Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2024-6028 The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user s... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-8570 The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 t... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-6220 The ็ฎๆฐ้้ๅจ (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-52441 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Rajesh Thanoch Quick Learn quick-learn allows Object Injection.This issue affects Quick Learn... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-6457 The HUSKY โ Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the โwoof_authorโ parameter in all versions up to, and including, 1.3.6 due ... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-7493 The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_u... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-12813 The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via the 'contents' parameter. This is due to a lack of sanitizatio... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-1711 The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.9.4 due to insufficient escaping on the user supplied paramet... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-11522 The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user ... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-5756 The Email Subscribers by Icegram Express โ Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in a... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-52440 Deserialization of Untrusted Data vulnerability in xpresslane Xpresslane Fast Checkout xpresslane-integration-for-woocommerce allows Object Injection.This issue affects Xpresslane Fast Checkout: from ... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-11457 The EasyCommerce โ AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privilege Escalation in versions 0.9.0-beta2 to 1.8.2. This is due to the /easycommerce... | 9.8 | CRITICAL | โ | 0 |
| CVE-2019-25614 Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized paylo... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-3495 The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the โcntโ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the u... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-4898 The InstaWP Connect โ 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, a... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-8485 The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validatio... | 9.8 | CRITICAL | โ | 0 |
| CVE-2026-39324 Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryp... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-4098 The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 via the shariff3uu_fetch_sharecounts function. This allows unauthenticated attac... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-1207 The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient ... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-8353 The GiveWP โ Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-10850 The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password in the 'fb_ajax_login_or_register' func... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-2771 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/f... | 9.8 | CRITICAL | โ | 0 |
| CVE-2026-31271 megagao production_ssm v1.0 contains an authorization bypass vulnerability in the user addition functionality. The insert() method in UserController.java lacks authentication checks, allowing unauthen... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-6314 The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process_image_upload' function in versions up to, and including, 2.2.7... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-8898 The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.0. This is due to the plugin ... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-0610 The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'MerchantReference' parameter in all versions up to, and including, 1.6.5.1 du... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-1512 The MasterStudy LMS WordPress Plugin โ for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST ro... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-50507 Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList: from n/a through <= 1.3. | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-4936 The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to inc... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-49332 Deserialization of Untrusted Data vulnerability in giveawayboost Giveaway Boost giveaway-boost allows Object Injection.This issue affects Giveaway Boost: from n/a through <= 2.1.4. | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-52439 Deserialization of Untrusted Data vulnerability in Mark O'Donnell Team Rosters team-rosters allows Object Injection.This issue affects Team Rosters: from n/a through <= 4.8.2. | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-3605 The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.1. This is due to the plugin not pr... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-2005 The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and inclu... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-11613 The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-14736 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is due to insufficient validation of user-supplied role ... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-6328 The MStore API โ Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient ver... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-12673 The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_qr_code() function in all versions up to, and including, 1.2.7... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-12374 The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login โ User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, ... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-13313 The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is due to missing authorization and authentication che... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-44000 Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1... | 9.8 | CRITICAL | โ | 0 |
| CVE-2023-6553 The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being a... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-6172 The Email Subscribers by Icegram Express โ Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in a... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-10412 The Product Options and Price Calculation Formulas for WooCommerce โ Uni CPO (Premium) plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'un... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-48028 Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affects IP Loc8: from n/a through <= 1.1. | 9.8 | CRITICAL | โ | 0 |
| CVE-2026-32746 telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full. | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-5432 The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.6. This is due to insufficient verification on the user being supplied during th... | 9.8 | CRITICAL | โ | 0 |
| CVE-2026-30305 Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular e... | 9.8 | CRITICAL | โ | 0 |
| CVE-2025-9286 The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all versions up to, and in... | 9.8 | CRITICAL | โ | 0 |
| CVE-2024-52443 Deserialization of Untrusted Data vulnerability in masikonis Geolocator geolocator allows Object Injection.This issue affects Geolocator: from n/a through <= 1.1. | 9.8 | CRITICAL | โ | 0 |
| CVE-2023-2601 The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin via CSRF. | 9.8 | CRITICAL | โ | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.