From 492c2d9bebfb034beec9d85c74ba3844fab68852 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 20 Oct 2024 12:31:54 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9cp8-pr92-vg9q.json | 6 ++- .../GHSA-3j33-rhmh-72pg.json | 38 +++++++++++++++++ .../GHSA-3rw3-4f78-wjrx.json | 38 +++++++++++++++++ .../GHSA-48m6-ppwj-w9gv.json | 38 +++++++++++++++++ .../GHSA-5h9r-8hc8-mvf6.json | 38 +++++++++++++++++ .../GHSA-5vpx-jjww-7m7g.json | 38 +++++++++++++++++ .../GHSA-6chh-jphh-hchv.json | 38 +++++++++++++++++ .../GHSA-6f2g-f8p6-xq23.json | 38 +++++++++++++++++ .../GHSA-6qpx-rmj4-mcj5.json | 38 +++++++++++++++++ .../GHSA-9crx-q2j4-3x69.json | 38 +++++++++++++++++ .../GHSA-9f2q-rr78-p4xx.json | 38 +++++++++++++++++ .../GHSA-cfh3-3xc6-pccj.json | 38 +++++++++++++++++ .../GHSA-g8f9-q4m9-5f38.json | 38 +++++++++++++++++ .../GHSA-h76p-cr44-hchf.json | 38 +++++++++++++++++ .../GHSA-hrm8-rc8p-35fq.json | 38 +++++++++++++++++ .../GHSA-jm9m-h6mg-fc5j.json | 38 +++++++++++++++++ .../GHSA-jx6p-33vm-7q3r.json | 38 +++++++++++++++++ .../GHSA-m3w3-qr42-6xp4.json | 38 +++++++++++++++++ .../GHSA-p4jj-gp83-qc3g.json | 38 +++++++++++++++++ .../GHSA-qvh6-69xv-v77r.json | 38 +++++++++++++++++ .../GHSA-r53c-qq92-w6x3.json | 38 +++++++++++++++++ .../GHSA-rh5m-mw2h-v9rv.json | 42 +++++++++++++++++++ .../GHSA-v69r-9546-4ccm.json | 38 +++++++++++++++++ .../GHSA-vpc4-q7gx-ppmw.json | 38 +++++++++++++++++ .../GHSA-w4xx-xxh4-422c.json | 38 +++++++++++++++++ .../GHSA-x2fw-rvp7-jwxc.json | 38 +++++++++++++++++ .../GHSA-xwg4-3m43-wmp8.json | 38 +++++++++++++++++ 27 files changed, 997 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-3j33-rhmh-72pg/GHSA-3j33-rhmh-72pg.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3rw3-4f78-wjrx/GHSA-3rw3-4f78-wjrx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-48m6-ppwj-w9gv/GHSA-48m6-ppwj-w9gv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5h9r-8hc8-mvf6/GHSA-5h9r-8hc8-mvf6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5vpx-jjww-7m7g/GHSA-5vpx-jjww-7m7g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6chh-jphh-hchv/GHSA-6chh-jphh-hchv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6f2g-f8p6-xq23/GHSA-6f2g-f8p6-xq23.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6qpx-rmj4-mcj5/GHSA-6qpx-rmj4-mcj5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9crx-q2j4-3x69/GHSA-9crx-q2j4-3x69.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9f2q-rr78-p4xx/GHSA-9f2q-rr78-p4xx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cfh3-3xc6-pccj/GHSA-cfh3-3xc6-pccj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g8f9-q4m9-5f38/GHSA-g8f9-q4m9-5f38.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h76p-cr44-hchf/GHSA-h76p-cr44-hchf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hrm8-rc8p-35fq/GHSA-hrm8-rc8p-35fq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jm9m-h6mg-fc5j/GHSA-jm9m-h6mg-fc5j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jx6p-33vm-7q3r/GHSA-jx6p-33vm-7q3r.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m3w3-qr42-6xp4/GHSA-m3w3-qr42-6xp4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-p4jj-gp83-qc3g/GHSA-p4jj-gp83-qc3g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qvh6-69xv-v77r/GHSA-qvh6-69xv-v77r.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r53c-qq92-w6x3/GHSA-r53c-qq92-w6x3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rh5m-mw2h-v9rv/GHSA-rh5m-mw2h-v9rv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v69r-9546-4ccm/GHSA-v69r-9546-4ccm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vpc4-q7gx-ppmw/GHSA-vpc4-q7gx-ppmw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w4xx-xxh4-422c/GHSA-w4xx-xxh4-422c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x2fw-rvp7-jwxc/GHSA-x2fw-rvp7-jwxc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xwg4-3m43-wmp8/GHSA-xwg4-3m43-wmp8.json diff --git a/advisories/unreviewed/2024/06/GHSA-9cp8-pr92-vg9q/GHSA-9cp8-pr92-vg9q.json b/advisories/unreviewed/2024/06/GHSA-9cp8-pr92-vg9q/GHSA-9cp8-pr92-vg9q.json index 1d74b2ea65b..ccb67058e4c 100644 --- a/advisories/unreviewed/2024/06/GHSA-9cp8-pr92-vg9q/GHSA-9cp8-pr92-vg9q.json +++ b/advisories/unreviewed/2024/06/GHSA-9cp8-pr92-vg9q/GHSA-9cp8-pr92-vg9q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9cp8-pr92-vg9q", - "modified": "2024-06-24T12:30:39Z", + "modified": "2024-10-20T12:30:29Z", "published": "2024-06-24T12:30:39Z", "aliases": [ "CVE-2024-37091" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://patchstack.com/database/vulnerability/consulting-elementor-widgets/wordpress-consulting-elementor-widgets-plugin-1-3-0-remote-code-execution-rce-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/masterstudy-elementor-widgets/wordpress-masterstudy-elementor-widgets-plugin-1-2-2-remote-code-execution-rce-vulnerability?