ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-13823
The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected C

The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.

NVD description · AI analysis pending
6.1<1% PoC
  • yofla 360 product rotation
CVE-2019-15082
The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.

The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.

NVD description · AI analysis pending
6.1<1%
  • yofla 360 product rotation