| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator. |
| The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration. |
| The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor. |
| The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured. |
| The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site. |
| Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions. |
| Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Review Schema: 3.1.0. |
| Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2. |
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. |
| Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS.
This issue affects JetEngine: from n/a through 3.8.15.3. |
| Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions. |
| Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. |
| Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. |
| Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions. |
| Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions. |
| Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. |
| Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions. |