_s_id=cve" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-3j33-rhmh-72pg/GHSA-3j33-rhmh-72pg.json b/advisories/unreviewed/2024/10/GHSA-3j33-rhmh-72pg/GHSA-3j33-rhmh-72pg.json new file mode 100644 index 00000000000..bbbe0fd0e69 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3j33-rhmh-72pg/GHSA-3j33-rhmh-72pg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j33-rhmh-72pg", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49620" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Naudin Vladimir FERMA.Ru.Net allows Blind SQL Injection.This issue affects FERMA.Ru.Net: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49620" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ferma-ru-net-checkout/wordpress-ferma-ru-net-plugin-1-3-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3rw3-4f78-wjrx/GHSA-3rw3-4f78-wjrx.json b/advisories/unreviewed/2024/10/GHSA-3rw3-4f78-wjrx/GHSA-3rw3-4f78-wjrx.json new file mode 100644 index 00000000000..8b2a269ab65 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3rw3-4f78-wjrx/GHSA-3rw3-4f78-wjrx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rw3-4f78-wjrx", + "modified": "2024-10-20T12:30:29Z", + "published": "2024-10-20T12:30:29Z", + "aliases": [ + "CVE-2024-49605" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Avchat.Net AVChat Video Chat allows Stored XSS.This issue affects AVChat Video Chat: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49605" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/avchat-3/wordpress-community-lite-video-chat-plugin-2-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-48m6-ppwj-w9gv/GHSA-48m6-ppwj-w9gv.json b/advisories/unreviewed/2024/10/GHSA-48m6-ppwj-w9gv/GHSA-48m6-ppwj-w9gv.json new file mode 100644 index 00000000000..3136acfdb74 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-48m6-ppwj-w9gv/GHSA-48m6-ppwj-w9gv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48m6-ppwj-w9gv", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49615" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Henrique Rodrigues SafetyForms allows Blind SQL Injection.This issue affects SafetyForms: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49615" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/safetymails-forms/wordpress-safetyforms-plugin-1-0-0-csrf-to-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5h9r-8hc8-mvf6/GHSA-5h9r-8hc8-mvf6.json b/advisories/unreviewed/2024/10/GHSA-5h9r-8hc8-mvf6/GHSA-5h9r-8hc8-mvf6.json new file mode 100644 index 00000000000..9dc92426ccb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5h9r-8hc8-mvf6/GHSA-5h9r-8hc8-mvf6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h9r-8hc8-mvf6", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49272" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPWeb Social Auto Poster allows Cross Site Request Forgery.This issue affects Social Auto Poster: from n/a through 5.3.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49272" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/social-auto-poster/wordpress-social-auto-poster-plugin-5-3-15-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T11:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5vpx-jjww-7m7g/GHSA-5vpx-jjww-7m7g.json b/advisories/unreviewed/2024/10/GHSA-5vpx-jjww-7m7g/GHSA-5vpx-jjww-7m7g.json new file mode 100644 index 00000000000..4f2cedd1dd1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5vpx-jjww-7m7g/GHSA-5vpx-jjww-7m7g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vpx-jjww-7m7g", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49617" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Back Link Tracker allows Blind SQL Injection.This issue affects Back Link