Show filters
95 Total Results
Displaying 71-80 of 95
Sort by:
Attacker Value
Unknown

CVE-2022-36345

Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Plugin <= 2.0.4 versions.
Attacker Value
Unknown

CVE-2023-33326

Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Unauth. Reflected (XSS) Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 2.8.6 versions.
Attacker Value
Unknown

CVE-2023-2548

Disclosure Date: May 16, 2023 (last updated October 08, 2023)
The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers, with administrator-level permissions and above, to change user passwords and potentially take over super-administrator accounts in multisite setup.
Attacker Value
Unknown

CVE-2023-2499

Disclosure Date: May 16, 2023 (last updated October 08, 2023)
The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Attacker Value
Unknown

CVE-2023-0889

Disclosure Date: April 17, 2023 (last updated October 08, 2023)
Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the options to be updated belong to the plugin. As a result, it could allow any authenticated users, such as subscriber, to update arbitrary blog options, such as enabling registration and set the default role to administrator
Attacker Value
Unknown

CVE-2023-0940

Disclosure Date: March 20, 2023 (last updated October 08, 2023)
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones.
Attacker Value
Unknown

CVE-2023-25991

Disclosure Date: March 13, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.
Attacker Value
Unknown

CVE-2021-25059

Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website.
Attacker Value
Unknown

CVE-2022-41791

Disclosure Date: November 17, 2022 (last updated December 22, 2024)
Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.
Attacker Value
Unknown

CVE-2022-3578

Disclosure Date: November 14, 2022 (last updated December 22, 2024)
The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting