From 7cb35d6879bdc6e6c4756f87855deb745d10aef2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 19 Apr 2025 06:32:03 +0000 Subject: [PATCH] Publish Advisories GHSA-6876-67w8-32f4 GHSA-cgf8-4346-5g89 GHSA-cxx2-6hj9-h66p GHSA-p6jq-9gcc-mcvx GHSA-p9f4-fp6p-vqgh GHSA-xg3f-6866-fpvf GHSA-xqfq-g578-jf37 --- .../GHSA-6876-67w8-32f4.json | 44 ++++++++++++++++ .../GHSA-cgf8-4346-5g89.json | 40 ++++++++++++++ .../GHSA-cxx2-6hj9-h66p.json | 52 +++++++++++++++++++ .../GHSA-p6jq-9gcc-mcvx.json | 29 +++++++++++ .../GHSA-p9f4-fp6p-vqgh.json | 40 ++++++++++++++ .../GHSA-xg3f-6866-fpvf.json | 40 ++++++++++++++ .../GHSA-xqfq-g578-jf37.json | 48 +++++++++++++++++ 7 files changed, 293 insertions(+) create mode 100644 advisories/unreviewed/2025/04/GHSA-6876-67w8-32f4/GHSA-6876-67w8-32f4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cgf8-4346-5g89/GHSA-cgf8-4346-5g89.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cxx2-6hj9-h66p/GHSA-cxx2-6hj9-h66p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p6jq-9gcc-mcvx/GHSA-p6jq-9gcc-mcvx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p9f4-fp6p-vqgh/GHSA-p9f4-fp6p-vqgh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xg3f-6866-fpvf/GHSA-xg3f-6866-fpvf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xqfq-g578-jf37/GHSA-xqfq-g578-jf37.json diff --git a/advisories/unreviewed/2025/04/GHSA-6876-67w8-32f4/GHSA-6876-67w8-32f4.json b/advisories/unreviewed/2025/04/GHSA-6876-67w8-32f4/GHSA-6876-67w8-32f4.json new file mode 100644 index 00000000000..95e131c8cd7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6876-67w8-32f4/GHSA-6876-67w8-32f4.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6876-67w8-32f4", + "modified": "2025-04-19T06:30:24Z", + "published": "2025-04-19T06:30:24Z", + "aliases": [ + "CVE-2025-3275" + ], + "details": "The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3275" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/assets/js/tf-flexslider.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3268183/themesflat-addons-for-elementor/tags/2.2.2/assets/js/tf-flexslider.js" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4ec73a61-9ae2-4e6f-b1fa-2d61f27d6809?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T04:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cgf8-4346-5g89/GHSA-cgf8-4346-5g89.json b/advisories/unreviewed/2025/04/GHSA-cgf8-4346-5g89/GHSA-cgf8-4346-5g89.json new file mode 100644 index 00000000000..0ba806121ff --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cgf8-4346-5g89/GHSA-cgf8-4346-5g89.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgf8-4346-5g89", + "modified": "2025-04-19T06:30:24Z", + "published": "2025-04-19T06:30:24Z", + "aliases": [ + "CVE-2025-3103" + ], + "details": "The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vulnerable to arbitrary file read due to insufficient file path validation in the 'history.php' file in all versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to read arbitrary files on the affected site's server, which may contain sensitive information including database credentials. The vulnerability was partially patched in version 2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3103" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/clever-html5-radio-player-with-history-shoutcast-and-icecast-elementor-widget-addon/26708087#item-description__updates-release-log" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0733261f-a2e1-4bd1-a57d-fdaaa8c904db?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T05:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cxx2-6hj9-h66p/GHSA-cxx2-6hj9-h66p.json b/advisories/unreviewed/2025/04/GHSA-cxx2-6hj9-h66p/GHSA-cxx2-6hj9-h66p.json new file mode 100644 index 00000000000..658e8a6beb7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cxx2-6hj9-h66p/GHSA-cxx2-6hj9-h66p.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxx2-6hj9-h66p", + "modified": "2025-04-19T06:30:24Z", + "published": "2025-04-19T06:30:24Z", + "aliases": [ + "CVE-2025-1457" + ], + "details": "The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Wrapper Link, Countdown and Gallery widgets in all versions up to, and including, 5.10.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1457" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/assets/js/modules/ep-countdown.min.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/assets/js/modules/ep-wrapper-link.min.