diff --git a/advisories/unreviewed/2024/01/GHSA-2737-gp9h-gmmc/GHSA-2737-gp9h-gmmc.json b/advisories/unreviewed/2024/01/GHSA-2737-gp9h-gmmc/GHSA-2737-gp9h-gmmc.json new file mode 100644 index 00000000000..db6c40ae84d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2737-gp9h-gmmc/GHSA-2737-gp9h-gmmc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2737-gp9h-gmmc", + "modified": "2024-01-05T09:30:31Z", + "published": "2024-01-05T09:30:31Z", + "aliases": [ + "CVE-2020-13878" + ], + "details": "IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+27ef heap-based out-of-bounds write.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13878" + }, + { + "type": "WEB", + "url": "https://gist.github.com/oicu0619/2b0eb7dd447aca8f4ab398a99f47488b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T08:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-2fmx-fw55-g6jg/GHSA-2fmx-fw55-g6jg.json b/advisories/unreviewed/2024/01/GHSA-2fmx-fw55-g6jg/GHSA-2fmx-fw55-g6jg.json new file mode 100644 index 00000000000..93d222f51f1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2fmx-fw55-g6jg/GHSA-2fmx-fw55-g6jg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fmx-fw55-g6jg", + "modified": "2024-01-05T09:30:31Z", + "published": "2024-01-05T09:30:31Z", + "aliases": [ + "CVE-2023-52184" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52184" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-job-portal/wordpress-wp-job-portal-plugin-2-0-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T08:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-32v9-4fqf-r943/GHSA-32v9-4fqf-r943.json b/advisories/unreviewed/2024/01/GHSA-32v9-4fqf-r943/GHSA-32v9-4fqf-r943.json new file mode 100644 index 00000000000..4639922961f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-32v9-4fqf-r943/GHSA-32v9-4fqf-r943.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32v9-4fqf-r943", + "modified": "2024-01-05T09:30:32Z", + "published": "2024-01-05T09:30:32Z", + "aliases": [ + "CVE-2023-50027" + ], + "details": "SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50027" + }, + { + "type": "WEB", + "url": "https://security.friendsofpresta.org/modules/2023/12/19/baproductzoommagnifier.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3wh6-ghqv-v6wx/GHSA-3wh6-ghqv-v6wx.json b/advisories/unreviewed/2024/01/GHSA-3wh6-ghqv-v6wx/GHSA-3wh6-ghqv-v6wx.json new file mode 100644 index 00000000000..3aa7a91fca8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3wh6-ghqv-v6wx/GHSA-3wh6-ghqv-v6wx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wh6-ghqv-v6wx", + "modified": "2024-01-05T09:30:31Z", + "published": "2024-01-05T09:30:31Z", + "aliases": [ + "CVE-2020-13879" + ], + "details": "IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+214f heap-based out-of-bounds write.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13879" + }, + { + "type": "WEB", + "url": "https://gist.github.com/oicu0619/878b8c37f238f4de5ff543973ef083f5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T08:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3wxg-f3wj-3x8p/GHSA-3wxg-f3wj-3x8p.json b/advisories/unreviewed/2024/01/GHSA-3wxg-f3wj-3x8p/GHSA-3wxg-f3wj-3x8p.json new file mode 100644 index 00000000000..a883f719b79 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3wxg-f3wj-3x8p/GHSA-3wxg-f3wj-3x8p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wxg-f3wj-3x8p", + "modified": "2024-01-05T09:30:31Z", + "published": "2024-01-05T09:30:31Z", + "aliases": [ + "CVE-2023-51502" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51502" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-gateway-stripe/wordpress-woocommerce-stripe-gateway-plugin-7-6-1-unauthenticated-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T08:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6j5w-7jm2-g5c8/GHSA-6j5w-7jm2-g5c8.json b/advisories/unreviewed/2024/01/GHSA-6j5w-7jm2-g5c8/GHSA-6j5w-7jm2-g5c8.json new file mode 100644 index 00000000000..852bdc12d01 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6j5w-7jm2-g5c8/GHSA-6j5w-7jm2-g5c8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j5w-7jm2-g5c8", + "modified": "2024-01-05T09:30:31Z", + "published": "2024-01-05T09:30:31Z", + "aliases": [ + "CVE-2023-52150" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ovation S.R.L. Dynamic Content for Elementor.This issue affects Dynamic Content for Elementor: from n/a before 2.12.