Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2023-3459: Changeset 2938705 for users-customers-import-export-for-wp-woocommerce – WordPress Plugin Repository

The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop manager-level permissions to change user passwords and potentially take over administrator accounts.

CVE
#web#wordpress#php#auth
CVE-2023-3714: profile-magic-group.php in profilegrid-user-profiles-groups-and-communities/tags/5.4.8/public/partials – WordPress Plugin Repository

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associate_role' parameter, which defines the member's role. This issue was partially patched in version 5.5.2 preventing privilege escalation, however, it was fully patched in 5.5.3.

BloodBank 1.1 SQL Injection

BloodBank version 1.1 suffers from a remote SQL injection vulnerability.

BloodBank 1.1 Cross Site Scripting

BloodBank version 1.1 suffers from a cross site scripting vulnerability.

Carlisting 1.6 Cross Site Scripting

Carlisting version 1.6 suffers from a cross site scripting vulnerability.

Pluck 4.7.18 Remote Code Execution

Pluck version 4.7.18 suffers from a remote code execution vulnerability.

Carlisting 1.6 SQL Injection

Carlisting version 1.6 suffers from a remote SQL injection vulnerability.

RecipePoint 1.9 SQL Injection

RecipePoint version 1.9 suffers from a remote SQL injection vulnerability.

Lawyer CMS 1.6 Cross Site Scripting

Lawyer CMS version 1.6 suffers from a cross site scripting vulnerability.

JobSeeker 1.5 Cross Site Scripting

JobSeeker version 1.5 suffers from a cross site scripting vulnerability.