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3272946%40bdthemes-element-pack-lite&new=3272946%40bdthemes-element-pack-lite&sfp_email=&sfph_mail=#file1095" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3272946%40bdthemes-element-pack-lite&new=3272946%40bdthemes-element-pack-lite&sfp_email=&sfph_mail=#file1097" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c6ac5484-3caa-4821-990b-cd49c2c4873d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T04:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p6jq-9gcc-mcvx/GHSA-p6jq-9gcc-mcvx.json b/advisories/unreviewed/2025/04/GHSA-p6jq-9gcc-mcvx/GHSA-p6jq-9gcc-mcvx.json new file mode 100644 index 00000000000..80e7c936983 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p6jq-9gcc-mcvx/GHSA-p6jq-9gcc-mcvx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6jq-9gcc-mcvx", + "modified": "2025-04-19T06:30:24Z", + "published": "2025-04-19T06:30:24Z", + "aliases": [ + "CVE-2024-13926" + ], + "details": "The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post containing a large number of tags, thereby exploiting a catastrophic backtracking issue in the regular expression processing to cause a DoS.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13926" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b5f0092e-7cd5-412f-a8ea-7bd4a8bf86d2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T06:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p9f4-fp6p-vqgh/GHSA-p9f4-fp6p-vqgh.json b/advisories/unreviewed/2025/04/GHSA-p9f4-fp6p-vqgh/GHSA-p9f4-fp6p-vqgh.json new file mode 100644 index 00000000000..925780b5f09 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p9f4-fp6p-vqgh/GHSA-p9f4-fp6p-vqgh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9f4-fp6p-vqgh", + "modified": "2025-04-19T06:30:24Z", + "published": "2025-04-19T06:30:24Z", + "aliases": [ + "CVE-2025-1093" + ], + "details": "The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generate_image function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1093" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/ai-hub-startup-technology-wordpress-theme/47473638" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/09adfe7e-f154-4143-827f-957ded3ffc8f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T04:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xg3f-6866-fpvf/GHSA-xg3f-6866-fpvf.json b/advisories/unreviewed/2025/04/GHSA-xg3f-6866-fpvf/GHSA-xg3f-6866-fpvf.json new file mode 100644 index 00000000000..88d75a7b0d0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xg3f-6866-fpvf/GHSA-xg3f-6866-fpvf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg3f-6866-fpvf", + "modified": "2025-04-19T06:30:24Z", + "published": "2025-04-19T06:30:24Z", + "aliases": [ + "CVE-2025-3809" + ], + "details": "The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the auto-refresh debug log in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3809" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3267252%40debug-log-manager&new=3267252%40debug-log-manager&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cbc3210d-224e-4ed2-ada7-dc17deb17584?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T06:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xqfq-g578-jf37/GHSA-xqfq-g578-jf37.json b/advisories/unreviewed/2025/04/GHSA-xqfq-g578-jf37/GHSA-xqfq-g578-jf37.json new file mode 100644 index 00000000000..435c554b118 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xqfq-g578-jf37/GHSA-xqfq-g578-jf37.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqfq-g578-jf37", + "modified": "2025-04-19T06:30:24Z", + "published": "2025-04-19T06:30:24Z", + "aliases": [ + "CVE-2025-2111" + ], + "details": "The Insert Headers And Footers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the 'custom_plugin_set_option' function. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site. The 'WPBRIGADE_SDK__DEV_MODE' constant must be set to 'true' to exploit the vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2111" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-headers-and-footers/trunk/lib/wpb-sdk/views/wpb-debug.php#L63" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-headers-and-footers/trunk/lib/wpb-sdk/views/wpb-debug.php#L69" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3276361" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7b00d175-261d-46e3-bf3c-2d18f4e4972d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T06:15:19Z" + } +} \ No newline at end of file