Show filters
250 Total Results
Displaying 11-20 of 250
Sort by:
Attacker Value
Unknown
CVE-2024-9939
Disclosure Date: January 08, 2025 (last updated January 09, 2025)
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read files outside of the originally intended directory.
0
Attacker Value
Unknown
CVE-2024-11635
Disclosure Date: January 08, 2025 (last updated January 09, 2025)
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.
0
Attacker Value
Unknown
CVE-2024-11613
Disclosure Date: January 08, 2025 (last updated January 09, 2025)
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined directory path. This makes it possible for unauthenticated attackers to execute code on the server.
0
Attacker Value
Unknown
CVE-2024-12719
Disclosure Date: January 07, 2025 (last updated January 07, 2025)
The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform limited path traversal to view directories and subdirectories in WordPress. Files cannot be viewed.
0
Attacker Value
Unknown
CVE-2024-11930
Disclosure Date: January 04, 2025 (last updated January 05, 2025)
The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppm_tasks shortcode in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-54347
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BAKKBONE Australia FloristPress allows Reflected XSS.This issue affects FloristPress: from n/a through 7.2.0.
0
Attacker Value
Unknown
CVE-2024-53798
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in BAKKBONE Australia FloristPress.This issue affects FloristPress: from n/a through 7.3.0.
0
Attacker Value
Unknown
CVE-2024-53799
Disclosure Date: December 06, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in BAKKBONE Australia FloristPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FloristPress: from n/a through 7.3.0.
0
Attacker Value
Unknown
CVE-2024-51723
Disclosure Date: November 25, 2024 (last updated January 05, 2025)
A Stored Cross-Site Scripting (XSS) vulnerability in the Management Console of BlackBerry AtHoc version 7.15 could allow an attacker to potentially execute actions in the context of the victim's session.
0
Attacker Value
Unknown
CVE-2024-51722
Disclosure Date: November 12, 2024 (last updated November 13, 2024)
A local privilege escalation vulnerability in the SecuSUITE Server (System Configuration) of SecuSUITE versions 5.0.420 and earlier could allow a successful attacker that had gained control of code running under one of the system accounts listed in the configuration file to potentially issue privileged script commands.
0