Show filters
64 Total Results
Displaying 11-20 of 64
Sort by:
Attacker Value
Unknown
CVE-2024-7263
Disclosure Date: August 15, 2024 (last updated August 22, 2024)
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an arbitrary Windows library.
The patch released in version 12.1.0.17119 to mitigate CVE-2024-7262 was not restrictive enough. Another parameter was not properly sanitized which leads to the execution of an arbitrary Windows library.
0
Attacker Value
Unknown
CVE-2024-7262
Disclosure Date: August 15, 2024 (last updated August 22, 2024)
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library.
The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document
0
Attacker Value
Unknown
CVE-2024-43165
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rashid87 WPSection allows PHP Local File Inclusion.This issue affects WPSection: from n/a through 1.3.8.
0
Attacker Value
Unknown
CVE-2024-6226
Disclosure Date: July 30, 2024 (last updated July 30, 2024)
The WpStickyBar WordPress plugin through 2.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0
Attacker Value
Unknown
CVE-2024-5765
Disclosure Date: July 30, 2024 (last updated July 30, 2024)
The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
0
Attacker Value
Unknown
CVE-2024-6289
Disclosure Date: July 15, 2024 (last updated July 17, 2024)
The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
0
Attacker Value
Unknown
CVE-2024-2473
Disclosure Date: June 11, 2024 (last updated July 26, 2024)
The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.
0
Attacker Value
Unknown
CVE-2023-49748
Disclosure Date: June 04, 2024 (last updated June 04, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPServeur, NicolasKulka, wpformation WPS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPS Hide Login: from n/a through 1.9.11.
0
Attacker Value
Unknown
CVE-2024-22143
Disclosure Date: January 31, 2024 (last updated February 03, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check.This issue affects WP Spell Check: from n/a through 9.17.
0
Attacker Value
Unknown
CVE-2023-6280
Disclosure Date: December 19, 2023 (last updated December 29, 2023)
An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.
0