Show filters
44 Total Results
Displaying 11-20 of 44
Sort by:
Attacker Value
Unknown

CVE-2023-4800

Disclosure Date: October 16, 2023 (last updated October 20, 2023)
The DoLogin Security WordPress plugin before 3.7.1 does not restrict the access of a widget that shows the IPs of failed logins to low privileged users.
Attacker Value
Unknown

CVE-2023-44995

Disclosure Date: October 10, 2023 (last updated October 13, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in WP Doctor WooCommerce Login Redirect plugin <= 2.2.4 versions.
Attacker Value
Unknown

CVE-2023-4631

Disclosure Date: September 25, 2023 (last updated October 08, 2023)
The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing.
Attacker Value
Unknown

CVE-2023-4549

Disclosure Date: September 25, 2023 (last updated October 08, 2023)
The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.
Attacker Value
Unknown

CVE-2023-4293

Disclosure Date: August 12, 2023 (last updated October 08, 2023)
The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'profile[role]' parameter during a profile update.
Attacker Value
Unknown

CVE-2023-2305

Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2023-1524

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.
Attacker Value
Unknown

CVE-2023-22713

Disclosure Date: May 03, 2023 (last updated October 08, 2023)
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions.
Attacker Value
Unknown

CVE-2023-1809

Disclosure Date: May 02, 2023 (last updated October 08, 2023)
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.
Attacker Value
Unknown

CVE-2022-45836

Disclosure Date: April 18, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.