7.5

CVSS3.1

CVE-2024-56068 - WordPress WP SuperBackup plugin <= 2.3.3 - Subscriber+ PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

๐Ÿ“… Published: Dec. 31, 2024, 12:51 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:22 p.m.

6.5

CVSS3.1

CVE-2024-55991 - WordPress CRM Plugin โ€“ WP-CRM System plugin <= 3.2.9.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-CRM System: from n/a through <= 3.2.9.1.

๐Ÿ“… Published: Dec. 31, 2024, 12:51 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:22 p.m.

6.5

CVSS3.1

CVE-2024-56031 - WordPress Smart Shopify Product plugin <= 1.0.2 - Arbitrary Content Deletion vulnerability

Missing Authorization vulnerability in Yulio Aleman Jimenez Smart Shopify Product smart-shopify-product allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Shopify Product: from n/a through <= 1.0.2.

๐Ÿ“… Published: Dec. 31, 2024, 12:49 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:22 p.m.

0.0

CVE-2024-56067 - WordPress WP SuperBackup plugin <= 2.3.3 - Unauthenticated Backup File Download Vulnerability

Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

๐Ÿ“… Published: Dec. 31, 2024, 12:48 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2023-48775 - WordPress WP CleanFix plugin <= 5.6.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Gfazioli WP Cleanfix allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cleanfix: from n/a through 5.6.2.

๐Ÿ“… Published: Dec. 31, 2024, 12:47 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 4:08 p.m.

4.3

CVSS3.1

CVE-2023-50850 - WordPress Woo Subscriptions plugin < 5.8.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Woo WooCommerce Subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Subscriptions: from n/a before 5.8.0.

๐Ÿ“… Published: Dec. 31, 2024, 12:46 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 4:08 p.m.

9.8

CVSS3.1

CVE-2024-56071 - WordPress Simple Dashboard plugin <= 2.0 - Privilege Escalation vulnerability

Incorrect Privilege Assignment vulnerability in mikeleembruggen Simple Dashboard simple-dashboard allows Privilege Escalation.This issue affects Simple Dashboard: from n/a through <= 2.0.

๐Ÿ“… Published: Dec. 31, 2024, 12:44 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:22 p.m.

9.8

CVSS3.1

CVE-2024-56205 - WordPress AI Magic โ€“ SEO Content Generator & Article Writer plugin <= 1.0.4 - Privilege Escalation โ€ฆ

Incorrect Privilege Assignment vulnerability in SunnyKai AI Magic newsletter-page-redirects allows Privilege Escalation.This issue affects AI Magic: from n/a through <= 1.0.4.

๐Ÿ“… Published: Dec. 31, 2024, 12:43 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:22 p.m.

9.8

CVSS3.1

CVE-2024-13061 - 2100 Technology Electronic Official Document Management System - Authentication Bypass

The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users,โ€ฆ

๐Ÿ“… Published: Dec. 31, 2024, 11:13 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-13069 - SourceCodester Multi Role Login System add-user.php cross site scripting

A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected is an unknown function of the file /endpoint/add-user.php. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The โ€ฆ

๐Ÿ“… Published: Dec. 31, 2024, 10:38 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 8:22 p.m.
Total resulsts: 349182
Page 7323 of 34,919
ยซ previous page ยป next page
Filters