From 65134fa4c149a8701a2d9bb405920e9f797136aa Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 6 Jun 2024 06:32:14 +0000 Subject: [PATCH] Publish Advisories GHSA-m9q4-fmg6-m8r5 GHSA-24rp-wx3g-3c5c GHSA-3mvr-pxcv-j67r GHSA-6mx3-v4px-m36j GHSA-76m6-2m38-53cq GHSA-7fhq-9c6m-3fj2 GHSA-8wh8-c2xr-4hxj GHSA-f5f7-2gvp-276p GHSA-fmp9-4pq7-hvhc GHSA-g9j3-gfvx-6m8g GHSA-gqh6-f673-ccgc GHSA-jw49-77hq-w4px GHSA-p826-3x73-p9j2 GHSA-r7v6-7rjj-ww63 GHSA-vhgg-c8h4-x9hr GHSA-vhrp-8vx7-m46h GHSA-w6x8-pprj-4vqq GHSA-wpvg-pwvm-4ff2 GHSA-xqr2-65hp-h5j3 --- .../GHSA-m9q4-fmg6-m8r5.json | 22 +++++- .../GHSA-24rp-wx3g-3c5c.json | 46 ++++++++++++ .../GHSA-3mvr-pxcv-j67r.json | 50 +++++++++++++ .../GHSA-6mx3-v4px-m36j.json | 42 +++++++++++ .../GHSA-76m6-2m38-53cq.json | 50 +++++++++++++ .../GHSA-7fhq-9c6m-3fj2.json | 42 +++++++++++ .../GHSA-8wh8-c2xr-4hxj.json | 42 +++++++++++ .../GHSA-f5f7-2gvp-276p.json | 42 +++++++++++ .../GHSA-fmp9-4pq7-hvhc.json | 42 +++++++++++ .../GHSA-g9j3-gfvx-6m8g.json | 42 +++++++++++ .../GHSA-gqh6-f673-ccgc.json | 42 +++++++++++ .../GHSA-jw49-77hq-w4px.json | 42 +++++++++++ .../GHSA-p826-3x73-p9j2.json | 46 ++++++++++++ .../GHSA-r7v6-7rjj-ww63.json | 42 +++++++++++ .../GHSA-vhgg-c8h4-x9hr.json | 46 ++++++++++++ .../GHSA-vhrp-8vx7-m46h.json | 70 +++++++++++++++++++ .../GHSA-w6x8-pprj-4vqq.json | 46 ++++++++++++ .../GHSA-wpvg-pwvm-4ff2.json | 42 +++++++++++ .../GHSA-xqr2-65hp-h5j3.json | 42 +++++++++++ 19 files changed, 837 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/06/GHSA-24rp-wx3g-3c5c/GHSA-24rp-wx3g-3c5c.json create mode 100644 advisories/unreviewed/2024/06/GHSA-3mvr-pxcv-j67r/GHSA-3mvr-pxcv-j67r.json create mode 100644 advisories/unreviewed/2024/06/GHSA-6mx3-v4px-m36j/GHSA-6mx3-v4px-m36j.json create mode 100644 advisories/unreviewed/2024/06/GHSA-76m6-2m38-53cq/GHSA-76m6-2m38-53cq.json create mode 100644 advisories/unreviewed/2024/06/GHSA-7fhq-9c6m-3fj2/GHSA-7fhq-9c6m-3fj2.json create mode 100644 advisories/unreviewed/2024/06/GHSA-8wh8-c2xr-4hxj/GHSA-8wh8-c2xr-4hxj.json create mode 100644 advisories/unreviewed/2024/06/GHSA-f5f7-2gvp-276p/GHSA-f5f7-2gvp-276p.json create mode 100644 advisories/unreviewed/2024/06/GHSA-fmp9-4pq7-hvhc/GHSA-fmp9-4pq7-hvhc.json create mode 100644 advisories/unreviewed/2024/06/GHSA-g9j3-gfvx-6m8g/GHSA-g9j3-gfvx-6m8g.json create mode 100644 advisories/unreviewed/2024/06/GHSA-gqh6-f673-ccgc/GHSA-gqh6-f673-ccgc.json create mode 100644 advisories/unreviewed/2024/06/GHSA-jw49-77hq-w4px/GHSA-jw49-77hq-w4px.json create mode 100644 advisories/unreviewed/2024/06/GHSA-p826-3x73-p9j2/GHSA-p826-3x73-p9j2.json create mode 100644 advisories/unreviewed/2024/06/GHSA-r7v6-7rjj-ww63/GHSA-r7v6-7rjj-ww63.json create mode 100644 advisories/unreviewed/2024/06/GHSA-vhgg-c8h4-x9hr/GHSA-vhgg-c8h4-x9hr.json create mode 100644 advisories/unreviewed/2024/06/GHSA-vhrp-8vx7-m46h/GHSA-vhrp-8vx7-m46h.json create mode 100644 advisories/unreviewed/2024/06/GHSA-w6x8-pprj-4vqq/GHSA-w6x8-pprj-4vqq.json create mode 100644 advisories/unreviewed/2024/06/GHSA-wpvg-pwvm-4ff2/GHSA-wpvg-pwvm-4ff2.json create mode 100644 advisories/unreviewed/2024/06/GHSA-xqr2-65hp-h5j3/GHSA-xqr2-65hp-h5j3.json diff --git a/advisories/unreviewed/2023/09/GHSA-m9q4-fmg6-m8r5/GHSA-m9q4-fmg6-m8r5.json b/advisories/unreviewed/2023/09/GHSA-m9q4-fmg6-m8r5/GHSA-m9q4-fmg6-m8r5.json index 5f927b42675..752309a5c9a 100644 --- a/advisories/unreviewed/2023/09/GHSA-m9q4-fmg6-m8r5/GHSA-m9q4-fmg6-m8r5.json +++ b/advisories/unreviewed/2023/09/GHSA-m9q4-fmg6-m8r5/GHSA-m9q4-fmg6-m8r5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9q4-fmg6-m8r5", - "modified": "2024-04-04T07:35:47Z", + "modified": "2024-06-06T06:30:28Z", "published": "2023-09-11T21:30:16Z", "aliases": [ "CVE-2023-31468" @@ -21,10 +21,30 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31468" }, + { + "type": "WEB", + "url": "https://cwe.mitre.org/data/definitions/276.html" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-151-03" + }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/51682" }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + }, + { + "type": "WEB", + "url": "https://www.inosoft.com/en/news-details/news/neue-visiwin-version-2024-1" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/174268/Inosoft-VisiWin-7-2022-2.1-Insecure-Permissions-Privilege-Escalation.html" diff --git a/advisories/unreviewed/2024/06/GHSA-24rp-wx3g-3c5c/GHSA-24rp-wx3g-3c5c.json b/advisories/unreviewed/2024/06/GHSA-24rp-wx3g-3c5c/GHSA-24rp-wx3g-3c5c.json new file mode 100644 index 00000000000..03833c5b44e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-24rp-wx3g-3c5c/GHSA-24rp-wx3g-3c5c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24rp-wx3g-3c5c", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-5615" + ], + "details": "The Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.2 via the 'opengraph_default_description' function. This makes it possible for unauthenticated attackers to extract sensitive data including partial content of password-protected blog posts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5615" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/opengraph/trunk/opengraph.php#L369" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3097574" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f57dc0fe-07f3-457e-8080-fe530f6a9f01?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3mvr-pxcv-j67r/GHSA-3mvr-pxcv-j67r.json b/advisories/unreviewed/2024/06/GHSA-3mvr-pxcv-j67r/GHSA-3mvr-pxcv-j67r.json new file mode 100644 index 00000000000..17c3ac1de00 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3mvr-pxcv-j67r/GHSA-3mvr-pxcv-j67r.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mvr-pxcv-j67r", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-4608" + ], + "details": "The SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4608" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sellkit/trunk/includes/elementor/modules/optin/fields/acceptance.php#L31" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sellkit/trunk/includes/elementor/modules/optin/fields/field-base.php#L304" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sellkit/trunk/includes/elementor/modules/optin/widgets/optin.php#L48" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9fbb31a5-9ed2-445a-b309-a9835128eb44?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-6mx3-v4px-m36j/GHSA-6mx3-v4px-m36j.json b/advisories/unreviewed/2024/06/GHSA-6mx3-v4px-m36j/GHSA-6mx3-v4px-m36j.json new file mode 100644 index 00000000000..0dd86c8da08 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6mx3-v4px-m36j/GHSA-6mx3-v4px-m36j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mx3-v4px-m36j", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-5152" + ], + "details": "The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5152" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/element-ready-lite/trunk/inc/Widgets/info_box/Element_Ready_Info_Box_Widget.php#L742" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d2cffdc3-bd74-42ab-befd-8a396c5d990d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-76m6-2m38-53cq/GHSA-76m6-2m38-53cq.json b/advisories/unreviewed/2024/06/GHSA-76m6-2m38-53cq/GHSA-76m6-2m38-53cq.json new file mode 100644 index 00000000000..d442ded8301 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-76m6-2m38-53cq/GHSA-76m6-2m38-53cq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76m6-2m38-53cq", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-4364" + ], + "details": "The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button widgets in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4364" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/qi-addons-for-elementor/tags/1.7.0/inc/shortcodes/button/class-qiaddonsforelementor-button-shortcode.php#L1253" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/qi-addons-for-elementor/tags/1.7.0/inc/shortcodes/info-button/class-qiaddonsforelementor-info-button-shortcode.php#L696" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3096634%40qi-addons-for-elementor%2Ftrunk&old=3092106%40qi-addons-for-elementor%2Ftrunk&sfp_email=&sfph_mail=#file21" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/061ada09-932f-4d2c-aa9e-c53f1d711c85?