Tracker: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49617" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/back-link-tracker/wordpress-back-link-tracker-plugin-1-0-0-csrf-to-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6chh-jphh-hchv/GHSA-6chh-jphh-hchv.json b/advisories/unreviewed/2024/10/GHSA-6chh-jphh-hchv/GHSA-6chh-jphh-hchv.json new file mode 100644 index 00000000000..9d36fb44573 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6chh-jphh-hchv/GHSA-6chh-jphh-hchv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6chh-jphh-hchv", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49609" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brandon White Author Discussion allows Blind SQL Injection.This issue affects Author Discussion: from n/a through 0.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49609" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/author-discussion/wordpress-author-discussion-plugin-0-2-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6f2g-f8p6-xq23/GHSA-6f2g-f8p6-xq23.json b/advisories/unreviewed/2024/10/GHSA-6f2g-f8p6-xq23/GHSA-6f2g-f8p6-xq23.json new file mode 100644 index 00000000000..340b1f96b9e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6f2g-f8p6-xq23/GHSA-6f2g-f8p6-xq23.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f2g-f8p6-xq23", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49614" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dan Alexander SermonAudio Widgets allows SQL Injection.This issue affects SermonAudio Widgets: from n/a through 1.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49614" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sermonaudio-widgets/wordpress-sermonaudio-widgets-plugin-1-9-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6qpx-rmj4-mcj5/GHSA-6qpx-rmj4-mcj5.json b/advisories/unreviewed/2024/10/GHSA-6qpx-rmj4-mcj5/GHSA-6qpx-rmj4-mcj5.json new file mode 100644 index 00000000000..501c3154882 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6qpx-rmj4-mcj5/GHSA-6qpx-rmj4-mcj5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qpx-rmj4-mcj5", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49275" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson IdeaPush allows Cross Site Request Forgery.This issue affects IdeaPush: from n/a through 8.69.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49275" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ideapush/wordpress-ideapush-plugin-8-69-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T11:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9crx-q2j4-3x69/GHSA-9crx-q2j4-3x69.json b/advisories/unreviewed/2024/10/GHSA-9crx-q2j4-3x69/GHSA-9crx-q2j4-3x69.json new file mode 100644 index 00000000000..74ee2eefad9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9crx-q2j4-3x69/GHSA-9crx-q2j4-3x69.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9crx-q2j4-3x69", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49627" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Noor Alam WordPress Image SEO allows Cross Site Request Forgery.This issue affects WordPress Image SEO: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49627" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-image-seo/wordpress-wordpress-image-seo-plugin-1-1-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T11:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9f2q-rr78-p4xx/GHSA-9f2q-rr78-p4xx.json b/advisories/unreviewed/2024/10/GHSA-9f2q-rr78-p4xx/GHSA-9f2q-rr78-p4xx.json new file mode 100644 index 00000000000..699544de27c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9f2q-rr78-p4xx/GHSA-9f2q-rr78-p4xx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f2q-rr78-p4xx", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49618" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jordan Lyall MyTweetLinks allows Blind SQL Injection.This issue affects MyTweetLinks: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49618" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mytweetlinks/wordpress-mytweetlinks-plugin-1-1-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cfh3-3xc6-pccj/GHSA-cfh3-3xc6-pccj.json b/advisories/unreviewed/2024/10/GHSA-cfh3-3xc6-pccj/GHSA-cfh3-3xc6-pccj.json new file mode 100644 index 00000000000..f4d2f1585d0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cfh3-3xc6-pccj/GHSA-cfh3-3xc6-pccj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfh3-3xc6-pccj", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49290" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Gora Tech LLC Cooked Pro allows Cross Site Request Forgery.This issue affects Cooked Pro: from n/a before 1.