cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forrafflepress rafflepress

Direction: ascending
Jun 07, 2024

Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers # CVE-2024-4745

CVE, Research URL

CVE-2024-4745

Date
Jun 10, 2024
Research Description
Missing Authorization vulnerability in RafflePress Giveaways and Contests by RafflePress.This issue affects Giveaways and Contests by RafflePress: from n/a through 1.12.4.
Affected versions
Min -, max -.
Status
vulnerable

Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers # CVE-2023-5049

CVE, Research URL

CVE-2023-5049

Date
Oct 30, 2023
Research Description
The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rafflepress' and 'rafflepress_gutenberg' shortcode in versions up to, and including, 1.12.0 due to insufficient input sanitization and output escaping on 'giframe' user supplied attribute. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers # CVE-2023-0176

CVE, Research URL

CVE-2023-0176

Date
Feb 07, 2023
Research Description
The Giveaways and Contests by RafflePress WordPress plugin before 1.11.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected versions
Min -, max -.
Status
vulnerable

Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers # CVE-2024-1935

CVE, Research URL

CVE-2024-1935

Date
Mar 13, 2024
Research Description
The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘parent_url’ parameter in all versions up to, and including, 1.12.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers # CVE-2024-32827

CVE, Research URL

CVE-2024-32827

Date
May 17, 2024
Research Description
Authentication Bypass by Spoofing vulnerability in RafflePress Giveaways and Contests allows Functionality Bypass.This issue affects Giveaways and Contests: from n/a through 1.12.7.
Affected versions
Min -, max -.
Status
vulnerable
Jul 15, 2024

Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers # CVE-2024-3963

CVE, Research URL

CVE-2024-3963

Date
Jul 13, 2024
Research Description
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks
Affected versions
Min -, max -.
Status
vulnerable
Sep 13, 2024

Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers # CVE-2024-6887

CVE, Research URL

CVE-2024-6887

Date
Sep 12, 2024
Research Description
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Giveaways settings, which could allow high privilege users such as editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
Min -, max -.
Status
vulnerable
Apr 17, 2025

Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers # CVE-2024-10107

CVE, Research URL

CVE-2024-10107

Date
-
Research Description
Giveaways and Contests by RafflePress &#8211; Get More Website Traffic, Email Subscribers, and Social Followers [rafflepress] < 1.12.17 CVE-2024-10107
Affected versions
Min -, max -.
Status
vulnerable