CVE-2024-13803 |
Description: The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-marker’ parameter in all versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS: MEDIUM (6.4) EPSS Score: 0.03%
February 26th, 2025 (4 months ago)
|
CVE-2024-12434 |
Description: The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including restricted content.
CVSS: MEDIUM (5.3) EPSS Score: 0.04%
February 26th, 2025 (4 months ago)
|
CVE-2025-27000 |
Description: Missing Authorization vulnerability in George Pattichis Simple Photo Feed allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple Photo Feed: from n/a through 1.4.0.
CVSS: MEDIUM (5.4) EPSS Score: 0.04%
February 25th, 2025 (4 months ago)
|
CVE-2025-26995 |
Description: Missing Authorization vulnerability in Anton Vanyukov Market Exporter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Market Exporter: from n/a through 2.0.21.
CVSS: MEDIUM (5.4) EPSS Score: 0.04%
February 25th, 2025 (4 months ago)
|
CVE-2025-26983 |
Description: Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Recipe Card Blocks for Gutenberg & Elementor: from n/a through 3.4.3.
CVSS: MEDIUM (4.3) EPSS Score: 0.03%
February 25th, 2025 (4 months ago)
|
CVE-2025-26980 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wired Impact Wired Impact Volunteer Management allows Stored XSS. This issue affects Wired Impact Volunteer Management: from n/a through 2.5.
CVSS: MEDIUM (6.5) EPSS Score: 0.03%
February 25th, 2025 (4 months ago)
|
CVE-2025-26975 |
Description: Missing Authorization vulnerability in WP Chill Strong Testimonials allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Strong Testimonials: from n/a through 3.2.3.
CVSS: MEDIUM (5.3) EPSS Score: 0.04%
February 25th, 2025 (4 months ago)
|
CVE-2025-26965 |
Description: Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Amelia: from n/a through 1.2.16.
CVSS: MEDIUM (5.3) EPSS Score: 0.04% SSVC Exploitation: none
February 25th, 2025 (4 months ago)
|
CVE-2025-26963 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in flowdee ClickWhale allows Cross Site Request Forgery. This issue affects ClickWhale: from n/a through 2.4.3.
CVSS: MEDIUM (5.4) EPSS Score: 0.02%
February 25th, 2025 (4 months ago)
|
CVE-2025-26962 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Easy Contact Form Lite allows Stored XSS. This issue affects Easy Contact Form Lite : from n/a through 1.1.25.
CVSS: MEDIUM (6.5) EPSS Score: 0.03%
February 25th, 2025 (4 months ago)
|