diff --git a/advisories/unreviewed/2025/01/GHSA-92mh-5j76-2j3x/GHSA-92mh-5j76-2j3x.json b/advisories/unreviewed/2025/01/GHSA-92mh-5j76-2j3x/GHSA-92mh-5j76-2j3x.json new file mode 100644 index 00000000000..b1610e979df --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-92mh-5j76-2j3x/GHSA-92mh-5j76-2j3x.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92mh-5j76-2j3x", + "modified": "2025-01-30T09:30:37Z", + "published": "2025-01-30T09:30:37Z", + "aliases": [ + "CVE-2024-13470" + ], + "details": "The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13470" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.8.23/includes/Display/Render.php#L708" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.8.23/includes/Display/Shortcodes.php#L8" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.8.23/ninja-forms.php#L953" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3229932%40ninja-forms%2Ftrunk&old=3226451%40ninja-forms%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6f2b46a9-d228-43b4-84af-d56218076087?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T08:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cr4f-qgfw-47cw/GHSA-cr4f-qgfw-47cw.json b/advisories/unreviewed/2025/01/GHSA-cr4f-qgfw-47cw/GHSA-cr4f-qgfw-47cw.json new file mode 100644 index 00000000000..1d4c42c001b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cr4f-qgfw-47cw/GHSA-cr4f-qgfw-47cw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr4f-qgfw-47cw", + "modified": "2025-01-30T09:30:36Z", + "published": "2025-01-30T09:30:36Z", + "aliases": [ + "CVE-2024-13457" + ], + "details": "The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view order details of orders they did not place, which includes ticket prices, user emails and order date.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13457" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3229935%40event-tickets%2Ftags%2F5.18.1.1&old=3227011%40event-tickets%2Ftags%2F5.18.1" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0cc2261a-889e-40ec-8382-48de65b91b34?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j2xr-87fv-4jx3/GHSA-j2xr-87fv-4jx3.json b/advisories/unreviewed/2025/01/GHSA-j2xr-87fv-4jx3/GHSA-j2xr-87fv-4jx3.json new file mode 100644 index 00000000000..f62561129eb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j2xr-87fv-4jx3/GHSA-j2xr-87fv-4jx3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2xr-87fv-4jx3", + "modified": "2025-01-30T09:30:37Z", + "published": "2025-01-30T09:30:37Z", + "aliases": [ + "CVE-2024-13642" + ], + "details": "The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hotspot widget in all versions up to, and including, 1.4.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13642" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3228058#file6" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7ccaee26-277e-4730-8242-9b5e6a281fcc?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j569-9j78-hxg5/GHSA-j569-9j78-hxg5.json b/advisories/unreviewed/2025/01/GHSA-j569-9j78-hxg5/GHSA-j569-9j78-hxg5.json new file mode 100644 index 00000000000..c2ba55be534 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j569-9j78-hxg5/GHSA-j569-9j78-hxg5.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j569-9j78-hxg5", + "modified": "2025-01-30T09:30:37Z", + "published": "2025-01-30T09:30:37Z", + "aliases": [ + "CVE-2024-13758" + ], + "details": "The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This is due to missing or incorrect nonce validation on the cp_contact_form_paypal_check_init_actions() function. This makes it possible for unauthenticated attackers to add discount codes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13758" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/cp-contact-form-with-paypal/trunk/cp_contactformpp_functions.php#L616" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3230873" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/cp-contact-form-with-paypal/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/495183b6-dc7c-4ff7-bc99-fc05a10d1269?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pf3q-2qv4-vx44/GHSA-pf3q-2qv4-vx44.json b/advisories/unreviewed/2025/01/GHSA-pf3q-2qv4-vx44/GHSA-pf3q-2qv4-vx44.json new file mode 100644 index 00000000000..4cbf69aa033 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pf3q-2qv4-vx44/GHSA-pf3q-2qv4-vx44.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf3q-2qv4-vx44", + "modified": "2025-01-30T09:30:37Z", + "published": "2025-01-30T09:30:37Z", + "aliases": [ + "CVE-2024-13694" + ], + "details": "The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.7 via the download_pdf_file() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to extract data from wishlists that they should not have access to.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13694" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/smart-wishlist-for-more-convert/trunk/includes/class-wlfmc-form-handler.php#L607" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/smart-wishlist-for-more-convert/trunk/includes/class-wlfmc-wishlist.php#L529" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3229758" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/smart-wishlist-for-more-convert/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/59fe7630-ab94-419f-aca5-39b74d86ae4e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rgvg-2qj5-mw9w/GHSA-rgvg-2qj5-mw9w.json b/advisories/unreviewed/2025/01/GHSA-rgvg-2qj5-mw9w/GHSA-rgvg-2qj5-mw9w.json new file mode 100644 index 00000000000..6bfc9981242 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rgvg-2qj5-mw9w/GHSA-rgvg-2qj5-mw9w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgvg-2qj5-mw9w", + "modified": "2025-01-30T09:30:38Z", + "published": "2025-01-30T09:30:37Z", + "aliases": [ + "CVE-2025-0834" + ], + "details": "Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow an attacker to escalate privileges by replacing the binary ‘C:\\ProgramData\\Wondershare\\wsServices\\ElevationService.exe’ with a malicious binary. This binary will be executed by SYSTEM automatically.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0834" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/wondershare-drfone-privilege-scalation-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rpx3-33f7-v6hv/GHSA-rpx3-33f7-v6hv.json b/advisories/unreviewed/2025/01/GHSA-rpx3-33f7-v6hv/GHSA-rpx3-33f7-v6hv.json new file mode 100644 index 00000000000..df24a4de01d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rpx3-33f7-v6hv/GHSA-rpx3-33f7-v6hv.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpx3-33f7-v6hv", + "modified": "2025-01-30T09:30:37Z", + "published": "2025-01-30T09:30:37Z", + "aliases": [ + "CVE-2024-13732" + ], + "details": "The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘section_tag’ parameter in all versions up to, and including, 1.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13732" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/responsive-block-editor-addons/trunk/src/blocks/post-carousel/index.php#L643" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3231017" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/responsive-block-editor-addons" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1c0e5c85-72c3-4f09-aade-ec5a82b9cc41?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T09:15:08Z" + } +} \ No newline at end of file