| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions. |
| Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. |
| Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions. |
| Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. |
| Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. |
| Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. |
| Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. |
| Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. |
| Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data.
This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6. |
| Contributor SQL Injection in MapSVG <= 8.14.0 versions. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS.
This issue affects Hubbub Lite: from n/a through 1.36.3. |
| Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers. |
| Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. |
| Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions. |
| Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. |