Filtered by vendor Wordlift Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-30624 1 Wordlift 1 Wordlift 2025-06-06 4.3 Medium
Missing Authorization vulnerability in WordLift WordLift allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordLift: from n/a through 3.54.4.
CVE-2022-3069 1 Wordlift 1 Wordlift 2025-05-22 4.8 Medium
The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.