Total
6931 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-47709 | 1 Miniorange | 1 Miniorange 2fa | 2025-06-10 | N/A | 6.5 MEDIUM |
|
Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
|
|||||
| CVE-2023-2299 | 1 Vcita | 1 Online Booking \& Scheduling Calendar | 2025-06-10 | N/A | 5.3 MEDIUM |
|
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.2.10 due to a missing capability check on the processAction function. This makes it possible for unauthenticated attackers modify the plugin's settings.
|
|||||
| CVE-2023-2415 | 1 Vcita | 1 Online Booking \& Scheduling Calendar | 2025-06-10 | N/A | 5.4 MEDIUM |
|
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to logout a vctia connected account which would cause a denial of service on the appointment scheduler.
|
|||||
| CVE-2024-32948 | 1 Reputeinfosystems | 1 Armember | 2025-06-09 | N/A | 9.1 CRITICAL |
|
Missing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28.
|
|||||
| CVE-2024-32776 | 1 Apppresser | 1 Apppresser | 2025-06-09 | N/A | 6.5 MEDIUM |
|
Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.
|
|||||
| CVE-2024-34372 | 1 Addonmaster | 1 Post Grid Master | 2025-06-09 | N/A | 5.3 MEDIUM |
|
Missing Authorization vulnerability in AddonMaster Post Grid Master.This issue affects Post Grid Master: from n/a through 3.4.7.
|
|||||
| CVE-2023-48740 | 1 Easysocialfeed | 1 Easy Social Feed | 2025-06-09 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Easy Social Feed Easy Social Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Feed: from n/a through 6.5.1.
|
|||||
| CVE-2023-47841 | 1 Analytify | 1 Analytify - Google Analytics Dashboard | 2025-06-09 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through 5.1.1.
|
|||||
| CVE-2023-47832 | 1 Searchiq | 1 Searchiq | 2025-06-09 | N/A | 5.3 MEDIUM |
|
Missing Authorization vulnerability in searchiq SearchIQ allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a through 4.4.
|
|||||
| CVE-2023-47770 | 1 Muffingroup | 1 Betheme | 2025-06-09 | N/A | 7.6 HIGH |
|
Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1.
|
|||||
| CVE-2023-41953 | 1 Properfraction | 1 Profilepress | 2025-06-09 | N/A | 5.3 MEDIUM |
|
Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1.
|
|||||
| CVE-2023-50882 | 1 Properfraction | 1 Profilepress | 2025-06-09 | N/A | 5.3 MEDIUM |
|
Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.13.2.
|
|||||
| CVE-2023-49835 | 1 Metaphorcreations | 1 Post Duplicator | 2025-06-09 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Duplicator: from n/a through 2.31.
|
|||||
| CVE-2023-48774 | 1 Northernbeacheswebsites | 1 Ideapush | 2025-06-09 | N/A | 5.4 MEDIUM |
|
Missing Authorization vulnerability in Martin Gibson IdeaPush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through n/a.
|
|||||
| CVE-2025-30897 | 1 Analytify | 1 Analytify - Google Analytics Dashboard | 2025-06-09 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.1.
|
|||||
| CVE-2025-24736 | 1 Metaphorcreations | 1 Post Duplicator | 2025-06-09 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post Duplicator: from n/a through 2.35.
|
|||||
| CVE-2025-48998 | 1 Dataease | 1 Dataease | 2025-06-09 | N/A | 8.8 HIGH |
|
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.10. No known workarounds are available.
|
|||||
| CVE-2025-5521 | 1 5kcrm | 1 Wukongcrm | 2025-06-09 | 5.0 MEDIUM | 4.3 MEDIUM |
|
A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/user/updataPassword. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2025-47601 | 2025-06-09 | N/A | 8.8 HIGH | ||
|
Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a through 2.1.0.
|
|||||
| CVE-2025-5814 | 2025-06-09 | N/A | 5.3 MEDIUM | ||
|
The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsd_plugin_control() function in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to reactivate previously deactivated plugins after accessing the "Profiler" page.
