| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped. |
| The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget chain reaches a database query that is built without parameterisation, so an unauthenticated attacker can read arbitrary database data (e.g. user password hashes, secret keys) when the booking is later loaded. |
| Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions. |
| The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. |
| The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings. |
| The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar. |
| The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3. |
| Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions. |
| Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. |
| Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. |
| Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. |
| Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions. |
| Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. |
| Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. |
| Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions. |
| Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. |
| Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. |
| Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. |