The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment conf…
CVSS 6.5
The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belongin…
CVSS 5.5
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing…
CVSS 5.3
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attack…
CVSS 5.3
The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing …
CVSS 5.3
The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public …
CVSS 5.3
The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation …
CVSS 8.8
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all v…
CVSS 7.2
Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Ch…
LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with …
CVSS 5.4
The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to m…
CVSS 5.3
The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or gu…
CVSS 5.9