Total
6931 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-10402 | 1 Wpmudev | 1 Forminator Forms | 2025-02-05 | N/A | 7.5 HIGH |
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to create new or edit existing forms, including updating the default registration role to Administrator on User Registration forms.
|
|||||
| CVE-2023-45101 | 1 Cusrev | 1 Customer Reviews For Woocommerce | 2025-02-05 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customer Reviews for WooCommerce: from n/a through 5.36.0.
|
|||||
| CVE-2023-51692 | 1 Cusrev | 1 Customer Reviews For Woocommerce | 2025-02-05 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.
|
|||||
| CVE-2024-11601 | 1 Wowdevs | 1 Sky Addons For Elementor | 2025-02-05 | N/A | 8.1 HIGH |
|
The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to missing or incorrect nonce validation on the save_options() function. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site via a forged request granted they can trick a site ...
Show More |
|||||
| CVE-2024-11104 | 1 Wowdevs | 1 Sky Addons For Elementor | 2025-02-05 | N/A | 8.1 HIGH |
|
The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the save_options() function in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. P ...
Show More |
|||||
| CVE-2024-10614 | 1 Cusrev | 1 Customer Reviews For Woocommerce | 2025-02-05 | N/A | 4.3 MEDIUM |
|
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up to, and including, 5.61.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel and import or check on the status.
|
|||||
| CVE-2024-3869 | 1 Cusrev | 1 Customer Reviews For Woocommerce | 2025-02-05 | N/A | 4.3 MEDIUM |
|
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.
|
|||||
| CVE-2024-3243 | 1 Cusrev | 1 Customer Reviews For Woocommerce | 2025-02-05 | N/A | 4.3 MEDIUM |
|
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails.
|
|||||
| CVE-2022-45806 | 1 Strategy11 | 1 Formidable Forms | 2025-02-05 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Formidable Forms: from n/a through 5.5.4.
|
|||||
| CVE-2023-47188 | 1 Presstigers | 1 Simple Job Board | 2025-02-05 | N/A | 5.3 MEDIUM |
|
Missing Authorization vulnerability in PressTigers Simple Job Board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Job Board: from n/a through 2.10.5.
|
|||||
| CVE-2023-40003 | 1 Wedevs | 1 Wp Project Manager | 2025-02-05 | N/A | 6.5 MEDIUM |
|
Missing Authorization vulnerability in weDevs WP Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Project Manager: from n/a through 2.6.7.
|
|||||
| CVE-2024-13335 | 1 Templatescoder | 1 Spexo Addons For Elementor | 2025-02-05 | N/A | 4.3 MEDIUM |
|
The Spexo Addons for Elementor – Free Elementor Addons, Widgets and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the tmpcoder_theme_install_func() function in all versions up to, and including, 1.0.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install a theme.
|
|||||
| CVE-2024-24832 | 1 Metagauss | 1 Eventprime | 2025-02-04 | N/A | 8.2 HIGH |
|
Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.
|
|||||
| CVE-2024-13368 | 1 Kainelabs | 1 Youzify | 2025-02-04 | N/A | 4.3 MEDIUM |
|
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the youzify_offer_banner() function in all versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary site options to a value of one.
|
|||||
| CVE-2024-11936 | 1 Mvpthemes | 1 Zox News | 2025-02-04 | N/A | 8.8 HIGH |
|
The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user r ...
Show More |
|||||
| CVE-2024-13370 | 1 Kainelabs | 1 Youzify | 2025-02-04 | N/A | 6.5 MEDIUM |
|
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the save_addon_key_license() function in all versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options to a value of a valid license key.
|
|||||
| CVE-2024-13449 | 1 Ibsofts | 1 Boom Fest | 2025-02-04 | N/A | 5.3 MEDIUM |
|
The Boom Fest plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'bf_admin_action' function in all versions up to, and including, 2.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin settings that change the appearance of the website.
|
|||||
| CVE-2024-49596 | 1 Dell | 1 Wyse Management Suite | 2025-02-04 | N/A | 5.9 MEDIUM |
|
Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and arbitrary file deletion
|
|||||
| CVE-2024-45760 | 1 Dell | 1 Openmanage Server Administrator | 2025-02-04 | N/A | 4.3 MEDIUM |
|
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.
