Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2022-37402: WordPress AFS Analytics plugin <= 4.18 - Auth. Stored Cross-Site Scripting (XSS) vulnerability - Patchstack

Stored Cross-site Scripting (XSS) vulnerability in AFS Analytics plugin <= 4.18 versions.

CVE
#xss#vulnerability#web#wordpress#auth
CVE-2022-38456: WordPress Ajax Search Lite plugin <= 4.10.3 - Auth. Data Exposure vulnerability - Patchstack

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions.

CVE-2022-34148: WordPress Backup Guard plugin <= 1.6.9.0 - Auth. Stored Cross-Site Scripting (XSS) vulnerability - Patchstack

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JetBackup JetBackup – WP Backup, Migrate & Restore plugin <= 1.6.9.0 versions.

WordPress Profile Builder 3.9.0 Missing Authorization

WordPress Profile Builder plugin versions 3.9.0 and below suffer from a missing authorization vulnerability in wppb_toolbox_usermeta_handler().

Oracle DB Broken PDB Isolation / Metadata Exposure

Proof of concept details for Oracle database versions 12.1.0.2, 12.2.0.1, 18c, and 19c that had a PDB isolation vulnerability allowing viewing of metadata for a different database within the same container.

CVE-2023-25708: WordPress WP VR 360 Panorama and Virtual Tour Builder plugin <= 8.2.7 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Rextheme WP VR – 360 Panorama and Virtual Tour Builder For WordPress plugin <= 8.2.7 versions.

CVE-2023-25968: WordPress Client Portal plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Madalin Ungureanu, Antohe Cristian Client Portal – Private user pages and login plugin <= 1.1.8 versions.

CVE-2023-25709: WordPress Locatoraid Store Locator plugin <= 3.9.11 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.11 versions.

CVE-2022-47427: WordPress My Calendar plugin <= 3.3.24.1 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions.