Publish Advisories

GHSA-72vc-f76g-4qq4
GHSA-fr47-p696-mm9v
GHSA-gwqx-m7rc-2c9p
GHSA-mgmj-jff7-4w5p
GHSA-p6qv-frqj-63r6
GHSA-w2rv-8vw7-735j
GHSA-w2x6-9r88-x4c6
GHSA-wwjm-ww5x-84hm
GHSA-xmjw-8f7c-p37x
This commit is contained in:
advisory-database[bot]
2024-05-02 06:31:53 +00:00
parent ffb4c092ff
commit 51e5191784
9 changed files with 315 additions and 0 deletions
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-72vc-f76g-4qq4",
"modified": "2024-05-02T06:30:31Z",
"published": "2024-05-02T06:30:31Z",
"aliases": [
"CVE-2024-3477"
],
"details": "The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting popups via CSRF attacks",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3477"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/ca5e59e6-c500-4129-997b-391cdf9aa9c7"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T06:15:50Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fr47-p696-mm9v",
"modified": "2024-05-02T06:30:31Z",
"published": "2024-05-02T06:30:31Z",
"aliases": [
"CVE-2024-3474"
],
"details": "The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3474"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/e5c3e145-6738-4d85-8507-43ca1b1d5877"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T06:15:50Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gwqx-m7rc-2c9p",
"modified": "2024-05-02T06:30:32Z",
"published": "2024-05-02T06:30:32Z",
"aliases": [
"CVE-2024-3481"
],
"details": "The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3481"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/0c441293-e7f9-4634-8f3a-09925cd2b696"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T06:15:51Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mgmj-jff7-4w5p",
"modified": "2024-05-02T06:30:31Z",
"published": "2024-05-02T06:30:31Z",
"aliases": [
"CVE-2024-2405"
],
"details": "The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2405"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/c42ffa15-6ebe-4c70-9e51-b95bd05ea04d"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T06:15:49Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p6qv-frqj-63r6",
"modified": "2024-05-02T06:30:31Z",
"published": "2024-05-02T06:30:31Z",
"aliases": [
"CVE-2024-3471"
],
"details": "The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3471"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/a3c282fb-81b8-48bf-8c18-8366ea8ad9af"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T06:15:50Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w2rv-8vw7-735j",
"modified": "2024-05-02T06:30:31Z",
"published": "2024-05-02T06:30:31Z",
"aliases": [
"CVE-2024-3476"
],
"details": "The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3476"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/46f74493-9082-48b2-90bc-2c1d1db64ccd"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T06:15:50Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w2x6-9r88-x4c6",
"modified": "2024-05-02T06:30:31Z",
"published": "2024-05-02T06:30:31Z",
"aliases": [
"CVE-2024-3475"
],
"details": "The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3475"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/bf540242-5306-4c94-ad50-782d0d5b127f"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T06:15:50Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wwjm-ww5x-84hm",
"modified": "2024-05-02T06:30:31Z",
"published": "2024-05-02T06:30:31Z",
"aliases": [
"CVE-2024-3472"
],
"details": "The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3472"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/d42f74dd-520f-40aa-9cf0-3544db9562c7"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T06:15:50Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xmjw-8f7c-p37x",
"modified": "2024-05-02T06:30:32Z",
"published": "2024-05-02T06:30:32Z",
"aliases": [
"CVE-2024-3478"
],
"details": "The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3478"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/09f1a696-86ee-47cc-99de-57cfd2a3219d"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-02T06:15:51Z"
}
}