Latest Vulnerabilities

Latest Vulnerabilities Updates on the latest vulnerabilities detected.

  • CVE-2024-12884 – Codezips E-Commerce Website SQL Injection
    on December 21, 2024 at 2:15 pm

    CVE ID : CVE-2024-12884 Published : Dec. 21, 2024, 2:15 p.m. | 8 hours, 50 minutes ago Description : A vulnerability was found in Codezips E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-51463 – IBM i SSRF
    on December 21, 2024 at 2:15 pm

    CVE ID : CVE-2024-51463 Published : Dec. 21, 2024, 2:15 p.m. | 8 hours, 50 minutes ago Description : IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-51464 – IBM Navigator for i Access Bypass Vulnerability
    on December 21, 2024 at 2:15 pm

    CVE ID : CVE-2024-51464 Published : Dec. 21, 2024, 2:15 p.m. | 8 hours, 50 minutes ago Description : IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to remotely perform operations that the user is not allowed to perform when using Navigator for i. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-12883 – Code-projects Job Recruitment Cross Site Scripting
    on December 21, 2024 at 1:15 pm

    CVE ID : CVE-2024-12883 Published : Dec. 21, 2024, 1:15 p.m. | 9 hours, 51 minutes ago Description : A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /_email.php. The manipulation of the argument email leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-12875 – Easy Digital Downloads WordPress Directory Traversal Vulnerability
    on December 21, 2024 at 12:15 pm

    CVE ID : CVE-2024-12875 Published : Dec. 21, 2024, 12:15 p.m. | 10 hours, 50 minutes ago Description : The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 via the file download functionality. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-12591 – MagicPost WordPress Stored Cross-Site Scripting
    on December 21, 2024 at 10:15 am

    CVE ID : CVE-2024-12591 Published : Dec. 21, 2024, 10:15 a.m. | 12 hours, 51 minutes ago Description : The MagicPost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s wb_share_social shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-12408 – “Amazon Web Services (AWS) WordPress Reflected Cross-Site Scripting (XSS)”
    on December 21, 2024 at 10:15 am

    CVE ID : CVE-2024-12408 Published : Dec. 21, 2024, 10:15 a.m. | 12 hours, 51 minutes ago Description : The WP on AWS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST data in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-12558 – WordPress WP BASE Booking Unauthenticated Database Access Vulnerability
    on December 21, 2024 at 10:15 am

    CVE ID : CVE-2024-12558 Published : Dec. 21, 2024, 10:15 a.m. | 12 hours, 51 minutes ago Description : The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db function in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to expose sensitive information from the database, such as the hashed administrator password. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-11722 – WordPress DynamiApps Frontend Admin SQL Injection
    on December 21, 2024 at 10:15 am

    CVE ID : CVE-2024-11722 Published : Dec. 21, 2024, 10:15 a.m. | 12 hours, 51 minutes ago Description : The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 3.25.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This requires an unauthenticated user to have been given permission to view form submissions, and the form submission shortcode be added to a page. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-11688 – WordPress LaTeX2HTML Reflected Cross-Site Scripting
    on December 21, 2024 at 10:15 am

    CVE ID : CVE-2024-11688 Published : Dec. 21, 2024, 10:15 a.m. | 12 hours, 51 minutes ago Description : The LaTeX2HTML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ver’ or ‘date’ parameter in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-10453 – Elementor Website Builder Stored Cross-Site Scripting Vulnerability
    on December 21, 2024 at 10:15 am

    CVE ID : CVE-2024-10453 Published : Dec. 21, 2024, 10:15 a.m. | 12 hours, 51 minutes ago Description : The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s Typography Settings in all versions up to, and including, 3.25.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-9545 – “WordPress Phlox Theme Plugin Stored Cross-Site Scripting Vulnerability”
    on December 21, 2024 at 9:15 am

    CVE ID : CVE-2024-9545 Published : Dec. 21, 2024, 9:15 a.m. | 13 hours, 51 minutes ago Description : The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s aux_contact_box and aux_gmaps shortcodes in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-11808 – Pingmeter WordPress Reflected Cross-Site Scripting Vulnerability
    on December 21, 2024 at 9:15 am

    CVE ID : CVE-2024-11808 Published : Dec. 21, 2024, 9:15 a.m. | 13 hours, 51 minutes ago Description : The Pingmeter Uptime Monitoring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘_wpnonce’ parameter in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-12588 – WordPress Phlox Theme Phlox Theme Stored Cross-Site Scripting
    on December 21, 2024 at 9:15 am

