The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attack…
CVSS 5.3
The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing …
CVSS 5.3
The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public …
CVSS 5.3
The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation …
CVSS 8.8
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all v…
CVSS 7.2
Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Ch…
LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with …
CVSS 5.4
The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to m…
CVSS 5.3
The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or gu…
CVSS 5.9
The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthent…
CVSS 5.9
The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is …
CVSS 5.3
The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a c…
CVSS 8.8