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52150" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dynamic-content-for-elementor/wordpress-dynamic-content-for-elementor-plugin-2-12-5-cross-site-request-forgery-csrf-leading-to-arbitrary-wordpress-options-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T08:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7g57-8pfv-q7q8/GHSA-7g57-8pfv-q7q8.json b/advisories/unreviewed/2024/01/GHSA-7g57-8pfv-q7q8/GHSA-7g57-8pfv-q7q8.json new file mode 100644 index 00000000000..1f3f8243616 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7g57-8pfv-q7q8/GHSA-7g57-8pfv-q7q8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g57-8pfv-q7q8", + "modified": "2024-01-05T09:30:33Z", + "published": "2024-01-05T09:30:33Z", + "aliases": [ + "CVE-2023-52145" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Republish Old Posts.This issue affects Republish Old Posts: from n/a through 1.21.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52145" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/republish-old-posts/wordpress-republish-old-posts-plugin-1-21-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8whm-5rcq-6487/GHSA-8whm-5rcq-6487.json b/advisories/unreviewed/2024/01/GHSA-8whm-5rcq-6487/GHSA-8whm-5rcq-6487.json new file mode 100644 index 00000000000..78544e44bce --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8whm-5rcq-6487/GHSA-8whm-5rcq-6487.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8whm-5rcq-6487", + "modified": "2024-01-05T09:30:32Z", + "published": "2024-01-05T09:30:32Z", + "aliases": [ + "CVE-2023-52127" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Product Bundles for WooCommerce.This issue affects WPC Product Bundles for WooCommerce: from n/a through 7.3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52127" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-product-bundle/wordpress-wpc-product-bundles-for-woocommerce-plugin-7-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cj36-rwcw-fx5g/GHSA-cj36-rwcw-fx5g.json b/advisories/unreviewed/2024/01/GHSA-cj36-rwcw-fx5g/GHSA-cj36-rwcw-fx5g.json new file mode 100644 index 00000000000..dd85b590783 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cj36-rwcw-fx5g/GHSA-cj36-rwcw-fx5g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj36-rwcw-fx5g", + "modified": "2024-01-05T09:30:33Z", + "published": "2024-01-05T09:30:33Z", + "aliases": [ + "CVE-2023-52129" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52129" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/teachpress/wordpress-teachpress-plugin-9-0-4-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fmvv-rrvc-rh7f/GHSA-fmvv-rrvc-rh7f.json b/advisories/unreviewed/2024/01/GHSA-fmvv-rrvc-rh7f/GHSA-fmvv-rrvc-rh7f.json new file mode 100644 index 00000000000..f791c2bd2f0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fmvv-rrvc-rh7f/GHSA-fmvv-rrvc-rh7f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmvv-rrvc-rh7f", + "modified": "2024-01-05T09:30:33Z", + "published": "2024-01-05T09:30:33Z", + "aliases": [ + "CVE-2023-52136" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds – A Tweets Widget or X Feed Widget.This issue affects Custom Twitter Feeds – A Tweets Widget or X Feed Widget: from n/a through 2.1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52136" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-twitter-feeds/wordpress-custom-twitter-feeds-tweets-widget-plugin-2-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gpp2-r65h-4c4w/GHSA-gpp2-r65h-4c4w.json b/advisories/unreviewed/2024/01/GHSA-gpp2-r65h-4c4w/GHSA-gpp2-r65h-4c4w.json new file mode 100644 index 00000000000..f657570f84f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gpp2-r65h-4c4w/GHSA-gpp2-r65h-4c4w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpp2-r65h-4c4w", + "modified": "2024-01-05T09:30:33Z", + "published": "2024-01-05T09:30:33Z", + "aliases": [ + "CVE-2023-52149" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button.This issue affects Floating Button: from n/a through 6.