| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Subscriber Broken Access Control in ListingPro <= 2.9.10 versions. |
| Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions. |
| Unauthenticated Broken Access Control in Civi <= 2.2.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions. |
| Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. |
| Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. |
| The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of server-side allow-list validation on the `employee_roles[]` and `new_role` POST parameters before they are passed to `mdjm_set_employee_role()` and `WP_User::set_role()`. This makes it possible for unauthenticated attackers to grant arbitrary MDJM capabilities — including `mdjm_employee` and `mdjm_employee_edit` — to any registered WordPress role, and subsequently leverage a subscriber-level account to escalate privileges to Administrator. `MDJM_Permissions::init()` is registered on the public WordPress `init` hook without any authentication gate, meaning the role-manipulation endpoint is reachable without any prior login. |
| The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. |
| Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. |
| Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. |
| Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. |
| Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. |
| Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. |
| Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. |
| Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. |
| Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. |