Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

WordPress Adivaha Travel 2.3 Cross Site Scripting

WordPress Adivaha Travel plugin version 2.3 suffers from a cross site scripting vulnerability.

Packet Storm
#sql#xss#vulnerability#web#windows#wordpress#auth#ssh
WordPress EventON Calendar 4.4 Insecure Direct Object Reference

WordPress EventON Calendar plugin version 4.4 suffers from an insecure direct object reference vulnerability.

WordPress Ninja Forms 3.6.25 Cross Site Scripting

WordPress Ninja Forms plugin version 3.6.25 suffers from a cross site scripting vulnerability.

CVE-2023-4142: WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Execution — Wordfence Intelligence

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to execute code on the server. The author resolved this vulnerability by removing the ability for authors and editors to import files, please note that this means remote code execution is still possible for site administrators, use the plugin with caution.

CVE-2023-4141: Changeset 2944635 for wp-ultimate-csv-importer/trunk/wp-ultimate-csv-importer.php – WordPress Plugin Repository

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to create a PHP file and execute code on the server. The author resolved this vulnerability by removing the ability for authors and editors to import files, please note that this means php file creation is still allowed for site administrators, use the plugin with caution.

CVE-2023-4139: WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listing — Wordfence Intelligence

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction in export folder indexing in versions up to, and including, 7.9.8. This makes it possible for unauthenticated attackers to list and view exported files.

WordPress Adivaha Travel 2.3 SQL Injection

WordPress Adivaha Travel plugin version 2.3 suffers from a remote SQL injection vulnerability.

CVE-2023-4067: Bus Ticket Booking with Seat Reservation <= 5.2.3 - Reflected Cross-Site Scripting — Wordfence Intelligence

The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

WordPress Stripe Payment Plugin For WooCommerce 3.7.7 Authentication Bypass

WordPress Stripe Payment Plugin for WooCommerce plugin versions 3.7.7 and below suffer from an authentication bypass vulnerability.

CVE-2023-3345

The LMS by Masteriyo WordPress plugin before 1.6.8 does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints.