Search Results (20778 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-0855 1 Spiffyplugins 1 Spiffy Calendar 2025-05-01 5.3 Medium
The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.
CVE-2024-1106 2 3uu, Datenverwurstungszentrale 2 Shariff Wrapper, Shariff Wrapper 2025-05-01 6.1 Medium
The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-4529 1 Esterox 1 Business Card 2025-05-01 5.0 Medium
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting card categories via CSRF attacks
CVE-2024-4530 1 Esterox 1 Business Card 2025-05-01 6.3 Medium
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing card categories via CSRF attacks
CVE-2024-4531 1 Esterox 1 Business Card 2025-05-01 7.1 High
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing cards via CSRF attacks
CVE-2024-4532 1 Esterox 1 Business Card 2025-05-01 6.4 Medium
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting cards via CSRF attacks
CVE-2023-6444 1 Castos 1 Seriously Simple Podcasting 2025-05-01 5.3 Medium
The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.
CVE-2023-7247 1 Wp-buy 1 Login As User Or Customer \(user Switching\) 2025-05-01 4.9 Medium
The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site.
CVE-2024-0561 2 Inisev, Themecheck 2 Ultimate Posts Widget, Ultimate Posts Widget 2025-05-01 5.4 Medium
The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-1068 1 Ajexperience 1 404 Solution 2025-05-01 7.2 High
The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins.
CVE-2024-1273 1 Squirrly 1 Starbox 2025-05-01 6.1 Medium
The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
CVE-2024-4957 1 J-breuer 1 Frontend Checklist 2025-04-30 4.3 Medium
The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-4959 2 J-breuer, Jonas Breuer 2 Frontend Checklist, Frontend Checklist 2025-04-30 4.8 Medium
The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-3632 1 Digitialpixies 1 Oauth Client 2025-04-30 6.5 Medium
The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions.
CVE-2022-3477 3 Newsmag Project, Newspaper Project, Tagdiv Composer Project 3 Newsmag, Newspaper, Tagdiv Composer 2025-04-30 9.8 Critical
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
CVE-2022-3415 1 Bluecoral 1 Chat Bubble 2025-04-30 6.1 Medium
The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unauthenticated attackers to set Stored Cross-Site Scripting payloads in them, which will trigger when an admin view the related contact message
CVE-2022-2450 1 Resmush.it 1 Resmush.it Image Optimizer 2025-04-30 4.3 Medium
The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.
CVE-2022-2449 1 Resmush.it 1 Resmush.it Image Optimizer 2025-04-30 6.5 Medium
The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF checks for any of its AJAX actions, allowing an attackers to trick logged in users to perform various actions on their behalf on the site.
CVE-2015-4582 1 Thecartpress 1 Boot Store 2025-04-30 7.2 High
The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.
CVE-2024-13874 1 Feedify 1 Web Push Notifications 2025-04-30 7.1 High
The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin