4.3

CVSS3.1

CVE-2023-3408 - Bricks <= 1.8.1 - Cross-Site Request Forgery via save_settings

The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'save_settings' function. This makes it possible for unauthenticated attackers to modify the theme's settings, including en…

📅 Published: Aug. 17, 2024, 8:37 a.m. 🔄 Last Modified: April 8, 2026, 5:26 p.m.

6.8

CVSS3.1

CVE-2023-5505 - BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal

The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific backup folder. This allows authenticated attackers to store backups in arbitrary folders on the server provided they can be written to by the server. Additionally, def…

📅 Published: Aug. 17, 2024, 8:37 a.m. 🔄 Last Modified: April 8, 2026, 5:10 p.m.

5.4

CVSS3.1

CVE-2023-3409 - Bricks <= 1.8.1 - Cross-Site Request Forgery via reset_settings

The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'reset_settings' function. This makes it possible for unauthenticated attackers to reset the theme's settings via a forged …

📅 Published: Aug. 17, 2024, 8:37 a.m. 🔄 Last Modified: April 8, 2026, 4:37 p.m.

6.1

CVSS3.1

CVE-2023-4604 - Slideshow, Image Slider by 2J <= 1.3.54 - Reflected Cross-Site Scripting via 'post'

The Slideshow, Image Slider by 2J plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post’ parameter in versions up to, and including, 1.3.54 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra…

📅 Published: Aug. 17, 2024, 7:34 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2023-1604 - Short URL <= 1.6.8 - Cross-Site Request Forgery via configuration_page

The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. This is due to missing or incorrect nonce validation on the configuration_page function. This makes it possible for unauthenticated attackers to add and import redirects, includin…

📅 Published: Aug. 17, 2024, 7:34 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2023-4025 - Radio Player <= 2.0.73 - Missing Authorization to Player Update

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update player instances.

📅 Published: Aug. 17, 2024, 7:34 a.m. 🔄 Last Modified: April 8, 2026, 5:01 p.m.

5.3

CVSS3.1

CVE-2023-4730 - LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.3 - Missing Authoriz…

The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to modify a variety of settings. An atta…

📅 Published: Aug. 17, 2024, 7:34 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2023-4507 - Admission AppManager <= 1.0.0 - Reflected Cross-Site Scripting

The Admission AppManager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script…

📅 Published: Aug. 17, 2024, 7:34 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2022-4532 - LOGIN AND REGISTRATION ATTEMPTS LIMIT<= 2.1 - IP Address Spoofing to Protection Mechanism Bypass

The LOGIN AND REGISTRATION ATTEMPTS LIMIT plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply…

📅 Published: Aug. 17, 2024, 7:34 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2023-4024 - Radio Player <= 2.0.73 - Missing Authorization to Player Deletion

The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to delete player instances.

📅 Published: Aug. 17, 2024, 7:34 a.m. 🔄 Last Modified: April 8, 2026, 4:48 p.m.
Total resulsts: 349182
Page 8815 of 34,919
« previous page » next page
Filters