Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-23660: WordPress MainWP Maintenance Extension Plugin <= 4.1.1 - Subscriber+ SQL Injection Vulnerability - Patchstack

Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP MainWP Maintenance Extension plugin <= 4.1.1 versions.

CVE
#sql#vulnerability#wordpress#auth
CVE-2023-37973: WordPress Replace Word plugin <= 2.1 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in David Pokorny Replace Word plugin <= 2.1 versions.

CVE-2023-37892: WordPress Shortcode IMDB plugin <= 6.0.8 - Cross Site Request Forgery (CSRF) - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Kemal YAZICI - PluginPress Shortcode IMDB plugin <= 6.0.8 versions.

CVE-2023-37889: WordPress WPAdmin AWS CDN plugin <= 2.0.13 - Cross Site Request Forgery (CSRF) - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in WPAdmin WPAdmin AWS CDN plugin <= 2.0.13 versions.

CVE-2022-47169: WordPress Visibility Logic for Elementor plugin <= 2.3.4 - Cross Site Request Forgery (CSRF) - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in StaxWP Visibility Logic for Elementor plugin <= 2.3.4 versions.

CVE-2023-3743: Sql Injection Vulnerability Leothemes Ap Page Builder | INCIBE-CERT

Ap Page Builder, in versions lower than 1.7.8.2, could allow a remote attacker to send a specially crafted SQL query to the product_one_img parameter to retrieve the information stored in the database.

CVE-2023-25473: WordPress Flickr Justified Gallery plugin <= 3.5 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Miro Mannino Flickr Justified Gallery plugin <= 3.5 versions.