etoilewebdesign CVE Vulnerabilities & Metrics

Focus on etoilewebdesign vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About etoilewebdesign Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with etoilewebdesign. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total etoilewebdesign CVEs: 16
Earliest CVE date: 02 Aug 2017, 05:29 UTC
Latest CVE date: 01 Nov 2024, 15:15 UTC

Latest CVE reference: CVE-2024-43343

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -50.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -50.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical etoilewebdesign CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.81

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 8
4.0-6.9 7
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS etoilewebdesign CVEs

These are the five CVEs with the highest CVSS scores for etoilewebdesign, sorted by severity first and recency.

All CVEs for etoilewebdesign

CVE-2024-43343 etoilewebdesign vulnerability CVSS: 0 01 Nov 2024, 15:15 UTC

Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Order Tracking: from n/a through 3.3.12.

CVE-2024-25597 etoilewebdesign vulnerability CVSS: 0 15 Mar 2024, 14:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from n/a through 3.2.8.

CVE-2023-4500 etoilewebdesign vulnerability CVSS: 0 31 Aug 2023, 06:15 UTC

The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers (admin or higher) to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2023-4471 etoilewebdesign vulnerability CVSS: 0 31 Aug 2023, 06:15 UTC

The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_date parameters in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-2711 etoilewebdesign vulnerability CVSS: 0 27 Jun 2023, 14:15 UTC

The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2020-36726 etoilewebdesign vulnerability CVSS: 0 07 Jun 2023, 02:15 UTC

The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.

CVE-2021-24993 etoilewebdesign vulnerability CVSS: 4.0 07 Feb 2022, 16:15 UTC

The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example

CVE-2022-23979 etoilewebdesign vulnerability CVSS: 3.5 28 Jan 2022, 20:15 UTC

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).

CVE-2021-24968 etoilewebdesign vulnerability CVSS: 3.5 24 Jan 2022, 08:15 UTC

The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions

CVE-2020-24313 etoilewebdesign vulnerability CVSS: 4.3 26 Aug 2020, 13:15 UTC

Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.

CVE-2020-7107 etoilewebdesign vulnerability CVSS: 4.3 16 Jan 2020, 05:15 UTC

The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.

CVE-2019-17233 etoilewebdesign vulnerability CVSS: 4.3 07 Oct 2019, 23:15 UTC

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.

CVE-2019-17232 etoilewebdesign vulnerability CVSS: 5.0 07 Oct 2019, 23:15 UTC

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

CVE-2019-15643 etoilewebdesign vulnerability CVSS: 4.3 27 Aug 2019, 12:15 UTC

The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.

CVE-2017-12200 etoilewebdesign vulnerability CVSS: 4.3 02 Aug 2017, 05:29 UTC

The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.

CVE-2017-12199 etoilewebdesign vulnerability CVSS: 7.5 02 Aug 2017, 05:29 UTC

The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_order video-item, image_update_order list-item, tag_group_update_order list_item, category_products_update_order category-product-item, custom_fields_update_order field-item, categories_update_order category-item, subcategories_update_order subcategory-item, and tags_update_order tag-list-item.