    CVE ID : CVE-2024-12588 Published : Dec. 21, 2024, 9:15 a.m. | 13 hours, 51 minutes ago Description : The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s Staff widget in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-10797 – Elementor WordPress Full Screen Menu Information Exposure
    on December 21, 2024 at 9:15 am

    CVE ID : CVE-2024-10797 Published : Dec. 21, 2024, 9:15 a.m. | 13 hours, 51 minutes ago Description : The Full Screen Menu for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.7 via the Full Screen Menu Elementor Widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with contributor-level access and above, to extract data from private or draft posts created with Elementor that they should not have access to. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-12262 – WordPress Ebook Store Reflected Cross-Site Scripting
    on December 21, 2024 at 7:15 am

    CVE ID : CVE-2024-12262 Published : Dec. 21, 2024, 7:15 a.m. | 15 hours, 51 minutes ago Description : The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘step’ parameter in all versions up to, and including, 5.8001 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-12635 – “WordPress WP Docs Time-Based SQL Injection”
    on December 21, 2024 at 7:15 am

    CVE ID : CVE-2024-12635 Published : Dec. 21, 2024, 7:15 a.m. | 15 hours, 51 minutes ago Description : The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the ‘dir_id’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerability was partially patched in version 2.2.0. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-12697 – RealKit WordPress Stored Cross-Site Scripting Vulnerability
    on December 21, 2024 at 7:15 am

    CVE ID : CVE-2024-12697 Published : Dec. 21, 2024, 7:15 a.m. | 15 hours, 51 minutes ago Description : The real.Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-12721 – WooCommerce Custom Product Tabs PHP Object Injection Vulnerability
    on December 21, 2024 at 7:15 am

    CVE ID : CVE-2024-12721 Published : Dec. 21, 2024, 7:15 a.m. | 15 hours, 51 minutes ago Description : The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.4 via deserialization of untrusted input from the ‘wb_custom_tabs’ parameter. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-12771 – WordPress eCommerce Product Catalog Cross-Site Request Forgery (CSRF)
    on December 21, 2024 at 7:15 am

    CVE ID : CVE-2024-12771 Published : Dec. 21, 2024, 7:15 a.m. | 15 hours, 51 minutes ago Description : The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.43. This is due to missing or incorrect nonce validation on the ‘customer_panel_password_reset’ function. This makes it possible for unauthenticated attackers to reset the password of any administrator or customer account via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-11287 – Ebook Store WordPress Reflected Cross-Site Scripting
    on December 21, 2024 at 7:15 am

    CVE ID : CVE-2024-11287 Published : Dec. 21, 2024, 7:15 a.m. | 15 hours, 51 minutes ago Description : The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.8001. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-11682 – WordPress G Web Pro Store Locator Reflected Cross-Site Scripting
    on December 21, 2024 at 7:15 am

    CVE ID : CVE-2024-11682 Published : Dec. 21, 2024, 7:15 a.m. | 15 hours, 51 minutes ago Description : The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘q’ parameter in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-11938 – “WooCommerce Sales Funnel Cross-Site Scripting Vulnerability”
    on December 21, 2024 at 7:15 am

    CVE ID : CVE-2024-11938 Published : Dec. 21, 2024, 7:15 a.m. | 15 hours, 51 minutes ago Description : The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Upsell & Cross Sell Offers that Boost Sales & Increase Profits with Sales Funnel Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s wps_wocuf_pro_yes shortcode in all versions up to, and including, 3.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-11975 – Reactflow WordPress CSRF
    on December 21, 2024 at 7:15 am

    CVE ID : CVE-2024-11975 Published : Dec. 21, 2024, 7:15 a.m. | 15 hours, 51 minutes ago Description : The Reactflow Visitor Recording and Heatmaps plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.10. This is due to missing or incorrect nonce validation affecting the _wpnonce parameter. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more…

  • CVE-2024-12066 – WordPress SMSA Shipping Plugin Remote File Deletion Vulnerability
    on December 21, 2024 at 7:15 am

    CVE ID : CVE-2024-12066 Published : Dec. 21, 2024, 7:15 a.m. | 15 hours, 51 minutes ago Description : The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the smsa_delete_label() function in all versions up to, and including, 2.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Share Websitecyber