| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a KiviCare custom role with the 'settings_view' permission (e.g., Doctor or Receptionist), meaning standard WordPress subscribers cannot exploit this without a KiviCare-assigned role. |
| The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data. |
| Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions. |
| Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS.
This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress Theme: from n/a through 2.5; M.Anh - Fashion WooCoommerce WordPress Theme: from n/a through 1.7. |
| The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the site issue arbitrary requests to internal hosts and services, including requests with an attacker-chosen method, headers and body. |
| Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. |
| Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. |
| Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. |
| Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. |
| Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. |
| Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. |
| Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. |
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. |
| Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. |