Latest CVE Feed
-
4.3
MEDIUMCVE-2024-0900
The Elespare – Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding Skills Required! plugin for WordPress is vulnerable to unauthorized post creation due to a missing capability check on the elespare_cr... Read more
Affected Products :- Published: Apr. 23, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32687
Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce.This issue affects WPC Frequently Bought Together for WooCommerce: from n/a through 7.0.3. ... Read more
Affected Products : wpc_product_bundles_for_woocommerce wpc_frequently_bought_together_for_woocommerce- Published: Apr. 22, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-3607
The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with sub... Read more
Affected Products : propertyhive- Published: May. 02, 2024
- Modified: Feb. 04, 2025
-
4.3
MEDIUMCVE-2024-0595
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes ... Read more
Affected Products : awesome_support- Published: Feb. 10, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1406
A vulnerability was found in Linksys WRT54GL 4.30.18. It has been declared as problematic. This vulnerability affects unknown code of the file /SysInfo1.htm of the component Web Management Interface. The manipulation leads to information disclosure. The e... Read more
- Published: Feb. 10, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-7469
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.... Read more
Affected Products : jazz_reporting_service- Published: Jan. 17, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2025-3949
The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'seedprod_lite_get_revisisons' function in... Read more
Affected Products : website_builder_by_seedprod- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-24837
Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joomla to WordPress.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.44.3; FG Dr... Read more
Affected Products : fg_drupal- Published: Feb. 21, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1898
Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notifications settings configured by an administrator. ... Read more
Affected Products : devolutions_server- Published: Mar. 05, 2024
- Modified: Mar. 14, 2025
-
4.3
MEDIUMCVE-2024-20937
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC). Supported versions that are affected are Prior to 9.2.8.1. Easily exploitable vulnerability allows low privileged attacker with ... Read more
Affected Products : jd_edwards_enterpriseone_tools- Published: Feb. 17, 2024
- Modified: Mar. 27, 2025
-
4.3
MEDIUMCVE-2024-32162
CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.... Read more
Affected Products : cmseasy- Published: Apr. 17, 2024
- Modified: Apr. 14, 2025
-
4.3
MEDIUMCVE-2024-0511
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the wpr_update_form_action_meta function. This ... Read more
Affected Products : royal_elementor_addons- Published: Feb. 08, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-7196
The Ultimate Noindex Nofollow Tool WordPress plugin through 1.1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : ultimate_noindex_nofollow_tool- Published: May. 15, 2025
- Modified: Jun. 11, 2025
-
4.3
MEDIUMCVE-2024-3825
Versions of the BlazeMeter Jenkins plugin prior to 4.22 contain a flaw which results in credential enumeration ... Read more
Affected Products :- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32517
Missing Authorization vulnerability in WooCommerce & WordPress Tutorials Custom Thank You Page Customize For WooCommerce by Binary Carpenter.This issue affects Custom Thank You Page Customize For WooCommerce by Binary Carpenter: from n/a through 1.4.12. ... Read more
Affected Products :- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-1530
The Tripetto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.9. This is due to missing nonce validation. This makes it possible for unauthenticated attackers to delete arbitrary results via a forg... Read more
Affected Products : tripetto- Published: Mar. 15, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-31219
Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site via `whispers_allowed_groups` and reactions are made on whispers on public topics, the contents of the whisper and the reaction data a... Read more
Affected Products : discourse_reactions- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-31383
Cross-Site Request Forgery (CSRF) vulnerability in Pagelayer PopularFX.This issue affects PopularFX: from n/a through 1.2.4. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-31940
Cross-Site Request Forgery (CSRF) vulnerability in RedNao Extra Product Options Builder for WooCommerce.This issue affects Extra Product Options Builder for WooCommerce: from n/a through 1.2.104. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-31427
Cross-Site Request Forgery (CSRF) vulnerability in Marker.Io Marker.Io.This issue affects Marker.Io : from n/a through 1.1.8. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024