| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. |
| Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions. |
| Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. |
| Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. |
| Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. |
| Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. |
| Contributor Broken Access Control in Style Kits <= 2.6.5 versions. |
| Administrator PHP Object Injection in Complianz <= 7.5.0 versions. |
| The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
| Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. |
| Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. |
| Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions. |
| The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
| Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. |
| Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions. |
| Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. |