Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions.
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multiplier in a template to force multi-gigabyte memory allocations, causing resource exhaustion and availability degradation.
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas.