Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2024-9626

Disclosure Date: October 26, 2024 (last updated October 26, 2024)
The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function in versions up to, and including, 1.3.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload attachment files (such as jpg, png, txt, zip), and set the post featured image.
0
Attacker Value
Unknown

CVE-2021-25928

Disclosure Date: April 26, 2021 (last updated February 22, 2025)
Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
Attacker Value
Unknown

CVE-2013-3257

Disclosure Date: June 02, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote attackers to hijack the authentication of users for requests that modify settings via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-3476

Disclosure Date: June 02, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the WordPress Related Posts plugin before 2.6.2 for WordPress allows remote attackers to hijack the authentication of users for requests that change settings via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-3477

Disclosure Date: May 27, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Related Posts by Zemanta plugin before 1.3.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that change settings via unknown vectors.
0
Attacker Value
Unknown

CVE-2014-3843

Disclosure Date: May 22, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown

CVE-2014-2316

Disclosure Date: March 09, 2014 (last updated October 05, 2023)
SQL injection vulnerability in se_search_default in the Search Everything plugin before 7.0.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the s parameter to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-5866

Disclosure Date: November 11, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to read and include arbitrary files via ".." sequences in the file parameter.
0