CVE-2024-0902 |
Description: The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVSS: MEDIUM (4.3) EPSS Score: 0.02% SSVC Exploitation: poc
March 26th, 2025 (3 months ago)
|
CVE-2024-2322 |
Description: The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admins delete arbitrary email templates as well as delete and unsubscribe users from abandoned orders via CSRF attacks.
CVSS: MEDIUM (6.8) EPSS Score: 0.04% SSVC Exploitation: poc
March 26th, 2025 (3 months ago)
|
CVE-2024-4382 |
Description: The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks
EPSS Score: 0.02% SSVC Exploitation: none
March 26th, 2025 (3 months ago)
|
CVE-2025-30524 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in origincode Product Catalog allows SQL Injection. This issue affects Product Catalog: from n/a through 1.0.4.
CVSS: CRITICAL (9.3) EPSS Score: 0.04% SSVC Exploitation: none
March 26th, 2025 (3 months ago)
|
CVE-2025-28942 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trust Payments Trust Payments Gateway for WooCommerce allows SQL Injection. This issue affects Trust Payments Gateway for WooCommerce: from n/a through 1.1.4.
CVSS: CRITICAL (9.3) EPSS Score: 0.04% SSVC Exploitation: none
March 26th, 2025 (3 months ago)
|
CVE-2025-28939 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound WP Google Calendar Manager allows Blind SQL Injection. This issue affects WP Google Calendar Manager: from n/a through 2.1.
CVSS: HIGH (8.5) EPSS Score: 0.04% SSVC Exploitation: none
March 26th, 2025 (3 months ago)
|
CVE-2025-28935 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in puzich Fancybox Plus allows Reflected XSS. This issue affects Fancybox Plus: from n/a through 1.0.1.
CVSS: HIGH (7.1) EPSS Score: 0.04% SSVC Exploitation: none
March 26th, 2025 (3 months ago)
|
CVE-2025-28934 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Simple Post Series allows Reflected XSS. This issue affects Simple Post Series: from n/a through 2.4.4.
CVSS: HIGH (7.1) EPSS Score: 0.04% SSVC Exploitation: none
March 26th, 2025 (3 months ago)
|
CVE-2025-28928 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sureshdsk Are you robot google recaptcha for wordpress allows Reflected XSS. This issue affects Are you robot google recaptcha for wordpress: from n/a through 2.2.
CVSS: HIGH (7.1) EPSS Score: 0.04% SSVC Exploitation: none
March 26th, 2025 (3 months ago)
|
CVE-2025-28924 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ZenphotoPress allows Reflected XSS. This issue affects ZenphotoPress: from n/a through 1.8.
CVSS: HIGH (7.1) EPSS Score: 0.04% SSVC Exploitation: none
March 26th, 2025 (3 months ago)
|