Vulnerabilities (CVE)

Filtered by vendor Rafflepress Subscribe
Filtered by product Rafflepress
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-3963 1 Rafflepress 1 Rafflepress 2025-06-09 N/A 6.5 MEDIUM
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks