Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2024-37242

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Automattic Newspack Newsletters allows Cross Site Request Forgery.This issue affects Newspack Newsletters: from n/a through 2.13.2.
0
Attacker Value
Unknown

CVE-2024-43968

Disclosure Date: November 01, 2024 (last updated November 09, 2024)
Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack: from n/a through 3.8.6.
Attacker Value
Unknown

CVE-2024-37477

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Automattic Newspack Content Converter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack Content Converter: from n/a through 0.1.5.
0
Attacker Value
Unknown

CVE-2024-37475

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Automattic Newspack Newsletters allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Newspack Newsletters: from n/a through 2.13.2.
0
Attacker Value
Unknown

CVE-2024-37425

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Automattic Newspack Blocks newspack-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack Blocks: from n/a through 3.0.8.
0
Attacker Value
Unknown

CVE-2024-37423

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic Newspack Blocks allows Path Traversal.This issue affects Newspack Blocks: from n/a through 3.0.8.
0
Attacker Value
Unknown

CVE-2024-37115

Disclosure Date: July 10, 2024 (last updated July 11, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affects Newspack Blocks: from n/a through 3.0.8.
0
Attacker Value
Unknown

CVE-2024-37424

Disclosure Date: July 09, 2024 (last updated July 09, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Automattic Newspack Blocks allows Upload a Web Shell to a Web Server.This issue affects Newspack Blocks: from n/a through 3.0.8.
0
Attacker Value
Unknown

CVE-2024-37474

Disclosure Date: July 04, 2024 (last updated August 01, 2024)
Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1.
Attacker Value
Unknown

CVE-2024-37476

Disclosure Date: July 04, 2024 (last updated November 02, 2024)
Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack Campaigns: from n/a through 2.31.1.