|
|||||
| CVE-2025-5894 | 2025-06-09 | N/A | 8.8 HIGH | ||
|
Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attackers with regular privileges to access a specific functionality to create administrator accounts, and subsequently log into the system using those accounts.
|
|||||
| CVE-2025-39493 | 1 Valvepress | 1 Rankie | 2025-06-06 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in ValvePress Rankie allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rankie: from n/a through 1.8.0.
|
|||||
| CVE-2025-26773 | 1 Analytify | 1 Analytify - Google Analytics Dashboard | 2025-06-06 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.0.
|
|||||
| CVE-2024-28159 | 1 Jenkins | 1 Subversion Partial Release Manager | 2025-06-06 | N/A | 4.3 MEDIUM |
|
A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build.
|
|||||
| CVE-2025-1778 | 2025-06-06 | N/A | 4.3 MEDIUM | ||
|
The Art Theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'arttheme_theme_option_restore' AJAX function in all versions up to, and including, 3.12.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete the theme option.
|
|||||
| CVE-2025-5018 | 2025-06-06 | N/A | 7.1 HIGH | ||
|
The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read and overwrite the site’s OpenAI API key and inspection data or modify AI-chat prompts and behavior. This vulnerability is potentially a ...
Show More |
|||||
| CVE-2025-1777 | 2025-06-06 | N/A | 6.4 MEDIUM | ||
|
The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'ux_cb_page_options_save' function in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
|
|||||
| CVE-2025-5486 | 2025-06-06 | N/A | 9.8 CRITICAL | ||
|
The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() function in versions 1.0 to 1.1.0. This makes it possible for unauthenticated attackers to enable debugging and send all emails to an attacker controlled address and then trigger a password reset for an administrator to gain access to an administrator account.
|
|||||
| CVE-2025-49289 | 2025-06-06 | N/A | 5.0 MEDIUM | ||
|
Missing Authorization vulnerability in add-ons.org PDF for WPForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for WPForms: from n/a through 5.5.0.
|
|||||
| CVE-2025-49240 | 2025-06-06 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in nK DocsPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DocsPress: from n/a through 2.5.2.
|
|||||
| CVE-2025-24778 | 2025-06-06 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in De paragon No Spam At All allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects No Spam At All: from n/a through 1.3.
|
|||||
| CVE-2025-28994 | 2025-06-06 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in viralloops Viral Loops WP Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Viral Loops WP Integration: from n/a through 3.8.1.
|
|||||
| CVE-2025-30945 | 2025-06-06 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in taskbuilder Taskbuilder allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Taskbuilder: from n/a through 4.0.3.
|
|||||
| CVE-2025-49441 | 2025-06-06 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in WP Map Plugins Interactive Regional Map of Florida allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Interactive Regional Map of Florida: from n/a through 1.0.
|
|||||
| CVE-2025-28997 | 2025-06-06 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in EXEIdeas International WP AutoKeyword allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP AutoKeyword: from n/a through 1.0.
|
|||||
| CVE-2025-24763 | 2025-06-06 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Pascal Casier bbPress API allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress API: from n/a through 1.0.14.
|
|||||
| CVE-2025-28985 | 2025-06-06 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in Elastic Email Elastic Email Subscribe Form allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elastic Email Subscribe Form: from n/a through 1.2.2.
|
|||||
| CVE-2025-31000 | 2025-06-06 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Miguel Fuentes Payment QR WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Payment QR WooCommerce: from n/a through 1.1.6.
|
|||||
| CVE-2025-49236 | 2025-06-06 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in raychat Raychat allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Raychat: from n/a through 2.1.0.
|
|||||
| CVE-2025-23971 | 2025-06-06 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in whassan KI Live Video Conferences allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects KI Live Video Conferences: from n/a through 5.5.15.
|
|||||