← WordPress Vulnerabilities
WordPress security by component

Image Hover Effects Ultimate

Image Hover Effects Ultimate is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published Dec 13, 2022; the highest CVE/CNA score is 9.8.

Plugin slug: image-hover-effects-ultimate

CVE-2022-4207: Image Hover Effects Ultimate: Cross-site scripting

Image Hover Effects Ultimate is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedDec 13, 2022
Safe version guidanceSee mitigation notes
Safe version
Dec 13, 2022 CVE-2022-4207
Image Hover Effects Ultimate: Cross-site scripting
Image Hover Effects Ultimate is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD5.4
Nov 18, 2022 CVE-2022-42459
Image Hover Effects Ultimate: A security weakness
Image Hover Effects Ultimate is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.2
NVD7.2
Sep 23, 2022 CVE-2022-2937
Image Hover Effects Ultimate: Cross-site scripting
Image Hover Effects Ultimate is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Sep 06, 2022 CVE-2022-2936
Image Hover Effects Ultimate: Cross-site scripting
Image Hover Effects Ultimate is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Sep 06, 2022 CVE-2022-2935
Image Hover Effects Ultimate: Cross-site scripting
Image Hover Effects Ultimate is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 20, 2022 CVE-2022-29424
Image Hover Effects Ultimate: Cross-site scripting
Image Hover Effects Ultimate is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jan 24, 2022 CVE-2021-25031
Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier): Cross-site scripting
Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Dec 15, 2021 CVE-2021-36888
Image Hover Effects Ultimate: A security weakness
Image Hover Effects Ultimate is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8