| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions. |
| Unauthenticated PHP Object Injection in Konsept <= 1.9 versions. |
| Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions. |
| Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions. |
| Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions. |
| Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions. |
| Unauthenticated PHP Object Injection in Zoya <= 1.4 versions. |
| Unauthenticated PHP Object Injection in Château <= 1.2.1 versions. |
| Unauthenticated Local File Inclusion in Kastell <= 2.0 versions. |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection.
This issue affects SureDash: from n/a through 1.8.0. |
| The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks |
| The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site. |
| The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'post_id' parameter in all versions up to, and including, 2.22.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The AJAX handler is registered for unauthenticated users via wp_ajax_nopriv_tf_room_availability, and the required nonce is emitted on the public single-hotel page template, allowing unauthenticated attackers to freely obtain a valid nonce and reach the vulnerable code path. |
| Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions. |
| Unauthenticated SQL Injection in MDTF <= 1.3.7 versions. |
| Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions. |
| Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions. |
| Contributor Broken Access Control in Slim SEO <= 4.6.2 versions. |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection.
This issue affects YMC Filter: from n/a through 3.11.5. |