| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. |
| Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions. |
| Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions. |
| Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. |
| Author SQL Injection in Quiz Cat <= 3.1.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. |
| Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions. |
| Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. |
| Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. |
| Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. |
| Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. |
| Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. |
| Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. |
| The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content. |
| The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting. |
| The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network, files belonging to a different site they have no access to. |