| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting. |
| Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. |
| Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. |
| Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. |
| Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. |
| Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. |
| Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. |
| Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions. |
| Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. |
| Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions. |
| Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. |
| Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. |
| Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions. |
| Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions. |
| The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the plugin's SMTP configuration, which can be leveraged to intercept all outbound emails from the site (including password reset emails). |