Total
6931 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-0939 | 1 Dcooperman | 1 Magicform | 2025-02-21 | N/A | 6.3 MEDIUM |
|
The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke those actions in order to delete or view logs, modify forms or modify plugin settings.
|
|||||
| CVE-2024-12825 | 1 Brechtvds | 1 Custom Related Posts | 2025-02-21 | N/A | 5.4 MEDIUM |
|
The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on three AJAX actions in all versions up to, and including, 1.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to search posts and link/unlink relations.
|
|||||
| CVE-2024-13783 | 1 Ncrafts | 1 Formcraft | 2025-02-21 | N/A | 4.3 MEDIUM |
|
The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, and including, 3.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all plugin data which may contain sensitive information from form submissions.
|
|||||
| CVE-2024-33570 | 1 Wpmet | 1 Metform Elementor Contact Form Builder | 2025-02-20 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Wpmet Metform Elementor Contact Form Builder.This issue affects Metform Elementor Contact Form Builder: from n/a through 3.8.3.
|
|||||
| CVE-2021-4375 | 1 Welcart | 1 Welcart E-commerce | 2025-02-20 | N/A | 4.3 MEDIUM |
|
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes it possible for authenticated attackers to download information including WordPress settings, plugin settings, PHP settings and server settings.
|
|||||
| CVE-2021-4355 | 1 Welcart | 1 Welcart E-commerce | 2025-02-20 | N/A | 7.5 HIGH |
|
The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via admin_init hooks in versions up to, and including, 2.2.7. This makes it possible for unauthenticated attackers to download lists of members, products and orders.
|
|||||
| CVE-2024-12296 | 1 Apusthemes | 1 Superio | 2025-02-20 | N/A | 8.8 HIGH |
|
The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'import_page_options' function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration f ...
Show More |
|||||
| CVE-2024-37363 | 2025-02-20 | N/A | 6.5 MEDIUM | ||
|
The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862)
Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, do not correctly perform an authorization check in the data source management service.
When access control checks are incorrectly applied, users can access data or perform actions that they should not be allowed to perform. This can lead to a wide rang ...
Show More |
|||||
| CVE-2023-0335 | 1 Wpvar | 1 Wp Shamsi | 2025-02-19 | N/A | 6.5 MEDIUM |
|
The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment.
|
|||||
| CVE-2023-0336 | 1 Ooohboi Steroids For Elementor Project | 1 Ooohboi Steroids For Elementor | 2025-02-19 | N/A | 6.5 MEDIUM |
|
The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.
|
|||||
| CVE-2024-6458 | 1 Wcproducttable | 1 Woocommerce Product Table | 2025-02-19 | N/A | 6.4 MEDIUM |
|
The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a missing capability check on the wcpt_presets__duplicate_preset_to_table function in all versions up to, and including, 3.5.1. This makes it possible for authenticated attackers with subscriber access and above to change titles of arbitrary posts. Missing sanitization can lead to Stored Cross-Site Scripting when viewed by an admin via the WooCommerce Product Table.
|
|||||
| CVE-2024-13468 | 2025-02-19 | N/A | 7.5 HIGH | ||
|
The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all versions up to, and including, 1.9. This makes it possible for unauthenticated attackers to delete arbitrary posts/pages.
|
|||||
| CVE-2023-27701 | 1 Muyucms | 1 Muyucms | 2025-02-18 | N/A | 8.1 HIGH |
|
MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /database/sqldel.html.
|
|||||
| CVE-2025-27013 | 2025-02-18 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in EPC MediCenter - Health Medical Clinic WordPress Theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MediCenter - Health Medical Clinic WordPress Theme: from n/a through n/a.
|
|||||
| CVE-2025-23684 | 2025-02-18 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in Eugen Bobrowski Debug Tool allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Debug Tool: from n/a through 2.2.
|
|||||
| CVE-2025-22657 | 2025-02-18 | N/A | 7.5 HIGH | ||
|
Missing Authorization vulnerability in Vito Peleg Atarim allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Atarim: from n/a through 4.0.9.
|
|||||
| CVE-2025-22730 | 2025-02-18 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Ksher Ksher allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ksher: from n/a through 1.1.2.
|
|||||
| CVE-2025-22643 | 2025-02-18 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in FameThemes OnePress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OnePress: from n/a through 2.3.11.
|
|||||
| CVE-2024-13639 | 1 Edmonsoft | 1 Read More \& Accordion | 2025-02-18 | N/A | 4.3 MEDIUM |
|
The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the expmDeleteData() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary 'read more' posts.
|
|||||
| CVE-2025-25241 | 2025-02-18 | N/A | 5.4 MEDIUM | ||
|
Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests� which could allow the attacker to access employee information. This leads to low impact on confidentiality, integrity of the application. There is no impact on availability.
|
|||||
| CVE-2025-23187 | 2025-02-18 | N/A | 5.3 MEDIUM | ||
|
Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.
|
|||||
| CVE-2025-1358 | 2025-02-18 | 5.0 MEDIUM | 4.3 MEDIUM | ||
|
A vulnerability classified as problematic was found in Pix Software Vivaz 6.0.10. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2025-26765 | 2025-02-16 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Distance Based Shipping Calculator: from n/a through 2.0.22.
|
|||||
| CVE-2025-22291 | 2025-02-16 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.0.20.
|
|||||
| CVE-2024-27190 | 1 Jeandaviddaviet | 1 Download Media | 2025-02-14 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a through 1.4.2.
|
|||||
| CVE-2025-24692 | 2025-02-14 | N/A | 7.1 HIGH | ||
|
Missing Authorization vulnerability in Michael Revellin-Clerc Bulk Menu Edit allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Menu Edit: from n/a through 1.3.
|
|||||
| CVE-2025-23771 | 2025-02-14 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Murali Push Notification for Post and BuddyPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Push Notification for Post and BuddyPress: from n/a through 2.11.
|
|||||
| CVE-2025-23766 | 2025-02-14 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in ashamil OPSI Israel Domestic Shipments allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OPSI Israel Domestic Shipments: from n/a through 2.6.6.
|
|||||
| CVE-2025-23534 | 2025-02-14 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Mark Winiarski WPLingo allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WPLingo: from n/a through 1.1.2.
|
|||||
| CVE-2025-22702 | 2025-02-14 | N/A | 6.3 MEDIUM | ||
|
Missing Authorization vulnerability in EPC Photography. This issue affects Photography: from n/a through 7.5.2.
|
|||||
| CVE-2025-22698 | 2025-02-14 | N/A | 6.3 MEDIUM | ||
|
Missing Authorization vulnerability in Ability, Inc Accessibility Suite by Online ADA allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Accessibility Suite by Online ADA: from n/a through 4.16.
|
|||||
| CVE-2024-52500 | 2025-02-14 | N/A | 7.2 HIGH | ||
|
Missing Authorization vulnerability in monetagwp Monetag Official Plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Monetag Official Plugin: from n/a through 1.1.3.
|
|||||
| CVE-2024-22257 | 2025-02-13 | N/A | 8.2 HIGH | ||
|
In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to
5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8,
versions 6.2.x prior to 6.2.3, an application is possible vulnerable to
broken access control when it directly uses the AuthenticatedVoter#vote passing a null Authentication parameter.
|
|||||
| CVE-2023-2183 | 1 Grafana | 1 Grafana | 2025-02-13 | N/A | 4.1 MEDIUM |
|
Grafana is an open-source platform for monitoring and observability.
The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a test alert using the API as the API does not check access to this function.
This might enable malicious users to abuse the functionality by sending multiple alert messages to e-mail and Slack, spamming users, prepare Phishing attack or block SMTP server.
Use ...
Show More |
|||||
| CVE-2023-26269 | 1 Apache | 1 James | 2025-02-13 | N/A | 7.8 HIGH |
|
Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a
malicious local user.
Administrators are advised to disable JMX, or set up a JMX password.
Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.
|
|||||
| CVE-2025-21396 | 1 Microsoft | 1 Account | 2025-02-12 | N/A | 8.2 HIGH |
|
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
|
|||||
| CVE-2024-4427 | 1 Comparisonslider | 1 Comparison Slider | 2025-02-12 | N/A | 4.3 MEDIUM |
|
The Comparison Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 1.0.5. This makes it possible for authenticated attackers, with subscriber access or above, to change plugin settings and perform other actions such deleting sliders.
|
|||||
| CVE-2023-0805 | 1 Gitlab | 1 Gitlab | 2025-02-12 | N/A | 4.9 MEDIUM |
|
An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to have access to the public projects of a public group even after being banned from the public group by the owner.
|
|||||
| CVE-2023-4947 | 1 Yanco | 1 Woocommerce Ean Payment Gateway | 2025-02-12 | N/A | 4.3 MEDIUM |
|
The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_ean_data AJAX action in versions up to 6.1.0. This makes it possible for authenticated attackers with contributor-level access and above, to update EAN numbers for orders.
|
|||||
| CVE-2025-26374 | 2025-02-12 | N/A | 6.5 MEDIUM | ||
|
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (users endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to enumerate users via crafted HTTP requests.
|
|||||