CVE-2024-1389 |
Description: The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pms_stripe_connect_handle_authorization_return function in all versions up to, and including, 2.11.1. This makes it possible for unauthenticated attackers to change the Stripe payment keys.
CVSS: MEDIUM (5.3) EPSS Score: 0.24% SSVC Exploitation: none
April 24th, 2025 (2 months ago)
|
CVE-2024-0791 |
Description: The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing capability check on the wpbe_create_new_term, wpbe_update_tax_term, and wpbe_delete_tax_term functions in all versions up to, and including, 1.0.8.1. This makes it possible for authenticated attackers, with subscriber access or higher, to create, delete or modify taxonomy terms.
CVSS: MEDIUM (4.3) EPSS Score: 0.13% SSVC Exploitation: none
April 24th, 2025 (2 months ago)
|
CVE-2024-0660 |
Description: The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. This is due to missing or incorrect nonce validation on the update_settings function. This makes it possible for unauthenticated attackers to change form settings and add malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS: MEDIUM (6.1) EPSS Score: 0.1% SSVC Exploitation: none
April 24th, 2025 (2 months ago)
|
CVE-2024-0595 |
Description: The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve user data such as emails.
CVSS: MEDIUM (4.3) EPSS Score: 0.08% SSVC Exploitation: none
April 24th, 2025 (2 months ago)
|
CVE-2024-0366 |
Description: The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.7 via the action function due to missing validation on a user controlled key. This makes it possible for subscribers to view plugin preferences and potentially other user settings.
CVSS: MEDIUM (4.3) EPSS Score: 0.26% SSVC Exploitation: none
April 24th, 2025 (2 months ago)
|
CVE-2024-0169 |
Description: Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
CVSS: MEDIUM (5.7) EPSS Score: 0.38% SSVC Exploitation: none
April 24th, 2025 (2 months ago)
|
CVE-2024-0010 |
Description: A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.
CVSS: MEDIUM (4.3) EPSS Score: 2.13% SSVC Exploitation: none
April 24th, 2025 (2 months ago)
|
CVE-2025-46417 |
Description: The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.
CVSS: MEDIUM (6.8) EPSS Score: 0.02% SSVC Exploitation: poc
April 24th, 2025 (2 months ago)
|
CVE-2025-29568 |
Description: A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects some unknown features in the file /Scheduling/pages/class_sched.php. Manipulating the class parameter can lead to cross-site scripting (XSS).
CVSS: MEDIUM (4.8) EPSS Score: 0.03%
April 24th, 2025 (2 months ago)
|
CVE-2025-30409 |
Description: Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904.
CVSS: MEDIUM (5.5) EPSS Score: 0.02% SSVC Exploitation: none
April 24th, 2025 (2 months ago)
|