| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path. |
| Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1. |
| Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions. |
| Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions. |
| Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions. |
| Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. |
| Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions. |
| Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions. |
| Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions. |
| Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions. |
| Contributor Arbitrary File Deletion in Jobs for WordPress <= 2.8.2 versions. |
| Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions. |
| Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in EduMall <= 4.5.3 versions. |
| Subscriber SQL Injection in Woffice <= 5.4.35 versions. |
| Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Contact Form to DB by BestWebSoft <= 1.7.6 versions. |