Show filters
29 Total Results
Displaying 1-10 of 29
Sort by:
Attacker Value
Unknown
CVE-2023-29429
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in WPEverest User Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 2.3.2.1.
0
Attacker Value
Unknown
CVE-2024-10028
Disclosure Date: November 06, 2024 (last updated November 09, 2024)
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during the backup process. This makes it possible for unauthenticated attackers to obtain an archive file name and download the site's backup.
0
Attacker Value
Unknown
CVE-2024-37310
Disclosure Date: July 10, 2024 (last updated July 11, 2024)
EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and 2024.6.0.
0
Attacker Value
Unknown
CVE-2023-51377
Disclosure Date: June 14, 2024 (last updated August 08, 2024)
Missing Authorization vulnerability in WPEverest Everest Forms.This issue affects Everest Forms: from n/a through 2.0.3.
0
Attacker Value
Unknown
CVE-2024-4958
Disclosure Date: June 01, 2024 (last updated January 05, 2025)
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_form_action' function in versions up to, and including, 3.2.0.1. This makes it possible for authenticated attackers, with contributor-level permissions and above, to import a registration form with a default user role of administrator. If an administrator approves or publishes a post or page with the shortcode to the imported form, any user can register as an administrator.
0
Attacker Value
Unknown
CVE-2024-3295
Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the profile_pic_remove function in versions up to, and including, 3.1.5. This makes it possible for unauthenticated attackers to delete any media file.
0
Attacker Value
Unknown
CVE-2024-2417
Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the form_save_action() function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the registration form and make the default registration role administrator. This subsequently allows the attacker to register an account as an administrator on the site.
0
Attacker Value
Unknown
CVE-2024-32531
Disclosure Date: April 17, 2024 (last updated April 17, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest themes GuCherry Blog allows Reflected XSS.This issue affects GuCherry Blog: from n/a through 1.1.8.
0
Attacker Value
Unknown
CVE-2024-1812
Disclosure Date: April 09, 2024 (last updated April 10, 2024)
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
0
Attacker Value
Unknown
CVE-2023-27459
Disclosure Date: March 26, 2024 (last updated April 02, 2024)
Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1.
0