Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2023-25481: WordPress Podlove Subscribe Button plugin <= 1.3.7 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versions.

CVE
#csrf#vulnerability#wordpress#auth
CVE-2023-28413: Multiple vulnerabilities in WordPress Plugin "MW WP Form" and "Snow Monkey Forms"

Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.

CVE-2023-28367: VK Blocks / ExUnit の脆弱性について

Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.

CVE-2023-27922: WordPress Plugin "Newsletter" vulnerable to cross-site scripting

Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.

W3 Eden Download Manager 3.2.70 Cross Site Scripting

W3 Eden Download Manager versions 3.2.70 and below suffer from a persistent cross site scripting vulnerability via ShortCode.

CVE-2023-25448: WordPress Archivist – Custom Archive Templates plugin <= 1.7.4 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.

CVE-2023-25447: WordPress ColorWay theme <= 4.2.3 - CSRF Leading to Arbitrary Plugin Activation - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Inkthemescom ColorWay theme <= 4.2.3 versions.

CVE-2023-23797: WordPress Auto YouTube Importer plugin <= 1.0.3 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in SecondLineThemes Auto YouTube Importer plugin <= 1.0.3 versions.

CVE-2022-47167: WordPress Crayon Syntax Highlighter plugin <= 2.8.4 - Cross Site Request Forgery (CSRF) - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Aram Kocharyan Crayon Syntax Highlighter plugin <= 2.8.4 versions.

CVE-2022-47183: WordPress Extra Block Design, Style, CSS for ANY Gutenberg Blocks plugin <= 0.2.6 - Cross Site Request Forgery (CSRF) - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in StylistWP Extra Block Design, Style, CSS for ANY Gutenberg Blocks plugin <= 0.2.6 versions.