CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 2, 2025

WordPress Ultimate Auction Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Ultimate Auction plugin, affecting versions through 4.2.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Leaky Paywall Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Leaky Paywall WordPress plugin, affecting versions through 4.21.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 2, 2025

The Events Calendar Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in The Events Calendar WordPress plugin, affecting versions through 6.5.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

4.6
Jan 2, 2025

SWTE Swift Performance Lite Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the SWTE Swift Performance Lite plugin for WordPress, affecting versions through 2.3.6.20. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Construction Landing Page Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Construction Landing Page, specifically in versions through 1.3.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Lawyer Landing Page Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Lawyer Landing Page, specifically in versions through 1.2.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

SKT Themes Posterity Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the SKT Themes Posterity WordPress theme, affecting versions through 3.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.4
Jan 2, 2025

Apollo13Themes Rife Free Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Apollo13Themes Rife Free WordPress theme, affecting versions through 2.4.18. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

3.4
Jan 2, 2025

WP Royal Bard Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Royal Bard theme, specifically in versions through 2.210. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

WP Royal Ashe Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Royal Ashe theme, specifically in versions through 2.233. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

BlazeThemes Trendy News Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the BlazeThemes Trendy News WordPress theme, affecting versions through 1.0.15. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

CreativeThemes Blocksy Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the CreativeThemes Blocksy WordPress theme, affecting versions through 2.0.22. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

4.1
Jan 2, 2025

ThemeIsle Hestia Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeIsle Hestia WordPress theme, specifically in versions through 3.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

ExtendThemes Highlight Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ExtendThemes Highlight WordPress theme, specifically in versions through 1.0.29. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Travel Agency Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Travel Agency, specifically in versions through 1.4.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Benevolent Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Benevolent, specifically in versions through 1.3.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 2, 2025

FameThemes OnePress Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the FameThemes OnePress WordPress theme, affecting versions through 2.3.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 2, 2025

DesertThemes NewsMash Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the DesertThemes NewsMash WordPress theme, specifically in versions through 1.0.34. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Perfect Portfolio Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Perfect Portfolio, affecting versions through 1.2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 2, 2025

WordPress Mesmerize Theme Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Mesmerize theme, specifically in versions through 1.6.120. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

4.1
Jan 2, 2025

Rara Theme Elegant Pink Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Elegant Pink, affecting versions through 1.3.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 2, 2025

Rara Theme JobScout Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme JobScout, specifically in versions through 1.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Coachify WordPress Theme Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Coachify WordPress theme, specifically in versions through 1.0.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Preschool and Kindergarten Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme for WordPress, specifically in versions through 1.2.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Blossom Themes Blossom Shop Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Blossom Shop WordPress theme, affecting versions through 1.1.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Freshlight Lab WP Mobile Menu Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Freshlight Lab WP Mobile Menu plugin for WordPress, affecting versions through 2.8.4.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.9
Jan 2, 2025

WP Travel Engine Travel Monster Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Travel Engine Travel Monster theme, affecting versions through 1.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.1
Jan 2, 2025

Blossom Themes Vandana Lite Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Blossom Themes Vandana Lite WordPress theme, specifically in versions through 1.1.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Automattic Newspack Newsletters Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Automattic Newspack Newsletters plugin for WordPress, affecting versions through 2.13.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Faboba Falang Multilanguage WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Faboba Falang multilanguage WordPress plugin, affecting versions through 1.3.51. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.9
Jan 2, 2025

WPAdverts Classifieds Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WPAdverts Classifieds Plugin for WordPress, affecting versions through 2.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Loco Translate WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Loco Translate WordPress plugin, specifically in versions through 2.6.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

5.0
Jan 2, 2025

Groundhogg WordPress Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Groundhogg WordPress plugin, specifically in versions through 3.4.2.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

3.5
Jan 2, 2025

Rara Theme Chic Lite Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Chic Lite, specifically in versions through 1.1.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Rara Theme Education Zone Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Education Zone, affecting versions through 1.3.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

Blossom Themes Vilva Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Blossom Themes Vilva WordPress theme, specifically in versions through 1.2.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

2.0
Jan 2, 2025

StylemixThemes MasterStudy LMS Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress MasterStudy LMS plugin, affecting versions through 3.2.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.

