CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
WordPress Ultimate Auction Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Ultimate Auction plugin, affecting versions through 4.2.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Leaky Paywall Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Leaky Paywall WordPress plugin, affecting versions through 4.21.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
The Events Calendar Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in The Events Calendar WordPress plugin, affecting versions through 6.5.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
SWTE Swift Performance Lite Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the SWTE Swift Performance Lite plugin for WordPress, affecting versions through 2.3.6.20. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Construction Landing Page Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Construction Landing Page, specifically in versions through 1.3.5. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Lawyer Landing Page Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Lawyer Landing Page, specifically in versions through 1.2.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
SKT Themes Posterity Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the SKT Themes Posterity WordPress theme, affecting versions through 3.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Apollo13Themes Rife Free Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Apollo13Themes Rife Free WordPress theme, affecting versions through 2.4.18. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WP Royal Bard Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Royal Bard theme, specifically in versions through 2.210. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WP Royal Ashe Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Royal Ashe theme, specifically in versions through 2.233. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
BlazeThemes Trendy News Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the BlazeThemes Trendy News WordPress theme, affecting versions through 1.0.15. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
CreativeThemes Blocksy Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the CreativeThemes Blocksy WordPress theme, affecting versions through 2.0.22. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
ThemeIsle Hestia Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeIsle Hestia WordPress theme, specifically in versions through 3.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
ExtendThemes Highlight Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the ExtendThemes Highlight WordPress theme, specifically in versions through 1.0.29. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Travel Agency Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Travel Agency, specifically in versions through 1.4.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Benevolent Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Benevolent, specifically in versions through 1.3.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
FameThemes OnePress Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the FameThemes OnePress WordPress theme, affecting versions through 2.3.6. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
DesertThemes NewsMash Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the DesertThemes NewsMash WordPress theme, specifically in versions through 1.0.34. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Perfect Portfolio Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Perfect Portfolio, affecting versions through 1.2.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WordPress Mesmerize Theme Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Mesmerize theme, specifically in versions through 1.6.120. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Elegant Pink Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Elegant Pink, affecting versions through 1.3.0. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme JobScout Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme JobScout, specifically in versions through 1.1.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Coachify WordPress Theme Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Coachify WordPress theme, specifically in versions through 1.0.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Preschool and Kindergarten Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme for WordPress, specifically in versions through 1.2.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Blossom Themes Blossom Shop Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Blossom Shop WordPress theme, affecting versions through 1.1.7. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Freshlight Lab WP Mobile Menu Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Freshlight Lab WP Mobile Menu plugin for WordPress, affecting versions through 2.8.4.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WP Travel Engine Travel Monster Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Travel Engine Travel Monster theme, affecting versions through 1.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Blossom Themes Vandana Lite Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Blossom Themes Vandana Lite WordPress theme, specifically in versions through 1.1.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Automattic Newspack Newsletters Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Automattic Newspack Newsletters plugin for WordPress, affecting versions through 2.13.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Faboba Falang Multilanguage WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Faboba Falang multilanguage WordPress plugin, affecting versions through 1.3.51. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
WPAdverts Classifieds Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WPAdverts Classifieds Plugin for WordPress, affecting versions through 2.1.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Loco Translate WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Loco Translate WordPress plugin, specifically in versions through 2.6.9. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Groundhogg WordPress Plugin Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Groundhogg WordPress plugin, specifically in versions through 3.4.2.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Chic Lite Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Chic Lite, specifically in versions through 1.1.3. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Rara Theme Education Zone Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rara Theme Education Zone, affecting versions through 1.3.4. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
Blossom Themes Vilva Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Blossom Themes Vilva WordPress theme, specifically in versions through 1.2.2. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
StylemixThemes MasterStudy LMS Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress MasterStudy LMS plugin, affecting versions through 3.2.1. This vulnerability allows attackers to trick users with higher privileges into performing actions they did not intend to.
