| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions. |
| Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. |
| The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including registered post types, labels, associated taxonomies, form scheme metadata, contact options, and custom field meta keys. |
| The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
| Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. |
| Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. |
| Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. |
| Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. |
| Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. |
| Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. |
| Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. |
| Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. |
| Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. |
| Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. |
| Editor PHP Object Injection in OptionTree <= 2.7.3 versions. |
| Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. |
| Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions. |
| Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. |
| Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. |