diff --git a/advisories/unreviewed/2025/01/GHSA-4cmc-6r4j-g9p3/GHSA-4cmc-6r4j-g9p3.json b/advisories/unreviewed/2025/01/GHSA-4cmc-6r4j-g9p3/GHSA-4cmc-6r4j-g9p3.json new file mode 100644 index 00000000000..9bff67515be --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4cmc-6r4j-g9p3/GHSA-4cmc-6r4j-g9p3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cmc-6r4j-g9p3", + "modified": "2025-01-22T09:32:01Z", + "published": "2025-01-22T09:32:01Z", + "aliases": [ + "CVE-2025-0428" + ], + "details": "The \"AI Power: Complete AI Pack\" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_prompts function. This allows authenticated attackers, with administrative privileges, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0428" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3224162" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/66a3abc1-0508-4ce3-952b-7dbf3738879a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4fp6-v5fm-gmq5/GHSA-4fp6-v5fm-gmq5.json b/advisories/unreviewed/2025/01/GHSA-4fp6-v5fm-gmq5/GHSA-4fp6-v5fm-gmq5.json new file mode 100644 index 00000000000..32e80e48693 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4fp6-v5fm-gmq5/GHSA-4fp6-v5fm-gmq5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fp6-v5fm-gmq5", + "modified": "2025-01-22T09:32:01Z", + "published": "2025-01-22T09:32:01Z", + "aliases": [ + "CVE-2024-12117" + ], + "details": "The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the Button block in all versions up to, and including, 3.13.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12117" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3223387%40stackable-ultimate-gutenberg-blocks&new=3223387%40stackable-ultimate-gutenberg-blocks&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bedc2254-29aa-46c5-8f85-47dd6affb42b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T07:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6c43-vrq5-7v76/GHSA-6c43-vrq5-7v76.json b/advisories/unreviewed/2025/01/GHSA-6c43-vrq5-7v76/GHSA-6c43-vrq5-7v76.json new file mode 100644 index 00000000000..2e0af635629 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6c43-vrq5-7v76/GHSA-6c43-vrq5-7v76.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c43-vrq5-7v76", + "modified": "2025-01-22T09:32:01Z", + "published": "2025-01-22T09:32:01Z", + "aliases": [ + "CVE-2025-0429" + ], + "details": "The \"AI Power: Complete AI Pack\" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_ai_forms() function. This allows authenticated attackers, with administrative privileges, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0429" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3224162" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bb927aba-a96d-47b9-ba35-60945ea5cfe5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ch5m-r77h-m55x/GHSA-ch5m-r77h-m55x.json b/advisories/unreviewed/2025/01/GHSA-ch5m-r77h-m55x/GHSA-ch5m-r77h-m55x.json new file mode 100644 index 00000000000..25690fce9ba --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ch5m-r77h-m55x/GHSA-ch5m-r77h-m55x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch5m-r77h-m55x", + "modified": "2025-01-22T09:32:01Z", + "published": "2025-01-22T09:32:01Z", + "aliases": [ + "CVE-2024-12857" + ], + "details": "The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they have configured OTP login by phone number.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12857" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/adforest-classified-wordpress-theme/19481695" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4ff3b4f1-dd36-43d0-b472-55a940907437?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T07:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-prqh-6jh9-2qr5/GHSA-prqh-6jh9-2qr5.json b/advisories/unreviewed/2025/01/GHSA-prqh-6jh9-2qr5/GHSA-prqh-6jh9-2qr5.json new file mode 100644 index 00000000000..e006c199e51 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-prqh-6jh9-2qr5/GHSA-prqh-6jh9-2qr5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prqh-6jh9-2qr5", + "modified": "2025-01-22T09:32:01Z", + "published": "2025-01-22T09:32:01Z", + "aliases": [ + "CVE-2024-13360" + ], + "details": "The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector(). This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13360" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3224162" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5cf6cbba-0e0c-4d2c-90d0-d7e0a5222df2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q9w3-c433-527w/GHSA-q9w3-c433-527w.json b/advisories/unreviewed/2025/01/GHSA-q9w3-c433-527w/GHSA-q9w3-c433-527w.json new file mode 100644 index 00000000000..85497362ada --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q9w3-c433-527w/GHSA-q9w3-c433-527w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9w3-c433-527w", + "modified": "2025-01-22T09:32:01Z", + "published": "2025-01-22T09:32:01Z", + "aliases": [ + "CVE-2024-13361" + ], + "details": "The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in all versions up to, and including, 1.8.96. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload image files and embed shortcode attributes in the image_alt value that will execute when sending a POST request to the attachment page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13361" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3224162/gpt3-ai-content-generator/trunk/classes/wpaicg_image.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/11d49c89-43be-4e12-86b5-aa7a72a89803?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vqv2-ch86-28w3/GHSA-vqv2-ch86-28w3.json b/advisories/unreviewed/2025/01/GHSA-vqv2-ch86-28w3/GHSA-vqv2-ch86-28w3.json new file mode 100644 index 00000000000..2f6862b4582 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vqv2-ch86-28w3/GHSA-vqv2-ch86-28w3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqv2-ch86-28w3", + "modified": "2025-01-22T09:32:01Z", + "published": "2025-01-22T09:32:01Z", + "aliases": [ + "CVE-2024-13406" + ], + "details": "The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id' parameter in all versions up to, and including, 3.0.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13406" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3226403%40xml-for-google-merchant-center&new=3226403%40xml-for-google-merchant-center&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/070f66ae-65aa-4670-8b69-103070a000a4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T07:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wh72-cw57-8837/GHSA-wh72-cw57-8837.json b/advisories/unreviewed/2025/01/GHSA-wh72-cw57-8837/GHSA-wh72-cw57-8837.json new file mode 100644 index 00000000000..6ee14a5ce9c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wh72-cw57-8837/GHSA-wh72-cw57-8837.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh72-cw57-8837", + "modified": "2025-01-22T09:32:01Z", + "published": "2025-01-22T09:32:01Z", + "aliases": [ + "CVE-2024-13319" + ], + "details": "The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13319" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3224684/themify-builder/trunk/themify/themify-admin.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/69ac1e37-4e31-4dce-a2d6-07a4299995c5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T08:15:08Z" + } +} \ No newline at end of file