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52149" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/floating-button/wordpress-floating-button-plugin-6-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-h27c-6j26-rv2x/GHSA-h27c-6j26-rv2x.json b/advisories/unreviewed/2024/01/GHSA-h27c-6j26-rv2x/GHSA-h27c-6j26-rv2x.json new file mode 100644 index 00000000000..048f47e4e80 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-h27c-6j26-rv2x/GHSA-h27c-6j26-rv2x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h27c-6j26-rv2x", + "modified": "2024-01-05T09:30:31Z", + "published": "2024-01-05T09:30:31Z", + "aliases": [ + "CVE-2020-13880" + ], + "details": "IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+1cbf heap-based out-of-bounds write.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13880" + }, + { + "type": "WEB", + "url": "https://gist.github.com/oicu0619/2de8f91ddc6b06b516475d5d67d7efba" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hp49-c946-wfm3/GHSA-hp49-c946-wfm3.json b/advisories/unreviewed/2024/01/GHSA-hp49-c946-wfm3/GHSA-hp49-c946-wfm3.json new file mode 100644 index 00000000000..5cb01956642 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hp49-c946-wfm3/GHSA-hp49-c946-wfm3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp49-c946-wfm3", + "modified": "2024-01-05T09:30:33Z", + "published": "2024-01-05T09:30:33Z", + "aliases": [ + "CVE-2023-52128" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WhiteWP White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard.This issue affects White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard: from n/a through 2.9.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52128" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/white-label/wordpress-white-label-plugin-2-9-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jjqg-cwmg-hr6c/GHSA-jjqg-cwmg-hr6c.json b/advisories/unreviewed/2024/01/GHSA-jjqg-cwmg-hr6c/GHSA-jjqg-cwmg-hr6c.json new file mode 100644 index 00000000000..c4bb716907b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jjqg-cwmg-hr6c/GHSA-jjqg-cwmg-hr6c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjqg-cwmg-hr6c", + "modified": "2024-01-05T09:30:31Z", + "published": "2024-01-05T09:30:31Z", + "aliases": [ + "CVE-2023-52178" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MojofyWP WP Affiliate Disclosure allows Stored XSS.This issue affects WP Affiliate Disclosure: from n/a through 1.2.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52178" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-affiliate-disclosure/wordpress-wp-affiliate-disclosure-plugin-1-2-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T08:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wqfq-9j6f-q6v9/GHSA-wqfq-9j6f-q6v9.json b/advisories/unreviewed/2024/01/GHSA-wqfq-9j6f-q6v9/GHSA-wqfq-9j6f-q6v9.json new file mode 100644 index 00000000000..82ecd088a90 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wqfq-9j6f-q6v9/GHSA-wqfq-9j6f-q6v9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqfq-9j6f-q6v9", + "modified": "2024-01-05T09:30:32Z", + "published": "2024-01-05T09:30:32Z", + "aliases": [ + "CVE-2023-52123" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: from n/a through 3.1.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52123" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/strong-testimonials/wordpress-strong-testimonials-plugin-3-1-10-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xv7q-66p6-r28c/GHSA-xv7q-66p6-r28c.json b/advisories/unreviewed/2024/01/GHSA-xv7q-66p6-r28c/GHSA-xv7q-66p6-r28c.json new file mode 100644 index 00000000000..936f03cb934 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xv7q-66p6-r28c/GHSA-xv7q-66p6-r28c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv7q-66p6-r28c", + "modified": "2024-01-05T09:30:33Z", + "published": "2024-01-05T09:30:33Z", + "aliases": [ + "CVE-2023-52130" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.31.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52130" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/affiliates-manager/wordpress-affiliates-manager-plugin-2-9-31-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T09:15:09Z" + } +} \ No newline at end of file