Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2 via the ced_wholesale_request_send AJAX action. The ced_wholesale_request_send_callback() handler only verifies a nonce (which is exposed to any authenticated user through wp_localize_script on the frontend) and that the caller has a positive user ID, then calls WP_User::add_role() with the client-supplied role_required POST parameter without restricting the value to an allowli
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' parameter in all versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the site administrator has enabled the 'Support G