| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions. |
| Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. |
| Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. |
| Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions. |
| Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. |
| Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. |
| Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. |
| Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. |
| The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. |
| Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions. |
| Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. |
| Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. |
| Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. |
| Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. |
| The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment images; its only guard passes for any logged-in user. A subscriber-level user can therefore supply an arbitrary attachment ID and overwrite that attachment's generated intermediate-size image (for example its thumbnail) and mutate its stored metadata, regardless of who owns the media. This is a cross-user integrity/defacement issue over the Media Library. The action also has no nonce, so it is additionally susceptible to CSRF. |
| The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query parameter, and the subsequent use of these URLs in fopen() calls without blocking internal or private network addresses. This makes it possible for authenticated attackers, with Contributor-level access and above, to make requests to arbitrary URLs and retrieve sensitive information from internal services. |