| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. |
| Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. |
| The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. |
| Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions. |
| Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID. |
| Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. |
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3.
Users are recommended to upgrade to version 1.6.4, which fixes the issue. |
| Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions. |
| Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions. |
| The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to, and including, 1.3.1. This is due to a lack of authentication and authorization checks in the 'handle_checkout_redirecturl_response' function. This makes it possible for unauthenticated attackers to cancel arbitrary WooCommerce orders by sending a crafted request with a valid order ID. |
| Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. |
| A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet. |
| Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. |
| Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. |
| Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. |
| Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. |