cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forrock-convert rock-convert

Direction: ascending
Jun 07, 2024

Rock Convert # CVE-2022-36428

CVE, Research URL

CVE-2022-36428

Application

Rock Convert

Date
Nov 04, 2022
Research Description
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress.
Affected versions
max 3.0.0.
Status
vulnerable

Rock Convert # CVE-2022-3440

CVE, Research URL

CVE-2022-3440

Application

Rock Convert

Date
Oct 31, 2022
Research Description
The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading to a Reflected Cross-Site Scripting
Affected versions
max 2.11.0.
Status
vulnerable

Rock Convert # CVE-2022-3441

CVE, Research URL

CVE-2022-3441

Application

Rock Convert

Date
Oct 31, 2022
Research Description
The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
max 2.11.0.
Status
vulnerable
Nov 10, 2025

Rock Convert # CVE-2025-62911

CVE, Research URL

CVE-2025-62911

Application

Rock Convert

Date
Oct 27, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Content Rock Convert rock-convert allows Stored XSS.This issue affects Rock Convert: from n/a through <= 3.0.1.
Affected versions
max 3.0.1.
Status
vulnerable