D-Link DIR-816 A2 ACL Handler Improper Access Control Vulnerability
A critical vulnerability has been identified in the D-Link DIR-816 A2 router, specifically in version 1.10CNB05_R1B011D88210. The issue resides in the ACL Handler component, within the file '/goform/form2LocalAclEditcfg.cgi'. This vulnerability allows for improper access controls, which can be exploited remotely.
D-Link DIR-816 A2 IP QoS Handler Access Control Vulnerability
A critical vulnerability has been identified in the D-Link DIR-816 A2 router, specifically in version 1.10CNB05_R1B011D88210. The issue arises from improper access controls in the IP QoS Handler component, particularly within the file '/goform/form2IPQoSTcAdd'. This vulnerability allows for unauthorized access and manipulation, and can be exploited remotely.
Themefic Ultimate Addons for Contact Form 7 Missing Authorization Vulnerability Allowing Broken Access Control
A missing authorization vulnerability has been identified in Themefic Ultimate Addons for Contact Form 7, specifically in versions through 3.2.6. This vulnerability allows exploitation of improperly configured access control, potentially enabling unauthorized users to perform actions reserved for higher privileges.
Flothemes Flo Forms Missing Authorization Vulnerability Allowing Broken Access Control
A missing authorization vulnerability has been identified in the Flothemes Flo Forms WordPress plugin, specifically in versions through 1.0.41. This vulnerability allows exploitation of improperly configured access control security levels, potentially enabling users to perform actions reserved for higher privileges.
Toast Plugins Animator Missing Authorization Vulnerability Allowing Unauthenticated Access Control Changes
A missing authorization vulnerability has been identified in the Toast Plugins Animator WordPress plugin, affecting versions through 3.0.10. This vulnerability allows unauthenticated users to exploit improperly configured access control settings, potentially leading to unauthorized changes in plugin settings.
Dragfy Addons for Elementor Missing Authorization Vulnerability
A broken access control vulnerability has been identified in the Dragfy Addons for Elementor WordPress plugin, affecting versions through 1.0.2. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.
WordPress EazyDocs Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WordPress EazyDocs plugin, specifically in versions through 2.3.5. This vulnerability allows exploitation of improperly configured access control security levels, potentially leading to unauthorized actions by users with lower privileges.
WordPress BadgeOS Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the WordPress BadgeOS plugin, specifically in versions through 3.7.1.6. This vulnerability allows unprivileged users to exploit improperly configured access control, potentially leading to unauthorized actions that require higher privileges.
WordPress Visitors Traffic Real Time Statistics Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the WordPress Visitors Traffic Real Time Statistics Plugin, affecting versions through 7.2. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.
Ecreate Infotech Auto Tag Creator Missing Authorization Vulnerability
A broken access control vulnerability has been identified in the Ecreate Infotech Auto Tag Creator WordPress plugin, affecting versions through 1.0.2. This vulnerability arises from missing authorization checks, allowing unprivileged users to perform actions reserved for higher privileges.
Seers WordPress Plugin Broken Access Control Vulnerability
A missing authorization vulnerability has been identified in the Seers WordPress plugin, specifically in versions through 8.1.1. This vulnerability arises from incorrectly configured access control security levels, allowing unprivileged users to perform actions reserved for higher privileges.
CoCart Headless Ecommerce Missing Authorization Vulnerability Allowing Broken Access Control
A missing authorization vulnerability has been identified in the CoCart Headless Ecommerce WordPress plugin, affecting versions through 3.11.2. This vulnerability allows exploitation of incorrectly configured access control security levels, potentially leading to unauthorized users performing actions reserved for higher privileges.
KaizenCoders Short URL Plugin Broken Access Control Vulnerability
A broken access control vulnerability has been identified in the KaizenCoders Short URL WordPress plugin, affecting versions through 1.6.8. This vulnerability arises from missing authorization checks, which could allow an unprivileged user to perform actions reserved for higher privileges.
