| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through unsanitized user input. Attackers can craft GET requests with SQL injection payloads to manipulate database queries and extract sensitive information from the WordPress database. |
| Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions. |
| Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. |
| Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions. |
| Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. |
| Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. |
| Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. |
| Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. |
| Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions. |
| Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. |
| Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. |
| Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. |
| Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. |
| Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. |
| Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions. |
| Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions. |
| The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped. |
| The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget chain reaches a database query that is built without parameterisation, so an unauthenticated attacker can read arbitrary database data (e.g. user password hashes, secret keys) when the booking is later loaded. |
| Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions. |
| The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. |