9.8
CVE-2023-26009 - WordPress Houzez Login Register plugin <= 2.6.3 - Privilege Escalation
Improper Privilege Management vulnerability in Favethemes Houzez Login Register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through 2.6.3.
9.8
CVE-2023-25701 - WordPress WatchTowerHQ plugin <= 3.6.16 - Privilege Escalation
Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects WatchTowerHQ: from n/a through 3.6.16.
9.1
CVE-2023-25444 - WordPress JS Help Desk β Best Help Desk & Support Plugin plugin <= 2.7.7 - Arbitrary File Upload vuβ¦
Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk β Best Help Desk & Support Plugin allows Using Malicious Files.This issue affects JS Help Desk β Best Help Desk & Support Plugin: from n/a through 2.7.7.
7.1
CVE-2023-25050 - WordPress Shortcodes Ultimate plugin <= 5.12.6 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vova Anokhin Shortcodes Ultimate allows Absolute Path Traversal.This issue affects Shortcodes Ultimate: from n/a through 5.12.6.
6.8
CVE-2023-24379 - WordPress Landing Page Builder β Free Landing Page Templates plugin <= 3.1.9.9 - Local File Inclusiβ¦
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Web-Settler Landing Page Builder β Free Landing Page Templates allows Path Traversal.This issue affects Landing Page Builder β Free Landing Page Templates: from n/a through 3.1.9.9.
7.6
CVE-2023-23990 - WordPress Redirection for Contact Form 7 plugin <= 2.7.0 - Privilege Escalation vulnerability
Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privilege Escalation.This issue affects Redirection for Contact Form 7: from n/a through 2.7.0.
7.5
CVE-2023-23988 - WordPress My Tickets plugin <= 1.9.11 - Payment Bypass Vulnerability
Missing Authorization vulnerability in Joseph C Dolson My Tickets.This issue affects My Tickets: from n/a through 1.9.11.
7.6
CVE-2023-23888 - WordPress Rank Math SEO plugin <= 1.0.107.2 - Local File Inclusion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rank Math Rank Math SEO allows Path Traversal.This issue affects Rank Math SEO: from n/a through 1.0.107.2.
4.9
CVE-2023-23872 - WordPress GMAce plugin <= 1.5.2 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in German Mesky GMAce allows Path Traversal.This issue affects GMAce: from n/a through 1.5.2.
7.6
CVE-2023-23700 - WordPress OceanWP theme <= 3.4.1 - Authenticated Local File Inclusion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OceanWP allows PHP Local File Inclusion.This issue affects OceanWP: from n/a through 3.4.1.