| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. |
| Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. |
| Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. |
| Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. |
| Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. |
| Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions. |
| Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. |
| The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
| Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. |
| Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions. |
| Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. |
| Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a malicious AJAX submission overriding field types, removing required flags, and disabling CAPTCHA checks through the nopriv AJAX endpoint to trigger form actions such as email notifications and database storage with unverified, attacker-controlled content. |
| Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions. |
| Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions. |