| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. |
| Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. |
| Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. |
| Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions. |
| Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. |
| Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. |
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions. |
| Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. |
| Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. |
| Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. |
| Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. |
| Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. |
| Unauthenticated SQL Injection in Readabler < 2.0.18 versions. |
| Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery.
This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0. |
| The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the site administrator has enabled the Lazy Load Media option in the plugin settings. |
| The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (replace-media-file execute_callback) function in all versions up to, and including, 5.1.1. This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is exploitable by first using the atarim/update-post-field ability to overwrite the _wp_attached_file meta of an attacker-owned attachment with a directory-traversal path, then invoking atarim/replace-media-file to cause get_attached_file() to resolve and unlink the targeted file. |