Show filters
2,398 Total Results
Displaying 101-110 of 2,398
Sort by:
Attacker Value
Unknown
CVE-2024-5743
Disclosure Date: January 13, 2025 (last updated February 27, 2025)
An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute arbitrary code.
This issue affects Eve Play: through 1.1.42.
0
Attacker Value
Unknown
CVE-2025-22508
Disclosure Date: January 09, 2025 (last updated February 27, 2025)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Roninwp FAT Event Lite allows PHP Local File Inclusion.This issue affects FAT Event Lite: from n/a through 1.1.
0
Attacker Value
Unknown
CVE-2024-12249
Disclosure Date: January 09, 2025 (last updated February 27, 2025)
The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings() function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's CSS settings.
0
Attacker Value
Unknown
CVE-2024-11642
Disclosure Date: January 09, 2025 (last updated February 27, 2025)
The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.4.12 via the 'locate_template' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. The file included must have a .php extension.
0
Attacker Value
Unknown
CVE-2024-12711
Disclosure Date: January 07, 2025 (last updated February 27, 2025)
The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions like bulk_delete_attendees() and bulk_delete_questions() in all versions up to, and including, 2.7.13. This makes it possible for unauthenticated attackers to delete questions and attendees and for authenticated users to update question menu orders.
0
Attacker Value
Unknown
CVE-2025-22362
Disclosure Date: January 07, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Powerfusion WPAchievements Free allows Stored XSS.This issue affects WPAchievements Free: from n/a through 1.2.0.
0
Attacker Value
Unknown
CVE-2024-12324
Disclosure Date: January 07, 2025 (last updated February 27, 2025)
The Unilevel MLM Plan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-56251
Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Event Espresso Event Espresso 4 Decaf allows Cross Site Request Forgery.This issue affects Event Espresso 4 Decaf: from n/a through 5.0.28.decaf.
0
Attacker Value
Unknown
CVE-2024-38762
Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar Event Tickets allows Cross Site Request Forgery.This issue affects Event Tickets: from n/a through 5.11.0.4.
0
Attacker Value
Unknown
CVE-2024-37518
Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar The Events Calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n/a through 6.5.1.4.
0