Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-16 CVE-2023-7293 Missing Authorization vulnerability in Paytium
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_mollie_account_details function in versions up to, and including, 4.3.7.
network
low complexity
paytium CWE-862
4.3
2024-10-16 CVE-2023-7294 Missing Authorization vulnerability in Paytium
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile function in versions up to, and including, 4.3.7.
network
low complexity
paytium CWE-862
6.5
2024-10-16 CVE-2024-8507 Cross-Site Request Forgery (CSRF) vulnerability in Filemanagerpro File Manager
The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9.
network
low complexity
filemanagerpro CWE-352
8.8
2024-10-16 CVE-2024-8746 Unrestricted Upload of File with Dangerous Type vulnerability in Filemanagerpro File Manager
The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9.
network
low complexity
filemanagerpro CWE-434
8.8
2024-10-16 CVE-2024-8918 Unrestricted Upload of File with Dangerous Type vulnerability in Filemanagerpro File Manager
The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9.
network
low complexity
filemanagerpro CWE-434
5.4
2024-10-16 CVE-2024-9888 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget redirect URL in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
5.4
2024-10-16 CVE-2024-9937 The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 6.1.7 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2024-10-16 CVE-2024-8541 Cross-site Scripting vulnerability in Flycart Discount Rules for Woocommerce
The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.6.5.
network
low complexity
flycart CWE-79
6.1
2024-10-16 CVE-2024-8787 The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.5.7.
network
low complexity
CWE-79
6.1
2024-10-16 CVE-2024-9104 The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3.
network
high complexity
CWE-703
5.6