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7fhq-9c6m-3fj2/GHSA-7fhq-9c6m-3fj2.json b/advisories/unreviewed/2024/06/GHSA-7fhq-9c6m-3fj2/GHSA-7fhq-9c6m-3fj2.json new file mode 100644 index 00000000000..c0794b830bf --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7fhq-9c6m-3fj2/GHSA-7fhq-9c6m-3fj2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fhq-9c6m-3fj2", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-2922" + ], + "details": "The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget tags in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2922" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/themesflat-addons-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1516280e-796e-4011-b15f-b754860ad414?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8wh8-c2xr-4hxj/GHSA-8wh8-c2xr-4hxj.json b/advisories/unreviewed/2024/06/GHSA-8wh8-c2xr-4hxj/GHSA-8wh8-c2xr-4hxj.json new file mode 100644 index 00000000000..47b3da20261 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8wh8-c2xr-4hxj/GHSA-8wh8-c2xr-4hxj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wh8-c2xr-4hxj", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-4459" + ], + "details": "The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget's titles in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4459" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-simple-slide.php#L1117" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ce7c2f30-188a-4ae7-976f-c7f0aaf96eee?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-f5f7-2gvp-276p/GHSA-f5f7-2gvp-276p.json b/advisories/unreviewed/2024/06/GHSA-f5f7-2gvp-276p/GHSA-f5f7-2gvp-276p.json new file mode 100644 index 00000000000..2bbc390af59 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-f5f7-2gvp-276p/GHSA-f5f7-2gvp-276p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5f7-2gvp-276p", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-5141" + ], + "details": "The Rotating Tweets (Twitter widget and shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's' 'rotatingtweets' in all versions up to, and including, 1.9.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5141" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/rotatingtweets/tags/1.9.10/rotatingtweets.php#L2267" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/02cff893-4f41-4bb0-9fb0-344a3a8afa0b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fmp9-4pq7-hvhc/GHSA-fmp9-4pq7-hvhc.json b/advisories/unreviewed/2024/06/GHSA-fmp9-4pq7-hvhc/GHSA-fmp9-4pq7-hvhc.json new file mode 100644 index 00000000000..6941064a000 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fmp9-4pq7-hvhc/GHSA-fmp9-4pq7-hvhc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmp9-4pq7-hvhc", + "modified": "2024-06-06T06:30:29Z", + "published": "2024-06-06T06:30:29Z", + "aliases": [ + "CVE-2024-1175" + ], + "details": "The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_payment' function in all versions up to, and including, 16.26.6. This makes it possible for unauthenticated attackers to delete arbitrary payments.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1175" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-recall" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6b84b13a-b46c-48fc-a7a8-de32c575d576?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g9j3-gfvx-6m8g/GHSA-g9j3-gfvx-6m8g.json b/advisories/unreviewed/2024/06/GHSA-g9j3-gfvx-6m8g/GHSA-g9j3-gfvx-6m8g.json new file mode 100644 index 00000000000..b0bbad6b7c6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-g9j3-gfvx-6m8g/GHSA-g9j3-gfvx-6m8g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9j3-gfvx-6m8g", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-5656" + ], + "details": "The Google CSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5656" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/adc6ea6d-29d8-4ad0-b0db-2540e8b3f9a9" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/37cf63e3-9301-441d-9852-b2de83078b51?