5.3

CVSS3.1

CVE-2024-11153 - Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blo…

The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.0 via the WordPress core search feature. This makes it possible for unauth…

📅 Published: March 5, 2025, 11:22 a.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.

9.8

CVSS3.1

CVE-2024-11951 - Homey Login Register <= 2.4.0 - Unauthenticated Privilege Escalation in homey_register

The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated pri…

📅 Published: March 5, 2025, 11:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-12281 - Homey <= 2.4.2 - Unauthenticated Privilege Escalation in homey_save_profile

The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creat…

📅 Published: March 5, 2025, 11:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-1702 - Ultimate Member <= 2.10.0 - Unauthenticated SQL Injection via search Parameter

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 2.10.0 due to insufficient escaping on the user supplied…

📅 Published: March 5, 2025, 11:22 a.m. 🔄 Last Modified: April 21, 2026, 10:15 p.m.

5.3

CVSS3.1

CVE-2024-13423 - Sparkling <= 2.4.9 - Missing Authorization to Unauthenticated Arbitrary Plugin Activation/Deactivat…

The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions up to, and including, 2.4.9. This makes it possible for unauthenticated attacke…

📅 Published: March 5, 2025, 11:22 a.m. 🔄 Last Modified: April 8, 2026, 5:17 p.m.

7.5

CVSS3.1

CVE-2024-13471 - DesignThemes Core Features <= 4.7 - Missing Authorization to Unauthenticated Arbitrary File Read vi…

The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in all versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to read arbitrary files on the …

📅 Published: March 5, 2025, 11:22 a.m. 🔄 Last Modified: April 8, 2026, 4:37 p.m.

4.3

CVSS3.1

CVE-2025-1463 - Spreadsheet Integration <= 3.8.2 - Cross-Site Request Forgery to Arbitrary Post Publish

The Spreadsheet Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.2. This is due to improper nonce validation within the class-wpgsi-show.php script. This makes it possible for unauthenticated attackers to publish arbitrary posts,…

📅 Published: March 5, 2025, 11:22 a.m. 🔄 Last Modified: April 22, 2026, 6 p.m.

9.9

CVSS3.1

CVE-2025-25015 - Kibana arbitrary code execution via prototype pollution

Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only exploitable by users th…

📅 Published: March 5, 2025, 9:46 a.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

8.8

CVSS3.1

CVE-2024-13232 - WordPress Awesome Import & Export Plugin - Import & Export WordPress Data <= 4.1.1 - Missing Author…

The WordPress Awesome Import & Export Plugin - Import & Export WordPress Data plugin for WordPress is vulnerable arbitrary SQL Execution and privilege escalation due to a missing capability check on the renderImport() function in all versions up to, and including, 4.1.1. This makes it possible for …

📅 Published: March 5, 2025, 9:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-11731 - Master Slider – Responsive Touch Slider <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site …

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slider shortcode in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possi…

📅 Published: March 5, 2025, 9:21 a.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.
Total resulsts: 349182
Page 6444 of 34,919
« previous page » next page
Filters