Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2023-25707: WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions.

CVE
#csrf#vulnerability#wordpress#auth
CVE-2023-25472: WordPress Podlove Podcast Publisher plugin <= 3.8.3 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.3 versions.

CVE-2023-25481: WordPress Podlove Subscribe Button plugin <= 1.3.7 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versions.

CVE-2023-28413: Multiple vulnerabilities in WordPress Plugin "MW WP Form" and "Snow Monkey Forms"

Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.

CVE-2023-28367: VK Blocks / ExUnit の脆弱性について

Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.

CVE-2023-27922: WordPress Plugin "Newsletter" vulnerable to cross-site scripting

Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.

W3 Eden Download Manager 3.2.70 Cross Site Scripting

W3 Eden Download Manager versions 3.2.70 and below suffer from a persistent cross site scripting vulnerability via ShortCode.

CVE-2023-25448: WordPress Archivist – Custom Archive Templates plugin <= 1.7.4 - Cross Site Request Forgery (CSRF) vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.

CVE-2023-25447: WordPress ColorWay theme <= 4.2.3 - CSRF Leading to Arbitrary Plugin Activation - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in Inkthemescom ColorWay theme <= 4.2.3 versions.