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gqh6-f673-ccgc/GHSA-gqh6-f673-ccgc.json b/advisories/unreviewed/2024/06/GHSA-gqh6-f673-ccgc/GHSA-gqh6-f673-ccgc.json new file mode 100644 index 00000000000..7a7ffd431e5 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gqh6-f673-ccgc/GHSA-gqh6-f673-ccgc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqh6-f673-ccgc", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-3049" + ], + "details": "A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3049" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-3049" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2272082" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jw49-77hq-w4px/GHSA-jw49-77hq-w4px.json b/advisories/unreviewed/2024/06/GHSA-jw49-77hq-w4px/GHSA-jw49-77hq-w4px.json new file mode 100644 index 00000000000..1b1d64fa286 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jw49-77hq-w4px/GHSA-jw49-77hq-w4px.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw49-77hq-w4px", + "modified": "2024-06-06T06:30:29Z", + "published": "2024-06-06T06:30:29Z", + "aliases": [ + "CVE-2024-0972" + ], + "details": "The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.5 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's \"All Other Sections On Your Site Will be Opened to Guest\" feature (when unset) and view restricted page and post content.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0972" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/buddypress-members-only/trunk/buddypress-members-only.php#L682" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dcfead67-d75d-46ae-ac68-a34643ac2f52?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-p826-3x73-p9j2/GHSA-p826-3x73-p9j2.json b/advisories/unreviewed/2024/06/GHSA-p826-3x73-p9j2/GHSA-p826-3x73-p9j2.json new file mode 100644 index 00000000000..5068ccf7aea --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-p826-3x73-p9j2/GHSA-p826-3x73-p9j2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p826-3x73-p9j2", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-5449" + ], + "details": "The WP Dark Mode – WordPress Dark Mode Plugin for Improved Accessibility, Dark Theme, Night Mode, and Social Sharing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdm_social_share_save_options function in all versions up to, and including, 5.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5449" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-dark-mode/trunk/includes/modules/social-share/class-social-share.php#L581" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3096290/wp-dark-mode/trunk?contextall=1&old=3073245&old_path=%2Fwp-dark-mode%2Ftrunk" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d7d20733-d61b-4b2f-8597-528644f0bc26?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-r7v6-7rjj-ww63/GHSA-r7v6-7rjj-ww63.json b/advisories/unreviewed/2024/06/GHSA-r7v6-7rjj-ww63/GHSA-r7v6-7rjj-ww63.json new file mode 100644 index 00000000000..eac5fbf1a97 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-r7v6-7rjj-ww63/GHSA-r7v6-7rjj-ww63.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7v6-7rjj-ww63", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-5162" + ], + "details": "The WordPress prettyPhoto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5162" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/prettyphoto/trunk/addon/jltma-wpf-addon.php#L96" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c581616d-c9e7-46f2-9c2f-5e082a13fd0b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vhgg-c8h4-x9hr/GHSA-vhgg-c8h4-x9hr.json b/advisories/unreviewed/2024/06/GHSA-vhgg-c8h4-x9hr/GHSA-vhgg-c8h4-x9hr.json new file mode 100644 index 00000000000..fb9c3fbf296 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vhgg-c8h4-x9hr/GHSA-vhgg-c8h4-x9hr.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhgg-c8h4-x9hr", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-4707" + ], + "details": "The Materialis Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's materialis_contact_form shortcode in all versions up to, and including, 1.3.41 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4707" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/materialis-companion/trunk/theme-data/materialis/functions.php#L90" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3097691%40materialis-companion&new=3097691%40materialis-companion&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6ca4dff0-ca3a-44cf-a30b-36b31d2848ab?