From 51e519178410bc710176555523b185084b816492 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 2 May 2024 06:31:53 +0000 Subject: [PATCH] Publish Advisories GHSA-72vc-f76g-4qq4 GHSA-fr47-p696-mm9v GHSA-gwqx-m7rc-2c9p GHSA-mgmj-jff7-4w5p GHSA-p6qv-frqj-63r6 GHSA-w2rv-8vw7-735j GHSA-w2x6-9r88-x4c6 GHSA-wwjm-ww5x-84hm GHSA-xmjw-8f7c-p37x --- .../GHSA-72vc-f76g-4qq4.json | 35 +++++++++++++++++++ .../GHSA-fr47-p696-mm9v.json | 35 +++++++++++++++++++ .../GHSA-gwqx-m7rc-2c9p.json | 35 +++++++++++++++++++ .../GHSA-mgmj-jff7-4w5p.json | 35 +++++++++++++++++++ .../GHSA-p6qv-frqj-63r6.json | 35 +++++++++++++++++++ .../GHSA-w2rv-8vw7-735j.json | 35 +++++++++++++++++++ .../GHSA-w2x6-9r88-x4c6.json | 35 +++++++++++++++++++ .../GHSA-wwjm-ww5x-84hm.json | 35 +++++++++++++++++++ .../GHSA-xmjw-8f7c-p37x.json | 35 +++++++++++++++++++ 9 files changed, 315 insertions(+) create mode 100644 advisories/unreviewed/2024/05/GHSA-72vc-f76g-4qq4/GHSA-72vc-f76g-4qq4.json create mode 100644 advisories/unreviewed/2024/05/GHSA-fr47-p696-mm9v/GHSA-fr47-p696-mm9v.json create mode 100644 advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json create mode 100644 advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json create mode 100644 advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json create mode 100644 advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json create mode 100644 advisories/unreviewed/2024/05/GHSA-w2x6-9r88-x4c6/GHSA-w2x6-9r88-x4c6.json create mode 100644 advisories/unreviewed/2024/05/GHSA-wwjm-ww5x-84hm/GHSA-wwjm-ww5x-84hm.json create mode 100644 advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json diff --git a/advisories/unreviewed/2024/05/GHSA-72vc-f76g-4qq4/GHSA-72vc-f76g-4qq4.json b/advisories/unreviewed/2024/05/GHSA-72vc-f76g-4qq4/GHSA-72vc-f76g-4qq4.json new file mode 100644 index 00000000000..2104b89b5b4 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-72vc-f76g-4qq4/GHSA-72vc-f76g-4qq4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72vc-f76g-4qq4", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-3477" + ], + "details": "The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting popups via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3477" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ca5e59e6-c500-4129-997b-391cdf9aa9c7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fr47-p696-mm9v/GHSA-fr47-p696-mm9v.json b/advisories/unreviewed/2024/05/GHSA-fr47-p696-mm9v/GHSA-fr47-p696-mm9v.json new file mode 100644 index 00000000000..ebe91ab98a3 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fr47-p696-mm9v/GHSA-fr47-p696-mm9v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr47-p696-mm9v", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-3474" + ], + "details": "The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3474" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e5c3e145-6738-4d85-8507-43ca1b1d5877" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json b/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json new file mode 100644 index 00000000000..03b7eb97548 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-gwqx-m7rc-2c9p/GHSA-gwqx-m7rc-2c9p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwqx-m7rc-2c9p", + "modified": "2024-05-02T06:30:32Z", + "published": "2024-05-02T06:30:32Z", + "aliases": [ + "CVE-2024-3481" + ], + "details": "The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3481" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0c441293-e7f9-4634-8f3a-09925cd2b696" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json b/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json new file mode 100644 index 00000000000..bbc516897f7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-mgmj-jff7-4w5p/GHSA-mgmj-jff7-4w5p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgmj-jff7-4w5p", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-2405" + ], + "details": "The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2405" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c42ffa15-6ebe-4c70-9e51-b95bd05ea04d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json b/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json new file mode 100644 index 00000000000..52d29622fad --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6qv-frqj-63r6", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-3471" + ], + "details": "The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3471" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a3c282fb-81b8-48bf-8c18-8366ea8ad9af" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json b/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json new file mode 100644 index 00000000000..899b7d35d28 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-w2rv-8vw7-735j/GHSA-w2rv-8vw7-735j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2rv-8vw7-735j", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-3476" + ], + "details": "The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3476" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/46f74493-9082-48b2-90bc-2c1d1db64ccd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-w2x6-9r88-x4c6/GHSA-w2x6-9r88-x4c6.json b/advisories/unreviewed/2024/05/GHSA-w2x6-9r88-x4c6/GHSA-w2x6-9r88-x4c6.json new file mode 100644 index 00000000000..81e9d3e3324 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-w2x6-9r88-x4c6/GHSA-w2x6-9r88-x4c6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2x6-9r88-x4c6", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-3475" + ], + "details": "The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3475" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/bf540242-5306-4c94-ad50-782d0d5b127f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-wwjm-ww5x-84hm/GHSA-wwjm-ww5x-84hm.json b/advisories/unreviewed/2024/05/GHSA-wwjm-ww5x-84hm/GHSA-wwjm-ww5x-84hm.json new file mode 100644 index 00000000000..b598358468d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-wwjm-ww5x-84hm/GHSA-wwjm-ww5x-84hm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwjm-ww5x-84hm", + "modified": "2024-05-02T06:30:31Z", + "published": "2024-05-02T06:30:31Z", + "aliases": [ + "CVE-2024-3472" + ], + "details": "The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3472" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d42f74dd-520f-40aa-9cf0-3544db9562c7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json b/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json new file mode 100644 index 00000000000..cf9820963f1 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmjw-8f7c-p37x", + "modified": "2024-05-02T06:30:32Z", + "published": "2024-05-02T06:30:32Z", + "aliases": [ + "CVE-2024-3478" + ], + "details": "The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3478" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/09f1a696-86ee-47cc-99de-57cfd2a3219d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-02T06:15:51Z" + } +} \ No newline at end of file