diff --git a/advisories/unreviewed/2024/09/GHSA-3rxw-2675-c3j9/GHSA-3rxw-2675-c3j9.json b/advisories/unreviewed/2024/09/GHSA-3rxw-2675-c3j9/GHSA-3rxw-2675-c3j9.json new file mode 100644 index 00000000000..45e8afb9187 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3rxw-2675-c3j9/GHSA-3rxw-2675-c3j9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rxw-2675-c3j9", + "modified": "2024-09-09T06:30:45Z", + "published": "2024-09-09T06:30:45Z", + "aliases": [ + "CVE-2024-7688" + ], + "details": "The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary indexes via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7688" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/6c1d4354-b88b-46ca-b25a-efb9518f4955" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T06:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-49hg-gf5g-95cj/GHSA-49hg-gf5g-95cj.json b/advisories/unreviewed/2024/09/GHSA-49hg-gf5g-95cj/GHSA-49hg-gf5g-95cj.json new file mode 100644 index 00000000000..c26e826dddf --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-49hg-gf5g-95cj/GHSA-49hg-gf5g-95cj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49hg-gf5g-95cj", + "modified": "2024-09-09T06:30:45Z", + "published": "2024-09-09T06:30:45Z", + "aliases": [ + "CVE-2024-7918" + ], + "details": "The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7918" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b1697646-1090-4a2b-9987-cec07428378e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T06:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7mq7-p8xv-m9wf/GHSA-7mq7-p8xv-m9wf.json b/advisories/unreviewed/2024/09/GHSA-7mq7-p8xv-m9wf/GHSA-7mq7-p8xv-m9wf.json new file mode 100644 index 00000000000..b5e69ec0b15 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7mq7-p8xv-m9wf/GHSA-7mq7-p8xv-m9wf.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mq7-p8xv-m9wf", + "modified": "2024-09-09T06:30:45Z", + "published": "2024-09-09T06:30:45Z", + "aliases": [ + "CVE-2024-45625" + ], + "details": "Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and accesses the webpage with the web form created by Forminator.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45625" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN65724976" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?new=3135507%40forminator%2Ftrunk%2Fassets%2Fjs%2Ffront%2Ffront.mergetags.js&old=3111152%40forminator%2Ftrunk%2Fassets%2Fjs%2Ffront%2Ffront.mergetags.js" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/forminator" + }, + { + "type": "WEB", + "url": "https://wpmudev.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T05:15:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8g86-p27w-cfrf/GHSA-8g86-p27w-cfrf.json b/advisories/unreviewed/2024/09/GHSA-8g86-p27w-cfrf/GHSA-8g86-p27w-cfrf.json new file mode 100644 index 00000000000..b032c3b82b2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8g86-p27w-cfrf/GHSA-8g86-p27w-cfrf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g86-p27w-cfrf", + "modified": "2024-09-09T06:30:45Z", + "published": "2024-09-09T06:30:45Z", + "aliases": [ + "CVE-2024-5561" + ], + "details": "The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5561" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/6a87cc25-bd7d-40e3-96f9-26646cd6f736" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T06:15:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fm87-mh9v-3658/GHSA-fm87-mh9v-3658.json b/advisories/unreviewed/2024/09/GHSA-fm87-mh9v-3658/GHSA-fm87-mh9v-3658.json new file mode 100644 index 00000000000..037171ffb0f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fm87-mh9v-3658/GHSA-fm87-mh9v-3658.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm87-mh9v-3658", + "modified": "2024-09-09T06:30:45Z", + "published": "2024-09-09T06:30:45Z", + "aliases": [ + "CVE-2024-7689" + ], + "details": "The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7689" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4463785c-55db-4f86-80a2-ada4d2241e5e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T06:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-whxv-xf4j-48r5/GHSA-whxv-xf4j-48r5.json b/advisories/unreviewed/2024/09/GHSA-whxv-xf4j-48r5/GHSA-whxv-xf4j-48r5.json new file mode 100644 index 00000000000..71854477811 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-whxv-xf4j-48r5/GHSA-whxv-xf4j-48r5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whxv-xf4j-48r5", + "modified": "2024-09-09T06:30:45Z", + "published": "2024-09-09T06:30:45Z", + "aliases": [ + "CVE-2024-7687" + ], + "details": "The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7687" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b861f18a-40ae-4989-a8e4-37df1771ae23" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T06:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wq3j-qfpm-h36f/GHSA-wq3j-qfpm-h36f.json b/advisories/unreviewed/2024/09/GHSA-wq3j-qfpm-h36f/GHSA-wq3j-qfpm-h36f.json new file mode 100644 index 00000000000..00d5c8e26a1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wq3j-qfpm-h36f/GHSA-wq3j-qfpm-h36f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq3j-qfpm-h36f", + "modified": "2024-09-09T06:30:45Z", + "published": "2024-09-09T06:30:45Z", + "aliases": [ + "CVE-2024-6910" + ], + "details": "The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6910" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/468373c6-7e47-489a-92c1-75025c543fd5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-09T06:15:02Z" + } +} \ No newline at end of file