| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions. |
| Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions. |
| Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.6 versions. |
| Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. |
| Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup & Restore <= 2.1.2 versions. |
| Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions. |
| Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions. |
| Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions. |
| Unauthenticated Sensitive Data Exposure in Snapshotify – All-in-One Backup & Restore & Migrate <= 1.3.2 versions. |
| CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19. |
| The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable get_autosuggest_values AJAX endpoint is reachable by any Contributor who owns a draft post, as the required fl_ajax_update nonce is emitted into the block editor for any user who can edit a Beaver Builder post type. |
| The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment. |
| Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0. |
| Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13. |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25. |
| Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25. |
| Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7. |
| Missing Authorization vulnerability in Kit Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kit (formerly ConvertKit) for WooCommerce: from n/a through 2.2.0. |