| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. |
| Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. |
| Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. |
| Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion.
This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1. |
| The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
| The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem allows DOM-Based XSS.
This issue affects TheGem: from n/a before 5.12.1.1. |
| Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal. |
| Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions. |
| Subscriber SQL Injection in Do Lasso <= 358 versions. |
| Subscriber Path Traversal in Do Lasso <= 358 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions. |
| Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. |
| Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. |
| Subscriber SQL Injection in CubeWP <= 1.1.30 versions. |
| Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. |
| Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions. |
| Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions. |