|
|||||
| CVE-2024-6489 | 1 Motopress | 1 Getwid | 2025-02-04 | N/A | 5.3 MEDIUM |
|
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_google_api_key function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to set the MailChimp API key.
|
|||||
| CVE-2024-6491 | 1 Motopress | 1 Getwid | 2025-02-04 | N/A | 4.3 MEDIUM |
|
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mailchimp_api_key_manage function in all versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to set the MailChimp API key.
|
|||||
| CVE-2024-3213 | 1 Relevanssi | 1 Relevanssi | 2025-02-04 | N/A | 5.3 MEDIUM |
|
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to execute expensive queries on the application that could lead into DOS.
|
|||||
| CVE-2024-3607 | 1 Wp-property-hive | 1 Propertyhive | 2025-02-04 | N/A | 4.3 MEDIUM |
|
The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts
|
|||||
| CVE-2024-50967 | 2025-02-04 | N/A | 6.5 MEDIUM | ||
|
The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.
|
|||||
| CVE-2023-1414 | 1 Rextheme | 1 Wp Vr | 2025-02-04 | N/A | 4.3 MEDIUM |
|
The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours
|
|||||
| CVE-2023-49831 | 1 Metagauss | 1 Registrationmagic | 2025-02-04 | N/A | 7.5 HIGH |
|
Missing Authorization vulnerability in Metagauss User Registration Forms RegistrationMagic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through 5.2.3.0.
|
|||||
| CVE-2024-32682 | 1 Bdthemes | 1 Prime Slider | 2025-02-04 | N/A | 7.1 HIGH |
|
Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2.
|
|||||
| CVE-2024-32681 | 1 Bdthemes | 1 Prime Slider | 2025-02-04 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2.
|
|||||
| CVE-2025-22696 | 2025-02-04 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in EmbedPress Document Block – Upload & Embed Docs. This issue affects Document Block – Upload & Embed Docs: from n/a through 1.1.0.
|
|||||
| CVE-2024-13529 | 2025-02-04 | N/A | 6.5 MEDIUM | ||
|
The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'socialv_send_download_file' function in all versions up to, and including, 2.0.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to download arbitrary files from the target system.
|
|||||
| CVE-2024-25935 | 1 Metagauss | 1 Registrationmagic | 2025-02-03 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.2.5.9.
|
|||||
| CVE-2024-33595 | 1 Master-addons | 1 Master Addons | 2025-02-03 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Jewel Theme Master Addons for Elementor.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1.
|
|||||
| CVE-2024-11134 | 2025-02-03 | N/A | 4.3 MEDIUM | ||
|
The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'eventer_export_bookings_csv' function in all versions up to, and including, 3.9.9. This makes it possible for authenticated attackers with subscriber-level permissions or above, to download bookings, which contains customers' personal data.
|
|||||
| CVE-2024-11133 | 2025-02-03 | N/A | 5.3 MEDIUM | ||
|
The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, and including, 3.9.9. This makes it possible for unauthenticated attackers to download event tickets.
|
|||||
| CVE-2024-33912 | 1 Kodezen | 1 Academy Lms | 2025-02-03 | N/A | 7.1 HIGH |
|
Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.
|
|||||
| CVE-2023-33321 | 1 Metagauss | 1 Eventprime | 2025-02-03 | N/A | 5.3 MEDIUM |
|
Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6.
|
|||||
| CVE-2025-24697 | 2025-02-03 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Realwebcare Image Gallery – Responsive Photo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Gallery – Responsive Photo Gallery: from n/a through 1.0.5.
|
|||||
| CVE-2025-24643 | 2025-02-03 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Amento Tech Pvt ltd WPGuppy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WPGuppy: from n/a through 1.1.0.
|
|||||
| CVE-2025-24642 | 2025-02-03 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in theme funda Setup Default Featured Image allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Setup Default Featured Image: from n/a through 1.2.
|
|||||
| CVE-2025-23527 | 2025-02-03 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in Hemnath Mouli WC Wallet allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WC Wallet: from n/a through 2.2.0.
|
|||||