| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys. |
| The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator. |
| Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions. |
| Editor SQL Injection in Amelia <= 2.4.9 versions. |
| Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions. |
| Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions. |
| Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions. |
| Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions. |
| Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions. |
| Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions. |
| Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions. |
| Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions. |
| Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions. |
| Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data.
This issue affects ElasticPress: from n/a through 5.3.4. |
| The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the bulk_action parameter in all versions up to, and including, 1.15.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. |
| Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions. |
| The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce protecting chat message submission is publicly visible on the chat page, rendering it ineffective as an authentication barrier and allowing fully unauthenticated attackers to submit malicious messages that are stored persistently and rendered to all visitors on every page load. |
| Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions. |
| Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions. |