| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. |
| Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions. |
| The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the site's stored third-party API key and authentication tokens in cleartext, despite those secrets being restricted to administrators everywhere else. |
| Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. |
| Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. |
| Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. |
| Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. |
| Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. |
| Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. |
| Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. |
| Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. |
| Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions. |
| Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. |
| Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. |
| The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13's premium licensing state and erase the stored license key. |
| Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed. Apps are only affected if they make net requests to attacker-influenced URLs with redirects followed and expose the response body. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3. |