5.3
CVE-2024-35692 - WordPress GDPR/CCPA Cookie Consent Banner plugin <= 3.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Termly Cookie Consent.This issue affects Cookie Consent: from n/a through 3.2.
6.5
CVE-2024-35716 - WordPress Copymatic plugin <= 1.9 - Broken Access Control vulnerability
Missing Authorization vulnerability in Copymatic Copymatic β AI Content Writer & Generator.This issue affects Copymatic β AI Content Writer & Generator: from n/a through 1.9.
4.3
CVE-2023-33922 - WordPress Elementor plugin <= 3.13.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2.
5.3
CVE-2023-28775 - WordPress Yoast SEO Premium plugin <= 20.4 - Unauthenticated Zapier API Key Reset vulnerability
Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.
8.3
CVE-2023-25799 - WordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilities
Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.
6.4
CVE-2024-5531 - Ocean Extra <= 2.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flickr Widget
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contriβ¦
5.3
CVE-2024-4266 - MetForm β Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticateβ¦
The MetForm β Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. This can allow unauthenticated attackers to extract sensitive data, such as Persβ¦
6.5
CVE-2020-11843 - Potential information leakage in administrator enabled debug mode
This allows the information exposure to unauthorized users.Β This issue affects NetIQ Access Manager using version 4.5 or before
9.9
CVE-2024-3549 - Blog2Social: Social Media Auto Post & Scheduler <= 7.4.1 - Authenticated (Subscriber+) SQL Injection
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL β¦
8.2
CVE-2022-23829 - hw: amd: SPI protection feature may result in a potential arbitrary code execution.
A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.