| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. |
| Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. |
| Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. |
| Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. |
| Unauthenticated SQL Injection in Readabler < 2.0.18 versions. |
| Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery.
This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0. |
| The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the site administrator has enabled the Lazy Load Media option in the plugin settings. |
| The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (replace-media-file execute_callback) function in all versions up to, and including, 5.1.1. This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is exploitable by first using the atarim/update-post-field ability to overwrite the _wp_attached_file meta of an attacker-owned attachment with a directory-traversal path, then invoking atarim/replace-media-file to cause get_attached_file() to resolve and unlink the targeted file. |
| The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is achieved by embedding a crafted img element with class='lazyload' and a data-script attribute pointing to an attacker-controlled URL in post content, which the plugin's bundled lazysizes ls.unveilhooks addon then uses to dynamically create and insert a script element into the DOM at page view time. |
| Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions. |
| Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions. |
| Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. |
| Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. |
| Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. |
| Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. |
| Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. |
| Unauthenticated Local File Inclusion in Resido <= 1.5 versions. |
| Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. |
| Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. |