Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2023-32239: WordPress Woodmart theme <= 7.2.1 - Cross-Site Scripting (XSS) vulnerability - Patchstack

Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in xtemos WoodMart theme <= 7.2.1 versions.

CVE
#xss#vulnerability#web#wordpress#auth
CVE-2022-47593: WordPress RapidLoad Power-Up for Autoptimize plugin <= 1.6.35 - SQL Injection - Patchstack

Auth. (subscriber+) SQL Injection (SQLi) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize plugin <= 1.6.35 versions.

CVE-2023-32960: WordPress UpdraftPlus plugin <= 1.23.3 - CSRF lead to wp-admin Site Wide XSS vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sitewide Cross-Site Scripting (XSS).

WordPress BackUpWordPress 3.8 Backup Disclosure

WordPress BackUpWordPress version 3.8 appears to leave backups in a world accessible directory under the document root.

CVE-2023-27452: WordPress Button Generator plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.3 versions.

CVE-2023-26539: WordPress Advanced Text Widget plugin <= 2.1.2 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Chirkov Advanced Text Widget plugin <= 2.1.2 versions.

CVE-2023-28784: WordPress Contest Gallery plugin <= 21.1.2 - Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 21.1.2 versions.

CVE-2023-28778: WordPress Pagination by BestWebSoft <= 1.2.2 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Pagination plugin <= 1.2.2 versions.

CVE-2023-28776: WordPress Continuous Image Carousel With Lightbox plugin <= 1.0.15 - Reflected Cross-Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Continuous Image Carousel With Lightbox plugin <= 1.0.15 versions.

CVE-2023-35093: WordPress MasterStudy LMS plugin <= 3.0.8 - Broken Access Control vulnerability - Patchstack

Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.