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49290" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cooked-pro/wordpress-cooked-pro-plugin-1-8-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T11:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g8f9-q4m9-5f38/GHSA-g8f9-q4m9-5f38.json b/advisories/unreviewed/2024/10/GHSA-g8f9-q4m9-5f38/GHSA-g8f9-q4m9-5f38.json new file mode 100644 index 00000000000..4d9fb0527c9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g8f9-q4m9-5f38/GHSA-g8f9-q4m9-5f38.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8f9-q4m9-5f38", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-47634" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Streamline.Lv CartBounty – Save and recover abandoned carts for WooCommerce allows Cross Site Request Forgery.This issue affects CartBounty – Save and recover abandoned carts for WooCommerce: from n/a through 8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47634" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-save-abandoned-carts/wordpress-cartbounty-plugin-8-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T11:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h76p-cr44-hchf/GHSA-h76p-cr44-hchf.json b/advisories/unreviewed/2024/10/GHSA-h76p-cr44-hchf/GHSA-h76p-cr44-hchf.json new file mode 100644 index 00000000000..a42ab871d13 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h76p-cr44-hchf/GHSA-h76p-cr44-hchf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h76p-cr44-hchf", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49612" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infotuts SW Contact Form allows Blind SQL Injection.This issue affects SW Contact Form: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49612" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sw-contact-form/wordpress-sw-contact-form-plugin-1-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hrm8-rc8p-35fq/GHSA-hrm8-rc8p-35fq.json b/advisories/unreviewed/2024/10/GHSA-hrm8-rc8p-35fq/GHSA-hrm8-rc8p-35fq.json new file mode 100644 index 00000000000..c038fea79d9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hrm8-rc8p-35fq/GHSA-hrm8-rc8p-35fq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrm8-rc8p-35fq", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49619" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Acespritech Solutions Pvt. Ltd. Social Link Groups allows Blind SQL Injection.This issue affects Social Link Groups: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49619" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/social-link-groups/wordpress-social-link-groups-plugin-1-1-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jm9m-h6mg-fc5j/GHSA-jm9m-h6mg-fc5j.json b/advisories/unreviewed/2024/10/GHSA-jm9m-h6mg-fc5j/GHSA-jm9m-h6mg-fc5j.json new file mode 100644 index 00000000000..3c0984401ad --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jm9m-h6mg-fc5j/GHSA-jm9m-h6mg-fc5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm9m-h6mg-fc5j", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49274" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Infomaniak Staff VOD Infomaniak allows Cross Site Request Forgery.This issue affects VOD Infomaniak: from n/a through 1.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49274" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/vod-infomaniak/wordpress-vod-infomaniak-plugin-1-5-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T11:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jx6p-33vm-7q3r/GHSA-jx6p-33vm-7q3r.json b/advisories/unreviewed/2024/10/GHSA-jx6p-33vm-7q3r/GHSA-jx6p-33vm-7q3r.json new file mode 100644 index 00000000000..219363feefc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jx6p-33vm-7q3r/GHSA-jx6p-33vm-7q3r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx6p-33vm-7q3r", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49325" + ], + "details": "Subscriber Broken Access Control in Photo Gallery Builder <= 3.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49325" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/photo-gallery-builder/wordpress-photo-gallery-builder-plugin-3-0-broken-access-control-to-notice-dismissal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T11:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m3w3-qr42-6xp4/GHSA-m3w3-qr42-6xp4.json b/advisories/unreviewed/2024/10/GHSA-m3w3-qr42-6xp4/GHSA-m3w3-qr42-6xp4.json new file mode 100644 index 00000000000..18922f72449 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m3w3-qr42-6xp4/GHSA-m3w3-qr42-6xp4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3w3-qr42-6xp4", + "modified": "2024-10-20T12:30:29Z", + "published": "2024-10-20T12:30:29Z", + "aliases": [ + "CVE-2024-47325" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows SQL Injection.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47325" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/multiple-pages-generator-by-porthas/wordpress-multiple-page-generator-plugin-mpg-plugin-3-4-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p4jj-gp83-qc3g/GHSA-p4jj-gp83-qc3g.json b/advisories/unreviewed/2024/10/GHSA-p4jj-gp83-qc3g/GHSA-p4jj-gp83-qc3g.json new file mode 100644 index 00000000000..5a6d119103e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p4jj-gp83-qc3g/GHSA-p4jj-gp83-qc3g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4jj-gp83-qc3g", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49616" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nyasro Rate Own Post allows Blind SQL Injection.This issue affects Rate Own Post: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49616" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rate-own-post/wordpress-rate-own-post-plugin-1-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qvh6-69xv-v77r/GHSA-qvh6-69xv-v77r.json b/advisories/unreviewed/2024/10/GHSA-qvh6-69xv-v77r/GHSA-qvh6-69xv-v77r.json new file mode 100644 index 00000000000..c4269dc2d5a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qvh6-69xv-v77r/GHSA-qvh6-69xv-v77r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvh6-69xv-v77r", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49250" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Michael Tran Table of Contents Plus allows Cross Site Request Forgery.This issue affects Table of Contents Plus: from n/a through 2408.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49250" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/table-of-contents-plus/wordpress-table-of-contents-plus-plugin-2408-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T11:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r53c-qq92-w6x3/GHSA-r53c-qq92-w6x3.json b/advisories/unreviewed/2024/10/GHSA-r53c-qq92-w6x3/GHSA-r53c-qq92-w6x3.json new file mode 100644 index 00000000000..ec8d45313d7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r53c-qq92-w6x3/GHSA-r53c-qq92-w6x3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r53c-qq92-w6x3", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49613" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lodel Geraldo Simple Code Insert Shortcode allows SQL Injection.This issue affects Simple Code Insert Shortcode: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49613" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-code-insert-shortcode/wordpress-simple-code-insert-shortcode-plugin-1-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rh5m-mw2h-v9rv/GHSA-rh5m-mw2h-v9rv.json b/advisories/unreviewed/2024/10/GHSA-rh5m-mw2h-v9rv/GHSA-rh5m-mw2h-v9rv.json new file mode 100644 index 00000000000..65b3a798566 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rh5m-mw2h-v9rv/GHSA-rh5m-mw2h-v9rv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh5m-mw2h-v9rv", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-44000" + ], + "details": "Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a before 6.5.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44000" + }, + { + "type": "WEB", + "url": "https://patchstack.com/articles/critical-account-takeover-vulnerability-patched-in-litespeed-cache-plugin?