CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Themeisle PPOM for WooCommerce Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Themeisle PPOM for WooCommerce plugin, affecting versions through 33.0.8. This vulnerability allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when users visit the site.
ThemeIsle AI Chatbot for WordPress Hyve Lite Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the ThemeIsle AI Chatbot for WordPress – Hyve Lite plugin, affecting versions through 1.2.2. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Simple Download Monitor SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the WordPress Simple Download Monitor plugin, affecting versions through 3.9.25. This vulnerability allows for improper neutralization of special elements used in SQL commands, enabling direct interaction with the database, such as stealing information.
WordPress Download Manager Premium Packages SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the WordPress Download Manager Premium Packages plugin, affecting versions through 5.9.6. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing for direct interaction with the database, such as stealing information.
WordPress Auction Nudge Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Auction Nudge – Your eBay on Your Site plugin, affecting versions through 7.2.0. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
WebToffee Wishlist for WooCommerce Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WebToffee Wishlist for WooCommerce plugin, affecting versions through 2.1.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Revmakx WP Duplicate WordPress Migration Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the Revmakx WP Duplicate – WordPress Migration Plugin, affecting versions through 1.1.6. This vulnerability allows exploitation of improperly configured access control, potentially enabling unprivileged users to perform actions reserved for higher privileges.
Themefic Tourfic WordPress Plugin Arbitrary File Upload Vulnerability
A vulnerability allowing unrestricted upload of files with dangerous types has been identified in the Themefic Tourfic WordPress plugin, affecting versions through 2.15.3. This vulnerability could be exploited to upload a web shell to the server.
WordPress Admin and Site Enhancements (ASE) Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WordPress Admin and Site Enhancements (ASE) Plugin, affecting versions through 7.6.2. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.
WordPress WooCommerce Cloak Affiliate Links Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress WooCommerce Cloak Affiliate Links plugin, affecting versions through 1.0.35. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WebToffee WooCommerce PDF Invoices Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin, affecting versions through 4.7.1. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users view the affected content.
WordPress Create with Code Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress Create with Code plugin, affecting versions through 1.4. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
Laymance Technologies MachForm Shortcode Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the MachForm Shortcode plugin by Laymance Technologies, LLC. This vulnerability allows for Stored Cross-Site Scripting (XSS) and affects versions of the plugin through 1.4.1.
WordPress Orbisius Simple Notice Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Orbisius Simple Notice WordPress plugin, specifically in versions through 1.1.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Silverplugins Build Private Store For WooCommerce Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the Silverplugins Build Private Store For WooCommerce plugin, affecting versions through 1.0. This vulnerability arises from missing authorization checks, allowing unprivileged users to perform actions reserved for higher privileges.
WordPress Blur Text Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Blur Text plugin, specifically in versions through 1.0.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Taxonomy/Term and Role Based Discounts for WooCommerce Missing Authorization Vulnerability
A missing authorization vulnerability has been identified in the WordPress plugin Taxonomy/Term and Role Based Discounts for WooCommerce, affecting versions through 5.1. This vulnerability allows exploitation of incorrectly configured access control security levels, potentially leading to unauthorized changes in settings.
Really Simple SSL WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Really Simple SSL WordPress plugin, affecting versions through 9.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
PickPlugins Job Board Manager Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the PickPlugins Job Board Manager WordPress plugin, affecting versions through 2.1.59. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
ElementInvader Addons for Elementor Missing Authorization Vulnerability
A broken access control vulnerability has been identified in the ElementInvader Addons for Elementor plugin, affecting versions through 1.3.1. This vulnerability arises from missing authorization checks, allowing users with lower privileges to perform actions reserved for higher privileged users.
Foliovision FV Thoughtful Comments Missing Authorization Vulnerability Allowing Access Control Exploitation
A missing authorization vulnerability has been identified in the Foliovision FV Thoughtful Comments WordPress plugin, affecting versions through 0.3.5. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions or access.
Smackcoders WP Ultimate Exporter Path Traversal Vulnerability Allowing Arbitrary File Download
A path traversal vulnerability has been identified in the Smackcoders WP Ultimate Exporter plugin, specifically in versions through 2.9. This vulnerability allows for absolute path traversal, enabling unauthorized access to files on the server. An attacker could exploit this to download sensitive files, such as those containing login credentials or backup data.
WordPress Restrict Anonymous Access Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Restrict Anonymous Access plugin, specifically in versions through 1.2. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that could be executed when visitors access the affected site.
Vikas Ratudi VForm WordPress Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the Vikas Ratudi VForm WordPress plugin, specifically in versions through 3.0.5. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.
WC Product Table WooCommerce Product Table Lite Missing Authorization Vulnerability
A missing authorization vulnerability has been identified in the WC Product Table WooCommerce Product Table Lite plugin, affecting versions through 3.8.7. This vulnerability allows exploitation of improperly configured access control, potentially leading to unauthorized actions by users with lower privileges.
WordPress All Embed – Elementor Addons Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress All Embed – Elementor Addons plugin, affecting versions through 1.1.3. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Speedcomp Linet ERP-Woocommerce Integration Missing Authorization Vulnerability
A missing authorization vulnerability has been identified in the Speedcomp Linet ERP-Woocommerce Integration plugin, affecting versions through 3.5.7. This vulnerability allows exploitation of improperly configured access control security levels, potentially leading to unauthorized actions being performed by users with higher privileges.
