Latest CVE Feed
-
4.3
MEDIUMCVE-2024-13420
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various ver... Read more
- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-11014
Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the manage... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Jul. 23, 2025
-
4.3
MEDIUMCVE-2025-3624
Missing Authorization vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.4-00.... Read more
Affected Products : ops_center_analyzer- Published: May. 16, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-10854
The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buy_one_click_import_options AJAX action in all versions up to, and including, 2.2.9. This makes it possible for... Read more
Affected Products : buy_one_click_woocommerce- Published: Nov. 13, 2024
- Modified: Jan. 17, 2025
-
4.3
MEDIUMCVE-2022-45208
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.... Read more
Affected Products : jeecg_boot- Published: Nov. 25, 2022
- Modified: Apr. 29, 2025
-
4.3
MEDIUMCVE-2014-125054
A vulnerability classified as critical was found in koroket RedditOnRails. This vulnerability affects unknown code of the component Vote Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The patch is identi... Read more
Affected Products : reddit-on-rails- Published: Jan. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-10593
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce validat... Read more
Affected Products : wpforms- Published: Nov. 13, 2024
- Modified: Jul. 10, 2025
-
4.3
MEDIUMCVE-2023-24058
Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014; the latest version of Booked Scheduler is not affected. However, La... Read more
Affected Products : booked- Published: Jan. 22, 2023
- Modified: Apr. 02, 2025
-
4.3
MEDIUMCVE-2025-53293
Missing Authorization vulnerability in Morten Dalgaard Johansen Dashboard Widget Sidebar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Dashboard Widget Sidebar: from n/a through 1.2.3.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2022-45306
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.... Read more
Affected Products : chocolatey_azure-pipelines-agent- Published: Nov. 29, 2022
- Modified: Apr. 25, 2025
-
4.3
MEDIUMCVE-2024-10780
The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.9 via the 'narestaurant_elementor_template' shortcode due to insufficient restrictions on which posts can be inc... Read more
Affected Products : restaurant_\&_cafe_addon_for_elementor- Published: Nov. 28, 2024
- Modified: Jul. 14, 2025
-
4.3
MEDIUMCVE-2024-10670
The Primary Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.2 via the [prim_elementor_template] shortcode due to insufficient restrictions on which posts can be included. This makes ... Read more
Affected Products : primary_addon_for_elementor- Published: Nov. 28, 2024
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-3995
The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-controlled key on the lock_unlock_terawallet AJAX action. This makes it poss... Read more
Affected Products : terawallet- Published: Nov. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-0634
The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the... Read more
Affected Products : thirstyaffiliates_affiliate_link_manager- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-8245
The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-10582
The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_mpfe_template() function in all versions up to, and including, 2.4.1. Th... Read more
Affected Products : music_player_for_elementor- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
4.3
MEDIUMCVE-2025-53327
Cross-Site Request Forgery (CSRF) vulnerability in rui_mashita Aioseo Multibyte Descriptions allows Cross Site Request Forgery. This issue affects Aioseo Multibyte Descriptions: from n/a through 0.0.6.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-10521
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it po... Read more
- Published: Nov. 27, 2024
- Modified: Mar. 19, 2025
-
4.3
MEDIUMCVE-2024-8050
The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : custom_author_base- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-53193
Cross-Site Request Forgery (CSRF) vulnerability in Burst Statistics B.V. Burst Statistics allows Cross Site Request Forgery. This issue affects Burst Statistics: from n/a through 2.0.6.... Read more
Affected Products : burst_statistics- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Cross-Site Request Forgery