| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions. |
| Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions. |
| Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions. |
| Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions. |
| Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. |
| Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions. |
| Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions. |
| Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. |
| Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. |
| Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions. |
| Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions. |
| Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions. |
| Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions. |
| The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data including personal information by iterating order identifiers. |
| The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier. |
| Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (XSS) in the `[drafts]` shortcode and Draft List widget when the documented custom `template` option places the `{{draft}}` placeholder inside an HTML attribute. The vulnerable code inserts the raw draft `post_title` into `{{draft}}` when the current viewer cannot edit posts. Because the template is sanitized before `{{draft}}` replacement, a Contributor can store a quote-only title payload that breaks out of an attribute in a site-configured Draft List template and executes JavaScript for visitors who load the public page. Version 2.6.4 fixes the issue. |
| The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). By placing post_type=attachment exclusively in the query string to bypass the consistency check, an attacker can convert an auto-draft GeoDirectory listing into a WordPress attachment with attacker-controlled file paths injected into attachment metadata, which the delete_revision handler then dereferences and unlinks without any post-type or path validation. |
| The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker. |