Search Results (18006 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-6723 1 Meowapps 1 Ai Engine 2024-09-27 4.7 Medium
The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.
CVE-2024-6850 1 Majeedraza 1 Carousel Slider 2024-09-27 4.8 Medium
The Carousel Slider WordPress plugin before 2.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVE-2024-7817 2 Michalaugustyniak, Misiek Photo Album 2 Misiek Photo Album, Misiek Photo Album 2024-09-27 6.5 Medium
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users delete arbitrary albums via a CSRF attack
CVE-2024-5170 2 Logo Manager For Enamad, Wp-master 2 Logo Manager For Enamad, Logo Manager For Enamad 2024-09-27 5.7 Medium
The Logo Manager For Enamad WordPress plugin through 0.7.1 does not sanitise and escape in its widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-8043 2 Seanschulte, Wordpress Plugin 2 Vikinghammer Tweet, Vikinghammer Tweet 2024-09-27 5.7 Medium
The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-8051 2 Moc, Wordpress Plugin 2 Special Feed Items, Special Feed Items 2024-09-27 5.7 Medium
The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-7818 2 Michalaugustyniak, Misiek Photo Album 2 Misiek Photo Album, Misiek Photo Album 2024-09-27 6.1 Medium
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-8091 2 Jakesnyder, Jupitercow 2 Enhanced Search Box, Enhanced Search Box 2024-09-27 4.8 Medium
The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-8092 2 Alaingg, Alaingonzalez 2 Accordion Image Menu, Accordion Image Menu 2024-09-27 5.4 Medium
The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-8093 2 Lucas Garcia, Lucasgarcia 2 Posts Reminder, Posts Reminder 2024-09-27 4.8 Medium
The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-7820 2 Elliot, Ilc Thickbox 2 Ilc Thickbox, Ilc Thickbox 2024-09-27 4.3 Medium
The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-7822 2 Gwycon, Quick Code 2 Quick Code, Quick Code 2024-09-27 6.1 Medium
The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-8052 2 Joen, Moc 2 Review Ratings, Review Ratings 2024-09-27 4.8 Medium
The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-8479 1 Webliberty 1 Simple Spoiler 2024-09-27 7.3 High
The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
CVE-2024-5799 2 Cminds, Creativemindssolutions 2 Cm Popup, Cm Pop-up Banners 2024-09-26 4.8 Medium
The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.
CVE-2024-6887 2 Rafflepress, Seedprod 2 Giveaways And Contests By Rafflepress, Rafflepress 2024-09-26 4.8 Medium
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Giveaways settings, which could allow high privilege users such as editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-7766 1 Erichamby 1 Adicon Server 2024-09-26 7.2 High
The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
CVE-2024-7816 2 Adeelraza, Gixaw Chat 2 Gixaw Chat, Gixaw Chat 2024-09-26 6.1 Medium
The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-3163 2 Easy Property Listings, Realestateconnected 2 Easy Property Listings, Easy Property Listings 2024-09-26 4.3 Medium
The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack
CVE-2024-8253 1 Pickplugins 1 Post Grid 2024-09-25 8.8 High
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting what user meta values can be updated and ensuring a form is active. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta to become an administrator.