| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers. |
| Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. |
| ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with an arbitrary `credential_id`. The endpoint does not enforce client scoping or object-level authorization before loading and decrypting the credential record. Version 26.05 fixes the issue. |
| Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. |
| Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions. |
| Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. |
| Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions. |
| Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. |
| Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions. |
| Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. |
| Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. |
| Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. |
| Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions. |
| Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. |
| Contributor Broken Access Control in Style Kits <= 2.6.5 versions. |
| Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion. |
| Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. |
| Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. |
| Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. |
| Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. |