| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. |
| Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. |
| Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. |
| Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. |
| Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data.
This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6. |
| Contributor SQL Injection in MapSVG <= 8.14.0 versions. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS.
This issue affects Hubbub Lite: from n/a through 1.36.3. |
| Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers. |
| Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. |
| Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions. |
| Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. |
| Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. |
| Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions. |
| Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions. |
| The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The required waic-nonce is emitted on the front-end whenever the [waic_form] or [aiwu-form] shortcode is rendered, enabling contributor-level users who can publish shortcodes to obtain a valid nonce and reach the vulnerable AJAX handler, which performs no capability check beyond nonce verification when the shortcodes are not already embedded in a page. |