CVE-2024-13791 |
Description: Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
CVSS: MEDIUM (4.9) EPSS Score: 0.06%
February 15th, 2025 (4 months ago)
|
CVE-2024-13735 |
Description: The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.11.2 due to insufficient input sanitization and output escaping of a campaign name. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS: MEDIUM (6.4) EPSS Score: 0.05%
February 15th, 2025 (4 months ago)
|
CVE-2024-13692 |
Description: The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 via several functions due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to overwrite linked refund image attachments, overwrite refund request message, overwrite order messages, and read order messages of other users.
CVSS: MEDIUM (5.4) EPSS Score: 0.06%
February 15th, 2025 (4 months ago)
|
CVE-2024-13641 |
Description: The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the 'attachment' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/attachment directory which can contain file attachments for order refunds.
CVSS: MEDIUM (5.9) EPSS Score: 0.06%
February 15th, 2025 (4 months ago)
|
CVE-2024-13493 |
Description: The Sensly Online Presence WordPress plugin through 0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVSS: MEDIUM (4.8) EPSS Score: 0.04%
February 15th, 2025 (4 months ago)
|
CVE-2025-26582 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in Blackbam TinyMCE Advanced qTranslate fix editor problems allows Stored XSS. This issue affects TinyMCE Advanced qTranslate fix editor problems: from n/a through 1.0.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-26580 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in CompleteWebResources Page/Post Specific Social Share Buttons allows Stored XSS. This issue affects Page/Post Specific Social Share Buttons: from n/a through 2.1.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-26578 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in mathieuhays Simple Documentation allows Stored XSS. This issue affects Simple Documentation: from n/a through 1.2.8.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-26577 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in daxiawp DX-auto-publish allows Stored XSS. This issue affects DX-auto-publish: from n/a through 1.2.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|
CVE-2025-26574 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moch Amir Google Drive WP Media allows Stored XSS. This issue affects Google Drive WP Media: from n/a through 2.4.4.
CVSS: MEDIUM (6.5) EPSS Score: 0.04%
February 14th, 2025 (4 months ago)
|