Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Unknown
CVE-2022-3180
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.
0
Attacker Value
Unknown
CVE-2025-24643
Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Missing Authorization vulnerability in Amento Tech Pvt ltd WPGuppy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WPGuppy: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2024-56280
Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Incorrect Privilege Assignment vulnerability in Amento Tech Pvt ltd WPGuppy allows Privilege Escalation.This issue affects WPGuppy: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2024-49222
Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Deserialization of Untrusted Data vulnerability in Amento Tech Pvt ltd WPGuppy allows Object Injection.This issue affects WPGuppy: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2024-9434
Disclosure Date: October 31, 2024 (last updated October 31, 2024)
The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the on__translate_options_page() function. This makes it possible for unauthenticated attackers to inject malicious web scripts and update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2022-1563
Disclosure Date: January 16, 2024 (last updated January 23, 2024)
The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.
0
Attacker Value
Unknown
CVE-2023-23684
Disclosure Date: November 13, 2023 (last updated December 21, 2023)
Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.
0
Attacker Value
Unknown
CVE-2023-25711
Disclosure Date: April 07, 2023 (last updated February 24, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPGlobus WPGlobus Translate Options plugin <= 2.1.0 versions.
0
Attacker Value
Unknown
CVE-2019-25060
Disclosure Date: May 09, 2022 (last updated February 23, 2025)
The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.
0
Attacker Value
Unknown
CVE-2021-39335
Disclosure Date: October 14, 2021 (last updated February 23, 2025)
The WpGenius Job Listing WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/admin/class/class-wpgenious-job-listing-options.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0.2. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
0