Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2023-32798
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in 10up Simple Page Ordering allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Page Ordering: from n/a through 2.5.0.
0
Attacker Value
Unknown
CVE-2024-10786
Disclosure Date: November 16, 2024 (last updated November 16, 2024)
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versions up to, and including, 2.7.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear user caches.
0
Attacker Value
Unknown
CVE-2024-43116
Disclosure Date: August 26, 2024 (last updated September 19, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10.
0
Attacker Value
Unknown
CVE-2024-35684
Disclosure Date: June 08, 2024 (last updated July 19, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in 10up ElasticPress.This issue affects ElasticPress: from n/a through 5.1.1.
0
Attacker Value
Unknown
CVE-2023-48753
Disclosure Date: June 04, 2024 (last updated June 04, 2024)
Authentication Bypass by Spoofing vulnerability in 10up Restricted Site Access allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Restricted Site Access: from n/a through 7.4.1.
0
Attacker Value
Unknown
CVE-2021-4405
Disclosure Date: July 01, 2023 (last updated November 09, 2023)
The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on the epio_send_autosuggest_allowed() function. This makes it possible for unauthenticated attackers to send allowed parameters for autosuggest to elasticpress[.]io via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2022-1613
Disclosure Date: September 26, 2022 (last updated October 08, 2023)
The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations.
0
Attacker Value
Unknown
CVE-2022-1091
Disclosure Date: April 18, 2022 (last updated October 07, 2023)
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks).
0
Attacker Value
Unknown
CVE-2019-18855
Disclosure Date: November 11, 2019 (last updated October 25, 2023)
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.
0
Attacker Value
Unknown
CVE-2019-18854
Disclosure Date: November 11, 2019 (last updated October 25, 2023)
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.
0