diff --git a/advisories/unreviewed/2024/05/GHSA-72vc-f76g-4qq4/GHSA-72vc-f76g-4qq4.json b/advisories/unreviewed/2024/05/GHSA-72vc-f76g-4qq4/GHSA-72vc-f76g-4qq4.json new file mode 100644 index 00000000000..2104b89b5b4 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-72vc-f76g-4qq4/GHSA-72vc-f76g-4qq4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72vc-f76g-4qq4", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-3477" + ], + "details": "The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting popups via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3477" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ca5e59e6-c500-4129-997b-391cdf9aa9c7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fr47-p696-mm9v/GHSA-fr47-p696-mm9v.json b/advisories/unreviewed/2024/05/GHSA-fr47-p696-mm9v/GHSA-fr47-p696-mm9v.json new file mode 100644 index 00000000000..ebe91ab98a3 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fr47-p696-mm9v/GHSA-fr47-p696-mm9v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr47-p696-mm9v", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-3474" + ], + "details": "The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3474" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e5c3e145-6738-4d85-8507-43ca1b1d5877" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json b/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json new file mode 100644 index 00000000000..03b7eb97548 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwqx-m7rc-2c9p", + "modified": "2024-05-02T06:30:32Z", + "published": "2024-05-02T06:30:32Z", + "aliases": [ + "CVE-2024-3481" + ], + "details": "The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3481" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0c441293-e7f9-4634-8f3a-09925cd2b696" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json b/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json new file mode 100644 index 00000000000..bbc516897f7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgmj-jff7-4w5p", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-2405" + ], + "details": "The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2405" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c42ffa15-6ebe-4c70-9e51-b95bd05ea04d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json b/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json new file mode 100644 index 00000000000..52d29622fad --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6qv-frqj-63r6", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-3471" + ], + "details": "The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3471" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a3c282fb-81b8-48bf-8c18-8366ea8ad9af" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json b/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json new file mode 100644 index 00000000000..899b7d35d28 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2rv-8vw7-735j", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-3476" + ], + "details": "The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3476" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/46f74493-9082-48b2-90bc-2c1d1db64ccd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-w2x6-9r88-x4c6/GHSA-w2x6-9r88-x4c6.json b/advisories/unreviewed/2024/05/GHSA-w2x6-9r88-x4c6/GHSA-w2x6-9r88-x4c6.json new file mode 100644 index 00000000000..81e9d3e3324 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-w2x6-9r88-x4c6/GHSA-w2x6-9r88-x4c6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2x6-9r88-x4c6", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-3475" + ], + "details": "The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3475" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/bf540242-5306-4c94-ad50-782d0d5b127f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-wwjm-ww5x-84hm/GHSA-wwjm-ww5x-84hm.json b/advisories/unreviewed/2024/05/GHSA-wwjm-ww5x-84hm/GHSA-wwjm-ww5x-84hm.json new file mode 100644 index 00000000000..b598358468d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-wwjm-ww5x-84hm/GHSA-wwjm-ww5x-84hm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwjm-ww5x-84hm", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-3472" + ], + "details": "The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3472" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d42f74dd-520f-40aa-9cf0-3544db9562c7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json b/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json new file mode 100644 index 00000000000..cf9820963f1 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmjw-8f7c-p37x", + "modified": "2024-05-02T06:30:32Z", + "published": "2024-05-02T06:30:32Z", + "aliases": [ + "CVE-2024-3478" + ], + "details": "The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3478" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/09f1a696-86ee-47cc-99de-57cfd2a3219d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:51Z" + } +} \ No newline at end of file