Show filters
123 Total Results
Displaying 31-40 of 123
Sort by:
Attacker Value
Unknown

CVE-2024-5804

Disclosure Date: July 20, 2024 (last updated January 05, 2025)
The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.13. This is due to missing or incorrect nonce validation on the wpcf7cf_admin_init function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown

CVE-2024-6168

Disclosure Date: July 09, 2024 (last updated January 05, 2025)
The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on several AJAX function. This makes it possible for unauthenticated attackers to invoke this functionality intended for admin users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This enables subscribers to manage field groups, change visibility of items among other things.
0
Attacker Value
Unknown

CVE-2024-6167

Disclosure Date: July 09, 2024 (last updated January 05, 2025)
The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX functions in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke this functionality intended for admin users. This enables subscribers to manage field groups, change visibility of items among other things.
0
Attacker Value
Unknown

CVE-2024-4565

Disclosure Date: June 20, 2024 (last updated July 18, 2024)
The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access
Attacker Value
Unknown

CVE-2024-35728

Disclosure Date: June 10, 2024 (last updated June 13, 2024)
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Themeisle PPOM for WooCommerce allows Code Inclusion.This issue affects PPOM for WooCommerce: from n/a through 32.0.20.
Attacker Value
Unknown

CVE-2024-34762

Disclosure Date: June 10, 2024 (last updated June 11, 2024)
Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows PHP Local File Inclusion.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10.
0
Attacker Value
Unknown

CVE-2024-34761

Disclosure Date: June 10, 2024 (last updated June 11, 2024)
Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows Code Injection.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10.
0
Attacker Value
Unknown

CVE-2024-35661

Disclosure Date: June 09, 2024 (last updated June 13, 2024)
Missing Authorization vulnerability in SoftLab Upload Fields for WPForms.This issue affects Upload Fields for WPForms: from n/a through 1.0.2.
Attacker Value
Unknown

CVE-2024-32081

Disclosure Date: June 09, 2024 (last updated June 13, 2024)
Missing Authorization vulnerability in Websupporter Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05.
Attacker Value
Unknown

CVE-2024-31267

Disclosure Date: June 09, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in WP Desk Flexible Checkout Fields for WooCommerce.This issue affects Flexible Checkout Fields for WooCommerce: from n/a through 4.1.2.