| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the site issue arbitrary requests to internal hosts and services, including requests with an attacker-chosen method, headers and body. |
| Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. |
| Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. |
| Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. |
| Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. |
| Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. |
| Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. |
| Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. |
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. |
| Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. |
| Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. |
| Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. |
| Subscriber SQL Injection in Reviewer <= 3.14.2 versions. |
| Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. |
| Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. |