| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public. |
| The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs. |
| Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. |
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. |
| Contributor Privilege Escalation in Forminator <= 1.56.0 versions. |
| Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. |
| The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inputPlaceHolder' parameter in all versions up to, and including, 5.0.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
| Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. |
| Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. |
| Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. |
| Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. |
| Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions. |
| Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. |
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. |
| Custom role Broken Access Control in Dokan <= 5.0.10 versions. |
| The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
| The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is possible because Forminator_Core::sanitize_array() skips all filtering for keys prefixed with 'select-', and set_field_data() treats a submitted 'return' member as a trusted internal flag — allowing an unauthenticated attacker to forge and persist a complete upload field record with an arbitrary file_url value without any sanitization or validation. |
| Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. |