| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.
This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/). |
| WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher.
Prerequisites:
* Imagick and Ghostscript in use on the server
* A malicious user with the `upload_files` capability
This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. |
| Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. |
| Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. |
| Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. |
| Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. |
| Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. |
| Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. |
| Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions. |
| Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions. |
| Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. |
| Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions. |
| Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions. |
| Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions. |
| Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions. |
| Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions. |
| Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions. |