulnerable
May 19, 2025

CM Tooltip Glossary – Powerful Glossary Plugin # CVE-2024-5026

CVE, Research URL

CVE-2024-5026

Date
May 16, 2025
Research Description
The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
Min -, max -.
Status
vulnerable