Publish Advisories

GHSA-3wg5-x88w-52fj
GHSA-4hc6-gpqp-6hfp
GHSA-53mg-f6w7-m2qc
GHSA-9f2c-45xq-c486
GHSA-9pxc-g2q3-vqwv
GHSA-mh59-w44g-9pjr
GHSA-q285-mcqv-8j69
GHSA-q4c5-pfxq-m759
GHSA-qc3g-q2wx-9mq2
GHSA-r7wf-fpff-w68q
GHSA-v4cx-r43j-pwh7
GHSA-w47r-whp2-pxw8
This commit is contained in:
advisory-database[bot]
2024-10-17 06:31:36 +00:00
parent f91cf76ced
commit 3837ee2e3d
12 changed files with 378 additions and 4 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3wg5-x88w-52fj",
"modified": "2024-10-15T15:30:45Z",
"modified": "2024-10-17T06:30:32Z",
"published": "2024-10-09T18:31:43Z",
"aliases": [
"CVE-2024-9466"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/PAN-SA-2024-0010"
},
{
"type": "WEB",
"url": "https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise"
}
],
"database_specific": {
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hc6-gpqp-6hfp",
"modified": "2024-10-17T06:30:32Z",
"published": "2024-10-17T06:30:32Z",
"aliases": [
"CVE-2024-9263"
],
"details": "The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to reset the emails and passwords of arbitrary user accounts, including administrators, which makes account takeover and privilege escalation possible.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9263"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/timetics/tags/1.0.25/core/customers/customer.php#L299"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3169771/timetics/trunk/core/customers/api-customer.php"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3169771/timetics/trunk/core/customers/customer.php"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/74bd595b-d2fa-4c62-82d2-dba2c2b128f0?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-639"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T04:15:05Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53mg-f6w7-m2qc",
"modified": "2024-10-17T06:30:32Z",
"published": "2024-10-17T06:30:32Z",
"aliases": [
"CVE-2024-9347"
],
"details": "The The Ultimate WordPress Toolkit WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpext-export' parameter in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9347"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/wpextended/tags/3.0.9/includes/libraries/wpext_export/wpext_export.php#L209"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3169963/wpextended/trunk/includes/libraries/wpext_export/wpext_export.php"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/822c0a33-e57e-48c7-b8df-fddf3bb2e552?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T04:15:05Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9f2c-45xq-c486",
"modified": "2024-10-15T15:30:45Z",
"modified": "2024-10-17T06:30:32Z",
"published": "2024-10-09T18:31:43Z",
"aliases": [
"CVE-2024-9465"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/PAN-SA-2024-0010"
},
{
"type": "WEB",
"url": "https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise"
}
],
"database_specific": {
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pxc-g2q3-vqwv",
"modified": "2024-10-17T06:30:32Z",
"published": "2024-10-17T06:30:32Z",
"aliases": [
"CVE-2024-8719"
],
"details": "The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters like 'MaxBeds' and 'MinBeds' in all versions up to, and including, 3.14.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8719"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3169439%40flexmls-idx&new=3169439%40flexmls-idx&sfp_email=&sfph_mail="
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/aac3fb8e-9b92-4ed1-ac9f-50870d4c5c9f?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T04:15:05Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mh59-w44g-9pjr",
"modified": "2024-10-17T06:30:32Z",
"published": "2024-10-17T06:30:32Z",
"aliases": [
"CVE-2024-7417"
],
"details": "The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected posts.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7417"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.3.985/classes/modules/wpr-ajax-search.php#L21"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3162784/royal-elementor-addons/tags/1.3.987/classes/modules/wpr-ajax-search.php?old=3141814&old_path=royal-elementor-addons%2Ftags%2F1.3.985%2Fclasses%2Fmodules%2Fwpr-ajax-search.php"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c3dfb0b7-5d9f-492b-9a1a-d4445d39c00c?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T04:15:04Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q285-mcqv-8j69",
"modified": "2024-10-17T06:30:32Z",
"published": "2024-10-17T06:30:32Z",
"aliases": [
"CVE-2024-49593"
],
"details": "In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of ACF, then you can follow the process shown at the advancedcustomfields.com blog URL within the References section below.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49593"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/advanced-custom-fields/#developers"
},
{
"type": "WEB",
"url": "https://www.advancedcustomfields.com/blog/installing-and-upgrading-to-the-latest-version-of-acf"
},
{
"type": "WEB",
"url": "https://www.advancedcustomfields.com/changelog"
},
{
"type": "WEB",
"url": "https://x.com/wp_acf/status/1845190372764401908"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T04:15:03Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q4c5-pfxq-m759",
"modified": "2024-10-17T06:30:32Z",
"published": "2024-10-17T06:30:32Z",
"aliases": [
"CVE-2024-9352"
],
"details": "The Forminator Forms Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.35.1. This is due to missing or incorrect nonce validation on the custom form 'create_module' function. This makes it possible for unauthenticated attackers to create draft forms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9352"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.35.0/library/modules/custom-forms/admin/admin-loader.php#L418"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3169243"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/81e6e266-078a-4f4f-a335-c9d388f41ef2?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T06:15:03Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qc3g-q2wx-9mq2",
"modified": "2024-10-17T06:30:32Z",
"published": "2024-10-17T06:30:32Z",
"aliases": [
"CVE-2024-9351"
],
"details": "The Forminator Forms Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.35.1. This is due to missing or incorrect nonce validation on the quiz 'create_module' function. This makes it possible for unauthenticated attackers to create draft quizzes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9351"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.35.0/library/modules/quizzes/admin/admin-loader.php#L719"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3169243"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8d89e3b7-d980-42bb-ab0c-d86ab174a69c?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T06:15:03Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r7wf-fpff-w68q",
"modified": "2024-10-15T15:30:45Z",
"modified": "2024-10-17T06:30:32Z",
"published": "2024-10-09T18:31:43Z",
"aliases": [
"CVE-2024-9464"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/PAN-SA-2024-0010"
},
{
"type": "WEB",
"url": "https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise"
}
],
"database_specific": {
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v4cx-r43j-pwh7",
"modified": "2024-10-17T06:30:32Z",
"published": "2024-10-17T06:30:32Z",
"aliases": [
"CVE-2024-5429"
],
"details": "The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5429"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/ddb76c88-aeca-42df-830e-abffd29f1141"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-17T06:15:02Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w47r-whp2-pxw8",
"modified": "2024-10-15T21:30:36Z",
"modified": "2024-10-17T06:30:32Z",
"published": "2024-10-09T18:31:44Z",
"aliases": [
"CVE-2024-9473"
@@ -25,6 +25,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9473"
},
{
"type": "WEB",
"url": "https://sec-consult.com/vulnerability-lab/advisory/local-privilege-escalation-via-msi-installer-in-palo-alto-networks-globalprotect"
},
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/CVE-2024-9473"