CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
WP Wand Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the WP Wand WordPress plugin, affecting versions through 1.2.5. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.
Stormhill Media MyBookTable Bookstore Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Stormhill Media MyBookTable Bookstore plugin for WordPress, affecting versions through 3.5.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
PixelYourSite WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the PixelYourSite WordPress plugin, specifically in versions through 10.0.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress AI for SEO Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WordPress AI for SEO plugin, specifically in versions through 1.2.9. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling unprivileged users to perform actions reserved for higher privileges.
Hive Support WordPress Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the Hive Support WordPress Help Desk plugin, specifically in versions through 1.1.6. This vulnerability allows unprivileged users to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions that require higher privileges.
AIpost AI WP Writer Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the AIpost AI WP Writer plugin for WordPress, affecting versions through 3.8.4.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Gutentor WordPress Plugin DOM-Based Cross-Site Scripting Vulnerability
A DOM-based cross-site scripting vulnerability has been identified in the Gutentor WordPress plugin, affecting versions through 3.4.3. This issue arises from improper input neutralization during web page generation, allowing malicious actors to inject and execute harmful scripts on the website.
WordPress WP FullCalendar Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress WP FullCalendar plugin, specifically in versions through 1.5. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WPSpins Post/Page Copying Tool Sensitive Data Exposure Vulnerability
A vulnerability allowing the exposure of sensitive information has been identified in the WPSpins Post/Page Copying Tool plugin for WordPress, affecting versions through 2.0.0. This issue arises from the insertion of sensitive data into sent content, which can be retrieved and potentially misused.
Pektsekye Notify Odoo Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Pektsekye Notify Odoo WordPress plugin, affecting versions through 1.0.0. This vulnerability arises from improper input neutralization during web page generation, allowing malicious actors to inject harmful scripts that are executed in the context of the user.
5 Star Plugins Pretty Simple Popup Builder Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Pretty Simple Popup Builder plugin by 5 Star Plugins, affecting versions through 1.0.9. This vulnerability allows for the injection of malicious scripts that are executed when users visit the site.
WordPress Highlight Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Highlight plugin, affecting versions through 2.0.2. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Hometory Mang Board WP Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Hometory Mang Board WP plugin, affecting versions through 1.8.4. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.
POSIMYTH Nexter Blocks Missing Authorization Vulnerability Allowing Access Control Exploitation
A broken access control vulnerability has been identified in the POSIMYTH Nexter Blocks WordPress plugin, affecting versions through 4.0.7. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.
WordPress Advanced Form Integration Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress plugin Advanced Form Integration, affecting versions through 1.95.0. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress Email Reminders Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress Email Reminders plugin, affecting versions through 2.0.5. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
Plainware PlainInventory Plugin PHP Object Injection Vulnerability
A deserialization vulnerability allowing object injection has been identified in the Plainware PlainInventory WordPress plugin, affecting versions through 3.1.6. This vulnerability could lead to various injection attacks, including code injection, SQL injection, and path traversal, especially if a suitable property-oriented programming chain is available.
WordPress Multiple Shipping and Billing Address for WooCommerce SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the WordPress plugin 'Multiple Shipping and Billing Address for WooCommerce', affecting versions through 1.2. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and interact with the database in unauthorized ways.
Groundhogg Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Groundhogg WordPress plugin, affecting versions through 3.7.3.3. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress WP Docs Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress WP Docs plugin, affecting versions through 2.2.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected site.
WordPress WP jQuery DataTable Plugin Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WordPress WP jQuery DataTable plugin, affecting versions through 4.0.1. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
Classic Addons WPBakery Page Builder Local File Inclusion Vulnerability
A path traversal vulnerability allowing PHP local file inclusion has been identified in the Classic Addons WPBakery Page Builder plugin, affecting versions through 3.0. This vulnerability could enable the inclusion of local files from the target website, potentially exposing sensitive information such as database credentials, which could lead to a complete database takeover depending on the configuration.
