Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-12 CVE-2023-25030 Missing Authorization vulnerability in Buymeacoffee BUY ME a Coffee
Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7.
network
low complexity
buymeacoffee CWE-862
4.3
2024-06-12 CVE-2023-38395 Missing Authorization vulnerability in Afzalmultani WP Clone Menu 1.0.1
Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1.
network
low complexity
afzalmultani CWE-862
4.3
2024-06-12 CVE-2023-40209 Missing Authorization vulnerability in Himalayasaxena Highcompress Image Compressor
Missing Authorization vulnerability in Himalaya Saxena Highcompress Image Compressor.This issue affects Highcompress Image Compressor: from n/a through 6.0.0.
network
low complexity
himalayasaxena CWE-862
4.3
2024-06-12 CVE-2023-40603 Missing Authorization vulnerability in Webtechforce Simple ORG Chart 2.3.4
Missing Authorization vulnerability in Gangesh Matta Simple Org Chart.This issue affects Simple Org Chart: from n/a through 2.3.4.
network
low complexity
webtechforce CWE-862
5.3
2024-06-12 CVE-2023-41240 Missing Authorization vulnerability in Varktech Pricing Deals for Woocommerce
Missing Authorization vulnerability in Vark Pricing Deals for WooCommerce.This issue affects Pricing Deals for WooCommerce: from n/a through 2.0.3.2.
network
low complexity
varktech CWE-862
5.3
2024-06-12 CVE-2023-44234 Missing Authorization vulnerability in Devfarm WP GPX Maps
Missing Authorization vulnerability in Bastianon Massimo WP GPX Map.This issue affects WP GPX Map: from n/a through 1.7.08.
network
low complexity
devfarm CWE-862
4.3
2024-06-12 CVE-2023-47828 Missing Authorization vulnerability in Millermedia Mandrill
Missing Authorization vulnerability in Mandrill wpMandrill.This issue affects wpMandrill: from n/a through 1.33.
network
low complexity
millermedia CWE-862
4.3
2024-06-12 CVE-2024-2092 Cross-site Scripting vulnerability in Wpvibes Elementor Addon Elements
The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter Widget in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpvibes CWE-79
5.4
2024-06-12 CVE-2023-51670 Missing Authorization vulnerability in Funnelkit Checkout 3.10.3
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
network
low complexity
funnelkit CWE-862
4.3
2024-06-12 CVE-2023-51671 Missing Authorization vulnerability in Funnelkit Checkout 3.10.3
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
network
low complexity
funnelkit CWE-862
5.4