| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17. |
| The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been left at its default empty value. |
| The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path. |
| Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1. |
| Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions. |
| Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions. |
| Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions. |
| Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. |
| Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions. |
| Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions. |
| Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions. |
| Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions. |
| Contributor Arbitrary File Deletion in Jobs for WordPress <= 2.8.2 versions. |
| Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions. |
| Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in EduMall <= 4.5.3 versions. |
| Subscriber SQL Injection in Woffice <= 5.4.35 versions. |