4.2
Jan 2, 2025

D-Link DIR-816 A2 ACL Handler Improper Access Control Vulnerability

A critical vulnerability has been identified in the D-Link DIR-816 A2 router, specifically in version 1.10CNB05_R1B011D88210. The issue resides in the ACL Handler component, within the file '/goform/form2LocalAclEditcfg.cgi'. This vulnerability allows for improper access controls, which can be exploited remotely.

6.8
Jan 2, 2025

D-Link DIR-816 A2 IP QoS Handler Access Control Vulnerability

A critical vulnerability has been identified in the D-Link DIR-816 A2 router, specifically in version 1.10CNB05_R1B011D88210. The issue arises from improper access controls in the IP QoS Handler component, particularly within the file '/goform/form2IPQoSTcAdd'. This vulnerability allows for unauthorized access and manipulation, and can be exploited remotely.

6.8
Jan 2, 2025

Themefic Ultimate Addons for Contact Form 7 Missing Authorization Vulnerability Allowing Broken Access Control

A missing authorization vulnerability has been identified in Themefic Ultimate Addons for Contact Form 7, specifically in versions through 3.2.6. This vulnerability allows exploitation of improperly configured access control, potentially enabling unauthorized users to perform actions reserved for higher privileges.

4.0
Jan 2, 2025

Flothemes Flo Forms Missing Authorization Vulnerability Allowing Broken Access Control

A missing authorization vulnerability has been identified in the Flothemes Flo Forms WordPress plugin, specifically in versions through 1.0.41. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling users to perform actions reserved for higher privileges.

1.8
Jan 2, 2025

Toast Plugins Animator Missing Authorization Vulnerability Allowing Unauthenticated Access Control Changes

A missing authorization vulnerability has been identified in the Toast Plugins Animator WordPress plugin, affecting versions through 3.0.10. This vulnerability allows unauthenticated users to exploit improperly configured access control settings, potentially leading to unauthorized changes in plugin settings.

2.5
Jan 2, 2025

Dragfy Addons for Elementor Missing Authorization Vulnerability

A broken access control vulnerability has been identified in the Dragfy Addons for Elementor WordPress plugin, affecting versions through 1.0.2. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.

1.7
Jan 2, 2025

WordPress EazyDocs Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the WordPress EazyDocs plugin, specifically in versions through 2.3.5. This vulnerability allows exploitation of improperly configured access control security levels, potentially leading to unauthorized actions by users with lower privileges.

3.0
Jan 2, 2025

WordPress BadgeOS Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the WordPress BadgeOS plugin, specifically in versions through 3.7.1.6. This vulnerability allows unprivileged users to exploit improperly configured access control, potentially leading to unauthorized actions that require higher privileges.

3.1
Jan 2, 2025

WordPress Visitors Traffic Real Time Statistics Plugin Broken Access Control Vulnerability

A broken access control vulnerability has been identified in the WordPress Visitors Traffic Real Time Statistics Plugin, affecting versions through 7.2. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.

2.2
Jan 2, 2025

Ecreate Infotech Auto Tag Creator Missing Authorization Vulnerability

A broken access control vulnerability has been identified in the Ecreate Infotech Auto Tag Creator WordPress plugin, affecting versions through 1.0.2. This vulnerability arises from missing authorization checks, allowing unprivileged users to perform actions reserved for higher privileges.

1.8
Jan 2, 2025

Seers WordPress Plugin Broken Access Control Vulnerability

A missing authorization vulnerability has been identified in the Seers WordPress plugin, specifically in versions through 8.1.1. This vulnerability arises from incorrectly configured access control security levels, allowing unprivileged users to perform actions reserved for higher privileges.

2.6
Jan 2, 2025

CoCart Headless Ecommerce Missing Authorization Vulnerability Allowing Broken Access Control

A missing authorization vulnerability has been identified in the CoCart Headless Ecommerce WordPress plugin, affecting versions through 3.11.2. This vulnerability allows exploitation of incorrectly configured access control security levels, potentially leading to unauthorized users performing actions reserved for higher privileges.

2.6
Jan 2, 2025

KaizenCoders Short URL Plugin Broken Access Control Vulnerability

A broken access control vulnerability has been identified in the KaizenCoders Short URL WordPress plugin, affecting versions through 1.6.8. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.

2.2