| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. |
| Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions. |
| Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions. |
| Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. |
| Author SQL Injection in Quiz Cat <= 3.1.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. |
| Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions. |
| Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. |
| Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. |
| Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. |
| Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. |
| Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. |
| Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. |
| The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed. |
| Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. |
| The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it. |
| The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content. |