| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions. |
| Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. |
| Author SQL Injection in Quiz Cat <= 3.1.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. |
| Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. |
| Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. |
| Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. |
| Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. |
| Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. |
| The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting. |
| The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators. |
| The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository. |
| Administrator SQL Injection in WP Activity Log <= 5.6.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. |
| A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. |
| A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of the argument command/shell leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. |