Show filters
546 Total Results
Displaying 81-90 of 546
Sort by:
Attacker Value
Unknown

CVE-2022-46846

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Trending/Popular Post Slider and Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trending/Popular Post Slider and Widget: from n/a through 1.5.7.
0
Attacker Value
Unknown

CVE-2024-12309

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.4 via the get_post_status() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to vote on unpublished scheduled posts.
Attacker Value
Unknown

CVE-2024-12156

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
The AI Content Writer, RSS Feed to Post, Autoblogging SEO Help plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 6.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-11709

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ai_post_generator_delete_Post AJAX action in all versions up to, and including, 3.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary pages and posts.
Attacker Value
Unknown

CVE-2023-49835

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Duplicator: from n/a through 2.31.
0
Attacker Value
Unknown

CVE-2023-49754

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Yogesh Pawar, Clarion Technologies Bulk Edit Post Titles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Edit Post Titles: from n/a through 5.0.0.
0
Attacker Value
Unknown

CVE-2023-48750

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elementor Page builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Void Elementor Post Grid Addon for Elementor Page builder: from n/a through 2.1.10.
0
Attacker Value
Unknown

CVE-2023-32094

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Felix Welberg Extended Post Status allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extended Post Status: from n/a through 1.0.19.
0
Attacker Value
Unknown

CVE-2023-31214

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Arul Prasad J WP Quick Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Quick Post Duplicator: from n/a through 2.0.
0
Attacker Value
Unknown

CVE-2023-31073

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Jose Vega Display custom fields in the frontend – Post and User Profile Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display custom fields in the frontend – Post and User Profile Fields: from n/a through 1.2.0.
0