Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2024-37204
Disclosure Date: November 01, 2024 (last updated January 30, 2025)
Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9.
0
Attacker Value
Unknown
CVE-2024-8490
Disclosure Date: September 17, 2024 (last updated September 28, 2024)
The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for unauthenticated attackers to edit the name, email address, and password of an administrator account via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-35701
Disclosure Date: June 08, 2024 (last updated August 30, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.13.
0
Attacker Value
Unknown
CVE-2024-34381
Disclosure Date: May 06, 2024 (last updated February 01, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10.
0
Attacker Value
Unknown
CVE-2024-3607
Disclosure Date: May 02, 2024 (last updated February 05, 2025)
The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts
0
Attacker Value
Unknown
CVE-2024-27985
Disclosure Date: April 11, 2024 (last updated January 29, 2025)
Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9.
0
Attacker Value
Unknown
CVE-2024-29923
Disclosure Date: March 27, 2024 (last updated February 01, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8.
0
Attacker Value
Unknown
CVE-2024-24718
Disclosure Date: March 26, 2024 (last updated February 01, 2025)
Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.
0
Attacker Value
Unknown
CVE-2024-23513
Disclosure Date: February 12, 2024 (last updated October 09, 2024)
Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.
0
Attacker Value
Unknown
CVE-2023-22706
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions.
0