| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions. |
| Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions. |
| Unauthenticated Local File Inclusion in Måne <= 1.7 versions. |
| Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. |
| Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. |
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. |
| Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. |
| Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. |
| Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. |
| The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The base64-encoded file contents are embedded into the cached invoice HTML and served directly to the attacker via the plugin's own Print/Download invoice endpoints, which require only a valid nonce and access key. |
| Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. |
| Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions. |
| Author SQL Injection in FluentCRM Pro <= 3.1.12 versions. |
| Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions. |