NinjaTeam GDPR CCPA Compliance Support Missing Authorization Vulnerability
A broken access control vulnerability has been identified in the NinjaTeam GDPR CCPA Compliance Support WordPress plugin, affecting versions through 2.7.1. This vulnerability arises from missing authorization checks, which can be exploited to manipulate access control security levels improperly.
WordPress JSM Show Post Metadata Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WordPress JSM Show Post Metadata plugin, affecting versions through 4.6.0. This vulnerability allows exploitation of improperly configured access control security levels, potentially leading to unauthorized actions by users with lower privileges.
Patreon WordPress Plugin Missing Authorization Vulnerability Allowing Broken Access Control
A missing authorization vulnerability has been identified in the Patreon WordPress plugin, specifically in versions through 1.9.1. This vulnerability allows for broken access control by exploiting incorrectly configured security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.
I Thirteen Web Solution Email Subscription Popup SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the I Thirteen Web Solution Email Subscription Popup plugin, affecting versions through 1.2.23. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing malicious actors to interact with the database and potentially steal information.
N.O.U.S. WordPress Event Post Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the N.O.U.S. WordPress Event Post plugin, affecting versions through 5.9.7. This vulnerability allows for the injection of malicious scripts that are executed when users visit the affected site.
Code for Recovery 12 Step Meeting List Sensitive Data Exposure Vulnerability
A vulnerability allowing the insertion of sensitive information into sent data has been identified in the Code for Recovery 12 Step Meeting List plugin, affecting versions through 3.16.5. This vulnerability could allow unauthorized retrieval of embedded sensitive data, which is typically not accessible to regular users.
Code for Recovery 12 Step Meeting List Missing Authorization Vulnerability Allowing Arbitrary Content Deletion
A missing authorization vulnerability has been identified in the Code for Recovery 12 Step Meeting List WordPress plugin, affecting versions through 3.16.5. This vulnerability allows exploitation of improperly configured access control security levels, leading to arbitrary content deletion. As a result, malicious actors could potentially remove posts, pages, or media from affected websites.
WordPress Nested Pages Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Nested Pages plugin, affecting versions through 3.2.9. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
ElementInvader Addons for Elementor DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the ElementInvader Addons for Elementor plugin, affecting versions through 1.3.0. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the affected site.
HelloAsso WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the HelloAsso WordPress plugin, affecting versions through 1.1.11. This vulnerability allows for the injection of malicious scripts that are executed when users visit the affected site.
WordPress PageLayer Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the WordPress PageLayer plugin, affecting versions through 1.9.4. This issue arises from improper input sanitization during web page generation, allowing malicious actors to inject and execute harmful scripts on the site.
Epsiloncool WP Fast Total Search Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Epsiloncool WP Fast Total Search plugin for WordPress, specifically in versions through 1.78.258. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Epsiloncool WP Fast Total Search Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the Epsiloncool WP Fast Total Search plugin for WordPress, specifically in versions through 1.78.258. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.
Atarim WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Atarim WordPress plugin, affecting versions through 4.0.8. This vulnerability allows attackers to inject malicious scripts that are executed when users visit the affected site.
Brainstorm Force Starter Templates Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Brainstorm Force Starter Templates plugin for WordPress, affecting versions through 4.4.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Optimal Access KBucket WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Optimal Access KBucket WordPress plugin, affecting versions through 4.1.6. This vulnerability allows for Stored Cross-Site Scripting, where an attacker can inject malicious scripts that are executed by users.
WordPress ReviewsTap Plugin Cross-Site Request Forgery Vulnerability Allowing Stored Cross-Site Scripting
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress ReviewsTap plugin, specifically in versions through 1.1.2. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be injected and executed within the user's browser.
WordPress Subscription DNA Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Subscription DNA plugin, affecting versions through 2.1. This vulnerability allows for Stored Cross-Site Scripting (XSS) attacks. The issue arises because the plugin does not properly validate requests, enabling attackers to trick users with higher privileges into performing actions that could lead to XSS vulnerabilities.
David de Boer Paytium WordPress Plugin Full Path Disclosure Vulnerability
A full path disclosure vulnerability has been identified in the David de Boer Paytium WordPress plugin, affecting versions through 4.4.11. This vulnerability allows the retrieval of embedded sensitive data by disclosing the full path of files or directories on the server.
Matthias Wagner Caching Compatible Cookie Opt-In and JavaScript Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress plugin 'Caching Compatible Cookie Opt-In and JavaScript' versions through 0.0.10. This issue allows for improper neutralization of input during web page generation, enabling the injection of malicious scripts that are executed when visitors access the affected site.
RSTheme Ultimate Coming Soon & Maintenance Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the RSTheme Ultimate Coming Soon & Maintenance plugin for WordPress, affecting versions through 1.0.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Ultimate Coming Soon and Maintenance Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Ultimate Coming Soon & Maintenance plugin, specifically in versions through 1.0.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Icegram WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Icegram WordPress plugin, affecting versions through 3.1.31. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