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vhrp-8vx7-m46h/GHSA-vhrp-8vx7-m46h.json b/advisories/unreviewed/2024/06/GHSA-vhrp-8vx7-m46h/GHSA-vhrp-8vx7-m46h.json new file mode 100644 index 00000000000..c1d32c3a983 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vhrp-8vx7-m46h/GHSA-vhrp-8vx7-m46h.json @@ -0,0 +1,70 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhrp-8vx7-m46h", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-4212" + ], + "details": "The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TF Group Image, TF Nav Menu, TF Posts, TF Woo Product Grid, TF Accordion, and TF Image Box widgets in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4212" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-accordion.php#L1158" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-clipping-mask.php#L619" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-imagebox.php#L1313" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-navmenu.php#L1843" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-posts.php#L3350" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-tfgroupimage.php#L423" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-woo-product-grid.php#L3646" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/themesflat-addons-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dc686a35-4ce3-4359-a7d3-e6459e2f5dfe?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-w6x8-pprj-4vqq/GHSA-w6x8-pprj-4vqq.json b/advisories/unreviewed/2024/06/GHSA-w6x8-pprj-4vqq/GHSA-w6x8-pprj-4vqq.json new file mode 100644 index 00000000000..618e30e619c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-w6x8-pprj-4vqq/GHSA-w6x8-pprj-4vqq.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6x8-pprj-4vqq", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-5161" + ], + "details": "The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 1.1.39 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5161" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/magical-addons-for-elementor/trunk/includes/widgets/advance-skill-bars.php#L502" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3098054%40magical-addons-for-elementor&new=3098054%40magical-addons-for-elementor&sfp_email=&sfph_mail=#file9" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cb64952e-170e-47c5-87fd-d2ec60192b65?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wpvg-pwvm-4ff2/GHSA-wpvg-pwvm-4ff2.json b/advisories/unreviewed/2024/06/GHSA-wpvg-pwvm-4ff2/GHSA-wpvg-pwvm-4ff2.json new file mode 100644 index 00000000000..8c5479bf93b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-wpvg-pwvm-4ff2/GHSA-wpvg-pwvm-4ff2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpvg-pwvm-4ff2", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-4458" + ], + "details": "The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets via URL parameters in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4458" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/themesflat-addons-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f0ff03ab-eeb9-4445-92c8-326783d4b10e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xqr2-65hp-h5j3/GHSA-xqr2-65hp-h5j3.json b/advisories/unreviewed/2024/06/GHSA-xqr2-65hp-h5j3/GHSA-xqr2-65hp-h5j3.json new file mode 100644 index 00000000000..2f51ce01068 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-xqr2-65hp-h5j3/GHSA-xqr2-65hp-h5j3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqr2-65hp-h5j3", + "modified": "2024-06-06T06:30:30Z", + "published": "2024-06-06T06:30:30Z", + "aliases": [ + "CVE-2024-5153" + ], + "details": "The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.15 via the 'dropzone_hash' parameter. This makes it possible for unauthenticated attackers to copy the contents of arbitrary files on the server, which can contain sensitive information, and to delete arbitrary directories, including the root WordPress directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5153" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/startklar-elmentor-forms-extwidgets/trunk/widgets/dropzone_form_field.php#L334" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/baa20290-9c01-4f8d-adeb-fbfb15b9d6a9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-06T04:15:13Z" + } +} \ No newline at end of file