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/litespeed-cache/wordpress-litespeed-cache-plugin-6-5-0-1-unauthenticated-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v69r-9546-4ccm/GHSA-v69r-9546-4ccm.json b/advisories/unreviewed/2024/10/GHSA-v69r-9546-4ccm/GHSA-v69r-9546-4ccm.json new file mode 100644 index 00000000000..4220da01716 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v69r-9546-4ccm/GHSA-v69r-9546-4ccm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v69r-9546-4ccm", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49628" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WhileTrue Most And Least Read Posts Widget allows Cross Site Request Forgery.This issue affects Most And Least Read Posts Widget: from n/a through 2.5.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49628" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/most-and-least-read-posts-widget/wordpress-most-and-least-read-posts-widget-plugin-2-5-18-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T11:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vpc4-q7gx-ppmw/GHSA-vpc4-q7gx-ppmw.json b/advisories/unreviewed/2024/10/GHSA-vpc4-q7gx-ppmw/GHSA-vpc4-q7gx-ppmw.json new file mode 100644 index 00000000000..48e1ab23676 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vpc4-q7gx-ppmw/GHSA-vpc4-q7gx-ppmw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpc4-q7gx-ppmw", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49306" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP-buy WP Content Copy Protection & No Right Click allows Cross Site Request Forgery.This issue affects WP Content Copy Protection & No Right Click: from n/a through 3.5.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49306" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-content-copy-protector/wordpress-wp-content-copy-protection-no-right-click-plugin-3-5-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T11:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w4xx-xxh4-422c/GHSA-w4xx-xxh4-422c.json b/advisories/unreviewed/2024/10/GHSA-w4xx-xxh4-422c/GHSA-w4xx-xxh4-422c.json new file mode 100644 index 00000000000..a5ce0010eb6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w4xx-xxh4-422c/GHSA-w4xx-xxh4-422c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4xx-xxh4-422c", + "modified": "2024-10-20T12:30:29Z", + "published": "2024-10-20T12:30:29Z", + "aliases": [ + "CVE-2024-44061" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WPFactory EU/UK VAT Manager for WooCommerce allows Cross-Site Scripting (XSS).This issue affects EU/UK VAT Manager for WooCommerce: from n/a through 2.12.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44061" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/eu-vat-for-woocommerce/wordpress-eu-uk-vat-manager-for-woocommerce-plugin-2-12-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x2fw-rvp7-jwxc/GHSA-x2fw-rvp7-jwxc.json b/advisories/unreviewed/2024/10/GHSA-x2fw-rvp7-jwxc/GHSA-x2fw-rvp7-jwxc.json new file mode 100644 index 00000000000..2c0516b1124 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x2fw-rvp7-jwxc/GHSA-x2fw-rvp7-jwxc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2fw-rvp7-jwxc", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:29Z", + "aliases": [ + "CVE-2024-49335" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Edush Maxim GoogleDrive folder list allows Stored XSS.This issue affects GoogleDrive folder list: from n/a through 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49335" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/googledrive-folder-list/wordpress-googledrive-folder-list-plugin-2-2-2-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xwg4-3m43-wmp8/GHSA-xwg4-3m43-wmp8.json b/advisories/unreviewed/2024/10/GHSA-xwg4-3m43-wmp8/GHSA-xwg4-3m43-wmp8.json new file mode 100644 index 00000000000..826d66c9089 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xwg4-3m43-wmp8/GHSA-xwg4-3m43-wmp8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwg4-3m43-wmp8", + "modified": "2024-10-20T12:30:30Z", + "published": "2024-10-20T12:30:30Z", + "aliases": [ + "CVE-2024-49629" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation allows Stored XSS.This issue affects Endless Posts Navigation: from n/a through 2.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49629" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/endless-posts-navigation/wordpress-endless-posts-navigation-plugin-2-2-7-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-20T10:15:05Z" + } +} \ No newline at end of file