Security
Headlines
HeadlinesLatestCVEs

Tag

#perl

CVE-2023-2187: Industrial and Manufacturing CVEs: Addressing the SCADA in the Room

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.

CVE
#vulnerability#web#ios#mac#php#perl#hard_coded_credentials#auth
CVE-2021-4342: Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass — Wordfence Intelligence

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

CVE-2022-4948: FlyingPress <= 3.9.6 - Missing Authorization — Wordfence Intelligence

The FlyingPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 3.9.6. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to interact with the plugin in ways administrators are intended to. One action (save_config) allows for the configuration of an external CDN. This could be used to include malicious javascript from a source controlled by the attacker.

CVE-2021-4383: WP Quick FrontEnd Editor <= 5.5 - Authenticated (Subscriber+) Content Injection — Wordfence Intelligence

The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. This is due to missing capability checks in the plugin's page-editing functionality. This makes it possible for low-authenticated attackers, such as subscribers, to edit/create any page or post on the blog.

CVE-2022-4950: Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activation — Wordfence Intelligence

Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.

CVE-2021-4376: WooCommerce Multi Currency <= 2.1.17 - Missing Authorization — Wordfence Intelligence

The WooCommerce Multi Currency plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.17. This makes it possible for authenticated attackers to change the price of a product to an arbitrary value.

CVE-2021-4378: WP Quick FrontEnd Editor <= 5.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting — Wordfence Intelligence

The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with minimal permissions like subscribers, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2021-4374: WordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update — Wordfence Intelligence

The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to arbitrarily update the settings of a vulnerable site and ultimately compromise the entire site.

CVE-2020-36702: Spectra – WordPress Gutenberg Blocks <= 1.14.7 - Missing Authorization — Wordfence Intelligence

The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.

CVE-2020-36722: Visual Composer <= 26.0 - Multiple Cross-Site Scripting — Wordfence Intelligence

The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.