🚨 CVE-2023-0865
The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete as well as retrieve addresses of other users.
🎖@cveNotify
The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete as well as retrieve addresses of other users.
🎖@cveNotify
WPScan
WooCommerce Multiple Customer Addresses & Shipping < 21.7 - Arbitrary Address Creation/Deletion/Access/Update via IDOR
See details on WooCommerce Multiple Customer Addresses & Shipping < 21.7 - Arbitrary Address Creation/Deletion/Access/Update via IDOR CVE 2023-0865. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2023-0631
The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.
🎖@cveNotify
The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.
🎖@cveNotify
WPScan
Paid Memberships Pro < 2.9.12 - Subscriber+ SQL Injection
See details on Paid Memberships Pro < 2.9.12 - Subscriber+ SQL Injection CVE 2023-0631. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2023-0630
The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query.
🎖@cveNotify
The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query.
🎖@cveNotify
WPScan
Slimstat Analytics < 4.9.3.3 - Subscriber+ SQL Injection
See details on Slimstat Analytics < 4.9.3.3 - Subscriber+ SQL Injection CVE 2023-0630. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2023-0370
The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
WPScan
WPB Advanced FAQ <= 1.0.6 - Contributor+ Stored XSS
See details on WPB Advanced FAQ <= 1.0.6 - Contributor+ Stored XSS CVE 2023-0370. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2023-0369
The GoToWP WordPress plugin through 5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
The GoToWP WordPress plugin through 5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
WPScan
GoToWP <= 5.1.1 - Contributor+ Stored XSS
See details on the GoToWP <= 5.1.1 - Contributor+ Stored XSS. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2023-0365
The React Webcam WordPress plugin through 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
The React Webcam WordPress plugin through 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
WPScan
React Webcam <= 1.2.0 - Contributor+ Stored XSS
See details on React Webcam <= 1.2.0 - Contributor+ Stored XSS CVE 2023-0365. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2023-0364
The real.Kit WordPress plugin before 5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
The real.Kit WordPress plugin before 5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
WPScan
real.Kit < 5.1.1 - Contributor+ Stored XSS
See details on the real.Kit < 5.1.1 - Contributor+ Stored XSS. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2023-0340
The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.
🎖@cveNotify
The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.
🎖@cveNotify
WPScan
Custom Content Shortcode <= 4.0.2 - Contributor+ LFI
See details on Custom Content Shortcode <= 4.0.2 - Contributor+ LFI CVE 2023-0340. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2023-0273
The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
🎖@cveNotify
The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
🎖@cveNotify
WPScan
Custom Content Shortcode <= 4.0.2 - Contributor+ Stored XSS
See details on Custom Content Shortcode <= 4.0.2 - Contributor+ Stored XSS CVE 2023-0273. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2023-0175
The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
WPScan
Smart Logo Showcase Lite <= 1.1.9 - Contributor+ Stored XSS
See details on Smart Logo Showcase Lite <= 1.1.9 - Contributor+ Stored XSS CVE 2023-0175. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2023-0167
The GetResponse for WordPress plugin through 5.5.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
The GetResponse for WordPress plugin through 5.5.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
WPScan
GetResponse for WordPress < 5.5.32 - Contributor+ Stored XSS
See details on GetResponse for WordPress < 5.5.32 - Contributor+ Stored XSS CVE 2023-0167. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2023-0145
The Saan World Clock WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
The Saan World Clock WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
🎖@cveNotify
WPScan
Saan World Clock <= 1.8 - Contributor+ Stored XSS
See details on the Saan World Clock <= 1.8 - Contributor+ Stored XSS. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2022-4148
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
🎖@cveNotify
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
🎖@cveNotify
WPScan
WP OAuth Server < 4.3.0 - Subscriber+ Arbitrary Client Deletion
See details on WP OAuth Server < 4.3.0 - Subscriber+ Arbitrary Client Deletion CVE 2022-4148. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2022-3894
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.
🎖@cveNotify
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.
🎖@cveNotify
WPScan
WP OAuth Server < 4.2.5 - Arbitrary Post Deletion via CSRF
See details on WP OAuth Server < 4.2.5 - Arbitrary Post Deletion via CSRF CVE 2022-3894. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2019-0803
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.
🎖@cveNotify
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.
🎖@cveNotify
🚨 CVE-2023-23404
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
🎖@cveNotify
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
🎖@cveNotify
🚨 CVE-2019-0810
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0812, CVE-2019-0829, CVE-2019-0860, CVE-2019-0861.
🎖@cveNotify
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0812, CVE-2019-0829, CVE-2019-0860, CVE-2019-0861.
🎖@cveNotify
🚨 CVE-2019-0841
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.
🎖@cveNotify
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.
🎖@cveNotify
🚨 CVE-2018-7084
A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system. An attacker could use this ability to copy files, read configuration, write files, delete files, or reboot the device. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.1
🎖@cveNotify
A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system. An attacker could use this ability to copy files, read configuration, write files, delete files, or reboot the device. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.1
🎖@cveNotify