| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions. |
| Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. |
| Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. |
| The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management operations, allowing authenticated users who have been granted file-manager access — which its premium add-on can extend to sub-administrator roles — to upload arbitrary PHP files and achieve remote code execution. This is an incomplete fix of CVE-2024-7985, which only added file-type validation to the upload operation. |
| Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. |
| Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery.
This issue affects MailPoet: from 5.30.0 through 5.33.0. |
| Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. |
| Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions. |
| Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. |
| Contributor Broken Access Control in Style Kits <= 2.6.5 versions. |
| Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. |
| Administrator PHP Object Injection in Complianz <= 7.5.0 versions. |
| The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
| Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. |
| Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. |
| Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. |
| Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. |