diff --git a/advisories/unreviewed/2025/04/GHSA-2q5m-vpfx-7jxh/GHSA-2q5m-vpfx-7jxh.json b/advisories/unreviewed/2025/04/GHSA-2q5m-vpfx-7jxh/GHSA-2q5m-vpfx-7jxh.json new file mode 100644 index 00000000000..4c71f2189fb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2q5m-vpfx-7jxh/GHSA-2q5m-vpfx-7jxh.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q5m-vpfx-7jxh", + "modified": "2025-04-05T06:30:21Z", + "published": "2025-04-05T06:30:21Z", + "aliases": [ + "CVE-2025-2789" + ], + "details": "The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_table_rate_shipping_row function in all versions up to, and including, 4.2.19. This makes it possible for unauthenticated attackers to delete Table Rates that can impact the shipping cost calculations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2789" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/dc-woocommerce-multi-vendor/tags/4.2.19/packages/mvx-tablerate/mvx-tablerate.php#L211" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/dc-woocommerce-multi-vendor/tags/4.2.19/packages/mvx-tablerate/mvx-tablerate.php#L78" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bf4eca37-066f-428c-a4f7-061ce06e1142?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-05T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2xch-5969-phfh/GHSA-2xch-5969-phfh.json b/advisories/unreviewed/2025/04/GHSA-2xch-5969-phfh/GHSA-2xch-5969-phfh.json new file mode 100644 index 00000000000..ed476353c8c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2xch-5969-phfh/GHSA-2xch-5969-phfh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xch-5969-phfh", + "modified": "2025-04-05T06:30:20Z", + "published": "2025-04-05T06:30:20Z", + "aliases": [ + "CVE-2025-32352" + ], + "details": "A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32352" + }, + { + "type": "WEB", + "url": "https://projectblack.io/blog/zendto-nday-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-05T05:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-63mg-cpcc-3q63/GHSA-63mg-cpcc-3q63.json b/advisories/unreviewed/2025/04/GHSA-63mg-cpcc-3q63/GHSA-63mg-cpcc-3q63.json new file mode 100644 index 00000000000..b5969f66c7f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-63mg-cpcc-3q63/GHSA-63mg-cpcc-3q63.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63mg-cpcc-3q63", + "modified": "2025-04-05T06:30:20Z", + "published": "2025-04-05T06:30:20Z", + "aliases": [ + "CVE-2024-13776" + ], + "details": "The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versions up to, and including, 6.91. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to 'seen' on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service to legitimate users or be used to set some values to true such as registration. There are several other functions also vulnerable to missing authorization.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13776" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/zoomsounds-wordpress-wave-audio-player-with-playlist/6181433" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0c8e538b-7157-42d3-abee-8259c6715cd5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-05T06:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c57h-rx24-vf52/GHSA-c57h-rx24-vf52.json b/advisories/unreviewed/2025/04/GHSA-c57h-rx24-vf52/GHSA-c57h-rx24-vf52.json index d941967113b..4e6d6371878 100644 --- a/advisories/unreviewed/2025/04/GHSA-c57h-rx24-vf52/GHSA-c57h-rx24-vf52.json +++ b/advisories/unreviewed/2025/04/GHSA-c57h-rx24-vf52/GHSA-c57h-rx24-vf52.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c57h-rx24-vf52", - "modified": "2025-04-03T21:32:59Z", + "modified": "2025-04-05T06:30:19Z", "published": "2025-04-03T21:32:59Z", "aliases": [ "CVE-2025-31161" @@ -30,6 +30,14 @@ { "type": "WEB", "url": "https://projectdiscovery.io/blog/crushftp-authentication-bypass" + }, + { + "type": "WEB", + "url": "https://www.darkreading.com/vulnerabilities-threats/disclosure-drama-clouds-crushftp-vulnerability-exploitation" + }, + { + "type": "WEB", + "url": "https://www.huntress.com/blog/crushftp-cve-2025-31161-auth-bypass-and-post-exploitation" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-gr28-46gw-83px/GHSA-gr28-46gw-83px.json b/advisories/unreviewed/2025/04/GHSA-gr28-46gw-83px/GHSA-gr28-46gw-83px.json new file mode 100644 index 00000000000..c961b23dc76 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gr28-46gw-83px/GHSA-gr28-46gw-83px.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr28-46gw-83px", + "modified": "2025-04-05T06:30:20Z", + "published": "2025-04-05T06:30:20Z", + "aliases": [ + "CVE-2025-1233" + ], + "details": "The Lafka Plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_options_upload' AJAX function in all versions up to, and including, 7.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the theme option that overrides the site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1233" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/lafka-fast-food-restaurant-woocommerce-theme/23969682" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/865b87a8-ab8a-4054-9e18-50693023cb96?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-05T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jq6v-cgfx-qfjg/GHSA-jq6v-cgfx-qfjg.json b/advisories/unreviewed/2025/04/GHSA-jq6v-cgfx-qfjg/GHSA-jq6v-cgfx-qfjg.json new file mode 100644 index 00000000000..24ed9ab1659 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jq6v-cgfx-qfjg/GHSA-jq6v-cgfx-qfjg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq6v-cgfx-qfjg", + "modified": "2025-04-05T06:30:20Z", + "published": "2025-04-05T06:30:20Z", + "aliases": [ + "CVE-2025-0839" + ], + "details": "The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0839" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/zoomsounds-wordpress-wave-audio-player-with-playlist/6181433" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/49b76f5f-03f7-48bc-b848-9ab55d875639?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-05T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r4mc-p68x-wx22/GHSA-r4mc-p68x-wx22.json b/advisories/unreviewed/2025/04/GHSA-r4mc-p68x-wx22/GHSA-r4mc-p68x-wx22.json new file mode 100644 index 00000000000..6a105bc0a7d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r4mc-p68x-wx22/GHSA-r4mc-p68x-wx22.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4mc-p68x-wx22", + "modified": "2025-04-05T06:30:20Z", + "published": "2025-04-05T06:30:20Z", + "aliases": [ + "CVE-2021-47667" + ], + "details": "An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via shell metacharacters in the tmp_name parameter when dropping off a file via a POST /dropoff request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47667" + }, + { + "type": "WEB", + "url": "https://projectblack.io/blog/zendto-nday-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-05T05:15:43Z" + } +} \ No newline at end of file