| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. |
| Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. |
| Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
| Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
| Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions. |
| Subscriber SQL Injection in Tainacan <= 1.2.0 versions. |
| Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions. |
| Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions. |
| Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions. |
| Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. |
| Contributor SQL Injection in WP EasyCart <= 5.9.4 versions. |
| Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions. |
| Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions. |
| The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up to, and including, 2.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. WordPress core applies wp_unslash() to the 'log' POST value before dispatching the wp_login_failed action, stripping magic-quotes backslash escaping and allowing a raw single quote to reach the plugin's handler unimpeded. |
| The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to take over another guest author's forum post and modify its title, body, author name, and stored owner email address. This requires that guest posting and editing are enabled on the forum, and that the attacker knows the target guest author's email address. |
| The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unauthenticated attackers can seed the translation dictionary's original column with executable HTML because the front-end rendering pipeline decodes entity-encoded payloads via html_entity_decode() before persistence, and the original column is deliberately exempt from kses filtering — meaning no save-time sanitizer neutralizes the stored payload before it is later rendered in an administrator's session. |
| Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0. |
| The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.7 via the tutor_quiz_builder_save AJAX action due to missing validation that nested question_id, answer_id, deleted_question_ids[], and deleted_answer_ids[] values in the submitted payload belong to a quiz/topic/course the requester is authorized to manage. The handler only validates the top-level course_id, topic_id, and (when supplied) payload['ID'], but the nested identifiers are passed straight into $wpdb->update/DELETE statements in QuizBuilder::save_questions(), QuizBuilder::save_question_answers(), and QuizBuilder::handle_delete(). This makes it possible for authenticated attackers, with Instructor-level access and above, to overwrite the content and re-parent arbitrary quiz questions/answers belonging to other instructors or administrators, and to delete arbitrary quiz question and answer rows. |