Show filters
70 Total Results
Displaying 51-60 of 70
Sort by:
Attacker Value
Unknown
CVE-2024-1389
Disclosure Date: February 29, 2024 (last updated January 28, 2025)
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pms_stripe_connect_handle_authorization_return function in all versions up to, and including, 2.11.1. This makes it possible for unauthenticated attackers to change the Stripe payment keys.
0
Attacker Value
Unknown
CVE-2024-24702
Disclosure Date: February 28, 2024 (last updated February 29, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Restrict: from n/a through 2.5.5.
0
Attacker Value
Unknown
CVE-2024-0682
Disclosure Date: February 28, 2024 (last updated February 07, 2025)
The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.
0
Attacker Value
Unknown
CVE-2024-0965
Disclosure Date: February 08, 2024 (last updated February 15, 2024)
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content.
0
Attacker Value
Unknown
CVE-2024-0909
Disclosure Date: February 03, 2024 (last updated February 09, 2024)
The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.6.2. This is due to insufficient restrictions through the REST API on the posts/pages that protections are being place on. This makes it possible for unauthenticated attackers to access protected content.
0
Attacker Value
Unknown
CVE-2023-6165
Disclosure Date: January 29, 2024 (last updated February 03, 2024)
The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
0
Attacker Value
Unknown
CVE-2023-47668
Disclosure Date: November 23, 2023 (last updated November 30, 2023)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions.
0
Attacker Value
Unknown
CVE-2023-47518
Disclosure Date: November 14, 2023 (last updated November 21, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Matthew Muro Restrict Categories plugin <= 2.6.4 versions.
0
Attacker Value
Unknown
CVE-2023-41861
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Restrict plugin <= 2.2.4 versions.
0
Attacker Value
Unknown
CVE-2023-41039
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling the format string to "read" all objects accessible through recursive attribute lookup and subscription from objects he can access. This can lead to critical information disclosure. With `RestrictedPython`, the format functionality is available via the `format` and `format_map` methods of `str` (and `unicode`) (accessed either via the class or its instances) and via `string.Formatter`. All known versions of `RestrictedPython` are vulnerable. This issue has been addressed in commit `4134aedcff1` which has been included in the 5.4 and 6.2 releases. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0