WPBits WPBITS Addons For Elementor Page Builder Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the WPBITS Addons For Elementor Page Builder plugin, affecting versions through 1.5.1. This vulnerability arises from improper input neutralization during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
SSL Wireless SMS Notification Plugin SQL Injection Vulnerability
A SQL injection vulnerability has been identified in the SSL Wireless SMS Notification WordPress plugin, affecting versions through 3.5.0. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to manipulate database queries and interact with the database in unauthorized ways.
Locatoraid Store Locator PHP Object Injection Vulnerability
A deserialization vulnerability allowing object injection has been identified in the Locatoraid Store Locator WordPress plugin, affecting versions through 3.9.50. This vulnerability could lead to various injection attacks, including code injection, SQL injection, and path traversal, especially if a suitable object injection chain is exploited.
Elicus WPMozo Addons Lite for Elementor Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the Elicus WPMozo Addons Lite for Elementor plugin, affecting versions through 1.1.0. This vulnerability arises from improper control of filenames in include or require statements, allowing PHP remote file inclusion. Exploitation of this issue could enable a malicious actor to include local files from the target website and display their contents, potentially leading to a database takeover if files containing database credentials are accessed.
CodeMShop WordPress Payment SimplePay Plugin Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the CodeMShop WordPress Payment SimplePay plugin, affecting versions through 5.2.0. This vulnerability arises from improper control of filenames in include or require statements, allowing PHP remote file inclusion. Exploitation of this issue could enable a malicious actor to include local files from the target website and display their contents, potentially leading to a database takeover if sensitive information such as database credentials is accessed.
Amento Tech WPGuppy Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the WPGuppy plugin by Amento Tech Pvt Ltd, affecting versions through 1.1.0. This vulnerability allows low-privileged users to gain higher privileges, potentially leading to full control of the website.
WordPress Compact WP Audio Player Server-Side Request Forgery Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in the WordPress Compact WP Audio Player plugin, affecting versions through 1.9.14. This vulnerability allows attackers to manipulate the server into making requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.
Smackcoders WP Ultimate Exporter Code Injection Vulnerability Allowing PHP Remote File Inclusion
A code injection vulnerability has been identified in the Smackcoders WP Ultimate Exporter plugin for WordPress, specifically in versions through 2.9.1. This vulnerability allows for PHP remote file inclusion, which could lead to remote code execution on the affected site.
WPForms Contact Form Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WPForms Contact Form plugin, specifically in versions through 1.9.2.2. This vulnerability allows exploitation of improperly configured access control, potentially enabling unprivileged users to perform actions reserved for higher privileges.
Envato Elements WordPress Plugin Server-Side Request Forgery Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in the Envato Elements WordPress plugin, affecting versions through 2.0.14. This vulnerability allows attackers to make the server perform requests to arbitrary domains, potentially leading to the exposure of sensitive information from other services running on the system.
Brainstorm Force Astra Widgets Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Brainstorm Force Astra Widgets plugin for WordPress, affecting versions through 1.2.15. This vulnerability arises from improper input handling during web page generation, allowing malicious scripts to be injected and executed when users visit the affected site.
WPvivid Backup and Migration Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the WPvivid Backup and Migration plugin for WordPress, affecting versions through 0.9.106. This vulnerability allows users to access functionalities that are not properly restricted by access control lists (ACLs), potentially leading to unauthorized actions.
WordPress WP SecureSubmit Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the WordPress WP SecureSubmit plugin, affecting versions through 1.5.16. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileged users.
ClickWhale WordPress Plugin SQL Injection Vulnerability
A blind SQL injection vulnerability has been identified in the ClickWhale WordPress plugin, specifically in versions through 2.4.1. This vulnerability allows for improper neutralization of special elements used in SQL commands, potentially enabling attackers to interact with the database in unauthorized ways, such as stealing information.
NAVER Analytics Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the NAVER Analytics WordPress plugin, affecting versions through 0.9. This issue arises from improper input sanitization during web page generation, allowing malicious scripts to be injected and executed.
CubeWP CubeWP Forms Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the CubeWP Forms – All-in-One Form Builder plugin for WordPress, affecting versions through 1.1.5. This vulnerability allows exploitation of incorrectly configured access control security levels, potentially leading to unauthorized users performing actions reserved for higher privileges.
