CVE/PSC | Application | Date | Affected versions | Description |
---|---|---|---|---|
Actual on: Mar 10, 2025, 21:03:41 | ||||
vulnerable
|
Mar 10, 2025, 16:03:29 |
Min -
Max 1.5.4
|
The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_options and reset_widgets functions in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify plugin settings or reset plugin widgets to their default state (all enabled). NOTE: This vulnerability was partially fixed in version 1.5.3. | |
Page Builder: Pagelayer – Drag and Drop website builder
vulnerable
|
Mar 10, 2025, 16:03:18 |
Min -
Max 1.9.9
|
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validation on the pagelayer_save_post function. This makes it possible for unauthenticated attackers to modify post contents via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link. | |
vulnerable
|
Mar 09, 2025, 19:03:54 |
Min -
Max 1.0.9
|
The Shortcode Cleaner Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_backup() function in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export arbitrary options. | |
All-in-One Addons for Elementor – WidgetKit
vulnerable
|
Mar 09, 2025, 18:03:31 |
Min -
Max 2.5.4
|
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.4 in elements/advanced-tab/template/view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data. | |
vulnerable
|
Mar 09, 2025, 18:03:27 |
Min -
Max 1.2.0
|
The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. | |
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn)
vulnerable
|
Mar 09, 2025, 16:03:55 |
Min -
Max 200.3.9
|
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username and the user does not have an already-existing account for the ... | |
vulnerable
|
Mar 09, 2025, 14:03:59 |
Min -
Max 3.0
|
The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
vulnerable
|
Mar 09, 2025, 14:03:43 |
Min -
Max 1.4.1
|
The Years Since – Timeless Texts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'years-since' shortcode in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels)
vulnerable
|
Mar 09, 2025, 13:03:57 |
Min -
Max 1.6.0
|
The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Icon List" Block in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
vulnerable
|
Mar 09, 2025, 13:03:51 |
Min -
Max 1.0
|
The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0. This is due to allowing PHP code to be entered by all users for whom unfiltered HTML is allowed. This makes it possible for authenticated attackers, with Editor-level access and above, to inject PHP code into posts and pages. |