Show filters
892 Total Results
Displaying 41-50 of 892
Sort by:
Attacker Value
Unknown
CVE-2024-43974
Disclosure Date: November 01, 2024 (last updated November 09, 2024)
Missing Authorization vulnerability in CozyThemes ReviveNews allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReviveNews: from n/a through 1.0.2.
0
Attacker Value
Unknown
CVE-2024-43968
Disclosure Date: November 01, 2024 (last updated November 09, 2024)
Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack: from n/a through 3.8.6.
0
Attacker Value
Unknown
CVE-2024-37477
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Automattic Newspack Content Converter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack Content Converter: from n/a through 0.1.5.
0
Attacker Value
Unknown
CVE-2024-37475
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Automattic Newspack Newsletters allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Newspack Newsletters: from n/a through 2.13.2.
0
Attacker Value
Unknown
CVE-2024-37468
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in blazethemes Newsmatic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newsmatic: from n/a through 1.3.1.
0
Attacker Value
Unknown
CVE-2024-37425
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Automattic Newspack Blocks newspack-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack Blocks: from n/a through 3.0.8.
0
Attacker Value
Unknown
CVE-2024-37423
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic Newspack Blocks allows Path Traversal.This issue affects Newspack Blocks: from n/a through 3.0.8.
0
Attacker Value
Unknown
CVE-2024-10181
Disclosure Date: October 29, 2024 (last updated October 30, 2024)
The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's newsletters_video shortcode in all versions up to, and including, 4.9.9.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-50435
Disclosure Date: October 28, 2024 (last updated October 29, 2024)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Theme Horse Meta News.This issue affects Meta News: from n/a through 1.1.7.
0
Attacker Value
Unknown
CVE-2024-50434
Disclosure Date: October 28, 2024 (last updated October 29, 2024)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Theme Horse NewsCard.This issue affects NewsCard: from n/a through 1.3.
0