Abdul Hakeem Build App Online PHP Local File Inclusion Vulnerability
A local file inclusion vulnerability has been identified in the Abdul Hakeem Build App Online plugin for WordPress, affecting versions through 1.0.23. This vulnerability arises from improper control of filenames in include or require statements, allowing PHP remote file inclusion that could be exploited to include local files from the target website and display their contents. Such exploitation could lead to the disclosure of sensitive information, like database credentials, potentially allowing a complete takeover of the database, depending on the configuration.
AllAccessible Team Accessibility Privilege Escalation Vulnerability
A privilege escalation vulnerability has been identified in the WordPress Accessibility by AllAccessible plugin, affecting versions through 1.3.4. This vulnerability allows low-privileged users to gain higher privileges, potentially leading to full control of the website.
Designinvento DirectoryPress Reflected Cross-Site Scripting Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Designinvento DirectoryPress plugin, affecting versions through 3.6.19. This issue arises from improper input sanitization during web page generation, allowing attackers to inject malicious scripts that are executed in the context of the user's browser.
MagePeople Bus Ticket Booking Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the MagePeople Bus Ticket Booking with Seat Reservation plugin for WordPress, affecting versions through 5.4.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
SMSA Express SMSA Shipping Path Traversal Vulnerability Allowing Arbitrary File Deletion
A path traversal vulnerability has been identified in the SMSA Express SMSA Shipping WordPress plugin, affecting versions through 2.3. This vulnerability allows for arbitrary file deletion, which could lead to the removal of critical files from a website, potentially causing the site to malfunction.
Amento Tech WPGuppy WordPress Plugin PHP Object Injection Vulnerability
A deserialization vulnerability allowing object injection has been identified in the WPGuppy WordPress plugin, affecting versions through 1.1.0. This vulnerability could lead to various injection attacks, including code injection, SQL injection, and path traversal, especially if a suitable property-oriented programming chain is available.
ThemeGlow JobBoard Plugin Unrestricted File Upload Vulnerability Allowing Web Shell Upload
A vulnerability allowing unrestricted file upload has been identified in the ThemeGlow JobBoard plugin, specifically in the Job Listing feature, affecting versions through 1.2.6. This vulnerability could be exploited to upload a web shell to the server, potentially leading to unauthorized access and execution of malicious actions.
WordPress File Upload Plugin Missing Capability Check Vulnerability Allowing Limited Path Traversal
A vulnerability exists in the WordPress File Upload plugin, specifically in versions through 4.24.15. The issue arises from a lack of proper capability checks in the 'wfu_ajax_action_read_subfolders' function. This flaw enables authenticated attackers with Subscriber-level access or higher to execute limited path traversal, allowing them to view directories and subdirectories within WordPress. However, this vulnerability does not permit access to files themselves.
Service Box WordPress Plugin Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Service Box plugin for WordPress, affecting all versions through 1.9. This vulnerability arises from inadequate input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary scripts into pages. The injected scripts are executed when users access the compromised pages.
MIPL WC Multisite Sync Directory Traversal Vulnerability Allowing Unauthenticated Arbitrary File Download
A directory traversal vulnerability has been identified in the MIPL WC Multisite Sync plugin for WordPress, affecting all versions through 1.1.5. The vulnerability arises from improper validation in the 'mipl_wc_sync_download_log' action, allowing unauthenticated users to access and read arbitrary files on the server. This could lead to the exposure of sensitive information.
OpenHarmony Denial-of-Service Vulnerability via Use-After-Free
A denial-of-service vulnerability has been identified in OpenHarmony versions through 4.1.2. This issue allows local attackers to cause a denial-of-service condition by exploiting a use-after-free flaw.
OpenHarmony Out-of-Bounds Write Vulnerability Leading to Boot Failure
A vulnerability in OpenHarmony versions through 4.1.2 allows local attackers to cause the device to fail to boot by exploiting an out-of-bounds write condition.
