WordPress security by component
Image Hover Effects Ultimate
Plugin description
Image Hover Effects Ultimate adds configurable hover effects and animations to images displayed on WordPress pages.
Image Hover Effects Ultimate (image-hover-effects-ultimate) is a WordPress plugin with 8 published CVE records in this archive. The latest tracked vulnerability was published Dec 13, 2022; the highest published CVSS base score is 9.8.
Plugin slug:
image-hover-effects-ultimateLatest vulnerability
CVE-2022-4207: Image Hover Effects Ultimate: Cross-site scripting
Image Hover Effects Ultimate is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
| Safe version |
|
||
|---|---|---|---|
| Dec 13, 2022 |
CVE-2022-4207
Image Hover Effects Ultimate: Cross-site scripting
Image Hover Effects Ultimate is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.5
NVD5.4
|
| Nov 18, 2022 |
CVE-2022-42459
Image Hover Effects Ultimate: A security weakness
Image Hover Effects Ultimate is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Sep 23, 2022 |
CVE-2022-2937
Image Hover Effects Ultimate: Cross-site scripting
Image Hover Effects Ultimate is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Sep 06, 2022 |
CVE-2022-2936
Image Hover Effects Ultimate: Cross-site scripting
Image Hover Effects Ultimate is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Sep 06, 2022 |
CVE-2022-2935
Image Hover Effects Ultimate: Cross-site scripting
Image Hover Effects Ultimate is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 20, 2022 |
CVE-2022-29424
Image Hover Effects Ultimate: Cross-site scripting
Image Hover Effects Ultimate is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Jan 24, 2022 |
CVE-2021-25031
Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier): Cross-site scripting
Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Dec 15, 2021 |
CVE-2021-36888
Image Hover Effects Ultimate: A security weakness
Image Hover Effects Ultimate is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVD9.8
|