Search Results (8930 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-38058 1 Wpvar 1 Wp Shamsi 2025-02-20 4.3 Medium
Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin <= 4.1.1 at WordPress.
CVE-2022-36793 1 Wp-shop 1 Wp Shop 2025-02-20 6.5 Medium
Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.
CVE-2022-38067 1 Total-soft 1 Event Calendar 2025-02-20 6.5 Medium
Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
CVE-2022-38135 1 Photospace Gallery Project 1 Photospace Gallery 2025-02-20 5.4 Medium
Broken Access Control vulnerability in Dean Oakley's Photospace Gallery plugin <= 2.3.5 at WordPress allows users with subscriber or higher role to change plugin settings.
CVE-2022-35238 1 Brinidesigner 1 Awesome Filterable Portfolio 2025-02-20 6.5 Medium
Unauthenticated Plugin Settings Change vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress.
CVE-2022-38134 1 Cusrev 1 Customer Reviews For Woocommerce 2025-02-20 4.3 Medium
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
CVE-2022-38104 1 Oxilab 1 Accordions 2025-02-20 7.2 High
Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accordions – Multiple Accordions or FAQs Builder plugin (versions <= 2.0.3 on WordPress.
CVE-2022-41978 1 Zohocorp 1 Zoho Crm Lead Magnet 2025-02-20 8.8 High
Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.
CVE-2022-38461 1 Wpml 1 Wpml 2025-02-20 5.4 Medium
Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a subscriber or higher user role to change plugin settings (selected language for legacy widgets, the default behavior for media content).
CVE-2022-45066 1 Thriveweb 1 Wooswipe Woocommerce Gallery 2025-02-20 5.4 Medium
Auth. (subscriber+) Broken Access Control vulnerability in WooSwipe WooCommerce Gallery plugin <= 2.0.1 on WordPress.
CVE-2022-45069 1 Automattic 1 Crowdsignal Dashboard 2025-02-20 6.3 Medium
Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
CVE-2022-38974 1 Wpml 1 Wpml 2025-02-20 4.3 Medium
Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with subscriber or higher user roles to change the status of the translation jobs.
CVE-2022-41781 1 Permalink Manager Lite Project 1 Permalink Manager Lite 2025-02-20 6.5 Medium
Broken Access Control vulnerability in Permalink Manager Lite plugin <= 2.2.20 on WordPress.
CVE-2022-42461 1 Miniorange 1 Google Authenticator 2025-02-20 5.4 Medium
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
CVE-2022-41839 1 Wpbrigade 1 Loginpress 2025-02-20 5.3 Medium
Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of Opt-In or Opt-Out tracking settings.
CVE-2022-45369 1 Richplugins 1 Plugin For Google Reviews 2025-02-20 4.3 Medium
Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.
CVE-2022-42459 1 Oxilab 1 Image Hover Effects Ultimate 2025-02-20 7.2 High
Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.
CVE-2022-42888 1 Armemberplugin 1 Armember 2025-02-20 9.8 Critical
Unauth. Privilege Escalation vulnerability in ARMember premium plugin <= 5.5.1 on WordPress.
CVE-2023-21068 1 Google 1 Android 2025-02-20 7.8 High
In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This could lead to local escalation of privilege after preparing the device, hiding the warning, and passing the phone to a new user, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243433344References: N/A
CVE-2024-12213 1 Apusthemes 1 Superio 2025-02-20 9.8 Critical
The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.76. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites.