5.3
CVE-2023-40332 - WordPress WP-PostRatings plugin <= 1.91 - Rating limit Bypass vulnerability
Improper Control of Interaction Frequency vulnerability in Lester βGaMerZβ Chan WP-PostRatings allows Functionality Misuse.This issue affects WP-PostRatings: from n/a through 1.91.
5.4
CVE-2023-39161 - WordPress Discussion Board plugin <= 2.4.8 - Content Injection vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Discussion Board Discussion Board allows Content Spoofing, Cross-Site Scripting (XSS).This issue affects Discussion Board: from n/a through 2.4.8.
6.5
CVE-2023-38520 - WordPress Pinpoint Booking System plugin <= 2.9.9.3.4 - Parameter Tampering
External Control of Assumed-Immutable Web Parameter vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Functionality Misuse.This issue affects Pinpoint Booking System: from n/a through 2.9.9.3.4.
5.3
CVE-2023-37865 - WordPress IP2Location Country Blocker plugin <= 2.29.1 - IP Bypass Vulnerability vulnerability
Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Download IP2Location Country Blocker: from n/a through 2.29.1.
5.3
CVE-2023-34001 - WordPress Hide My WP Ghost β Security Plugin plugin <= 5.0.25 - Captcha Bypass vulnerability
Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins β WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects Hide My WP Ghost: from n/a through 5.0.25.
9.1
CVE-2023-33930 - WordPress Unlimited Elements For Elementor plugin <= 1.5.66 - Unrestricted Zip Extraction vulnerabiβ¦
Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Code Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.66.
4.3
CVE-2023-28494 - WordPress Contact Form Email plugin <= 1.3.31 - Missing Authorization Leading To Feedback Submissioβ¦
Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31.
6.2
CVE-2024-20887 -
Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary directory.
6.2
CVE-2024-20886 -
Arbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary directory.
5.1
CVE-2024-20885 -
Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to make a call without proper permission.