Show filters
81 Total Results
Displaying 61-70 of 81
Sort by:
Attacker Value
Unknown
CVE-2017-20086
Disclosure Date: June 23, 2022 (last updated October 07, 2023)
A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely.
0
Attacker Value
Unknown
CVE-2021-32789
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]` endpoint that allows the execution of a read only sql query. There are patches for many versions of this package, starting with version 2.5.16. There are no known workarounds aside from upgrading.
0
Attacker Value
Unknown
CVE-2021-24374
Disclosure Date: June 21, 2021 (last updated February 22, 2025)
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.
0
Attacker Value
Unknown
CVE-2021-24312
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209.
0
Attacker Value
Unknown
CVE-2021-24329
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2021-24209
Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.
0
Attacker Value
Unknown
CVE-2020-8215
Disclosure Date: July 20, 2020 (last updated February 21, 2025)
A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image.
0
Attacker Value
Unknown
CVE-2013-2010
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2013-2009
Disclosure Date: February 07, 2020 (last updated February 21, 2025)
WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution
0
Attacker Value
Unknown
CVE-2013-2008
Disclosure Date: February 07, 2020 (last updated February 21, 2025)
WordPress Super Cache Plugin 1.3 has XSS.
0