| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. |
| Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions. |
| Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. |
| Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. |
| Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions. |
| Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. |
| Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. |
| Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. |
| Unauthenticated SQL Injection in Bookly <= 27.7 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions. |
| Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. |
| Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. |
| Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. |
| Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. |
| Contributor SQL Injection in Visualizer <= 4.0.6 versions. |
| Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS.
This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30. |
| DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS. |