diff --git a/advisories/unreviewed/2025/01/GHSA-2358-vv2w-hxq3/GHSA-2358-vv2w-hxq3.json b/advisories/unreviewed/2025/01/GHSA-2358-vv2w-hxq3/GHSA-2358-vv2w-hxq3.json new file mode 100644 index 00000000000..b21d1b2e0a5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2358-vv2w-hxq3/GHSA-2358-vv2w-hxq3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2358-vv2w-hxq3", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13224" + ], + "details": "The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13224" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/32a90907-e82f-41b3-b20e-d10a722e2999" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-238q-xvw6-rfhf/GHSA-238q-xvw6-rfhf.json b/advisories/unreviewed/2025/01/GHSA-238q-xvw6-rfhf/GHSA-238q-xvw6-rfhf.json new file mode 100644 index 00000000000..b5cda4f25dc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-238q-xvw6-rfhf/GHSA-238q-xvw6-rfhf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-238q-xvw6-rfhf", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-12872" + ], + "details": "The Zalomení WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12872" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a8a706c6-7f0f-4148-9f6f-40c0ca95dd9a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-25ff-84m3-7r6v/GHSA-25ff-84m3-7r6v.json b/advisories/unreviewed/2025/01/GHSA-25ff-84m3-7r6v/GHSA-25ff-84m3-7r6v.json new file mode 100644 index 00000000000..b0bcae17bb3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-25ff-84m3-7r6v/GHSA-25ff-84m3-7r6v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25ff-84m3-7r6v", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13226" + ], + "details": "The A5 Custom Login Page WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13226" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/dd09fe99-2334-4d6f-8a70-e1cd856b1486" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3cxg-xc64-j4m4/GHSA-3cxg-xc64-j4m4.json b/advisories/unreviewed/2025/01/GHSA-3cxg-xc64-j4m4/GHSA-3cxg-xc64-j4m4.json new file mode 100644 index 00000000000..1ee84a35228 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3cxg-xc64-j4m4/GHSA-3cxg-xc64-j4m4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cxg-xc64-j4m4", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-12772" + ], + "details": "The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, leading to a Cross Site Scripting vulnerability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12772" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7b6d0f95-6632-4079-8c1b-517a8d02c330" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3pmw-rf4c-vg6h/GHSA-3pmw-rf4c-vg6h.json b/advisories/unreviewed/2025/01/GHSA-3pmw-rf4c-vg6h/GHSA-3pmw-rf4c-vg6h.json new file mode 100644 index 00000000000..b759cb6b378 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3pmw-rf4c-vg6h/GHSA-3pmw-rf4c-vg6h.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pmw-rf4c-vg6h", + "modified": "2025-01-31T06:30:52Z", + "published": "2025-01-31T06:30:52Z", + "aliases": [ + "CVE-2025-0493" + ], + "details": "The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and including, 4.2.14 via the tabname parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0493" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/dc-woocommerce-multi-vendor/tags/4.2.14/classes/class-mvx-ajax.php#L661" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/dc-woocommerce-multi-vendor/tags/4.2.15/classes/class-mvx-ajax.php#L661" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/812029d9-95d6-4bc9-98b2-700f462163b3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T05:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-42c6-24m9-97gm/GHSA-42c6-24m9-97gm.json b/advisories/unreviewed/2025/01/GHSA-42c6-24m9-97gm/GHSA-42c6-24m9-97gm.json new file mode 100644 index 00000000000..36f9a21c841 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-42c6-24m9-97gm/GHSA-42c6-24m9-97gm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42c6-24m9-97gm", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13112" + ], + "details": "The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13112" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/155df231-30ef-47bb-aa91-a7deb1779bd1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5mrr-3jvw-jc5j/GHSA-5mrr-3jvw-jc5j.json b/advisories/unreviewed/2025/01/GHSA-5mrr-3jvw-jc5j/GHSA-5mrr-3jvw-jc5j.json new file mode 100644 index 00000000000..67c56924ed0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5mrr-3jvw-jc5j/GHSA-5mrr-3jvw-jc5j.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mrr-3jvw-jc5j", + "modified": "2025-01-31T06:30:52Z", + "published": "2025-01-31T06:30:52Z", + "aliases": [ + "CVE-2025-0470" + ], + "details": "The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the title parameter in all versions up to, and including, 1.38.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0470" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/forminator/tags/1.38.2/requirejs/main.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3226716%40forminator%2Ftrunk&old=3222217%40forminator%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f5281d4b-c2cd-4972-b837-e101a8893c6e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-64wx-c7jg-27vx/GHSA-64wx-c7jg-27vx.json b/advisories/unreviewed/2025/01/GHSA-64wx-c7jg-27vx/GHSA-64wx-c7jg-27vx.json new file mode 100644 index 00000000000..c4f8117c468 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-64wx-c7jg-27vx/GHSA-64wx-c7jg-27vx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64wx-c7jg-27vx", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13223" + ], + "details": "The Tabulate WordPress plugin through 2.10.3 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13223" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e3a52af1-7cb6-4361-b1c7-a50e0cc62fb1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-67cc-w9jq-w47v/GHSA-67cc-w9jq-w47v.json b/advisories/unreviewed/2025/01/GHSA-67cc-w9jq-w47v/GHSA-67cc-w9jq-w47v.json new file mode 100644 index 00000000000..ff262af6139 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-67cc-w9jq-w47v/GHSA-67cc-w9jq-w47v.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67cc-w9jq-w47v", + "modified": "2025-01-31T06:30:51Z", + "published": "2025-01-31T06:30:51Z", + "aliases": [ + "CVE-2024-47899" + ], + "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47899" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6pjp-mfjp-9hmj/GHSA-6pjp-mfjp-9hmj.json b/advisories/unreviewed/2025/01/GHSA-6pjp-mfjp-9hmj/GHSA-6pjp-mfjp-9hmj.json new file mode 100644 index 00000000000..37c75a5dfb3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6pjp-mfjp-9hmj/GHSA-6pjp-mfjp-9hmj.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pjp-mfjp-9hmj", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-11886" + ], + "details": "The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler ' shortcode in all versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11886" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/lead-capturing-call-to-actions-by-vcita/trunk/lead-capturing-call-to-actions.php#L44" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/lead-capturing-call-to-actions-by-vcita/trunk/vcita-widgets-functions.php#L104" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/lead-capturing-call-to-actions-by-vcita/trunk/vcita-widgets-functions.php#L63" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4a9021b4-54f8-4ba3-bc81-49271dde1b44?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7whw-5h5g-gmvc/GHSA-7whw-5h5g-gmvc.json b/advisories/unreviewed/2025/01/GHSA-7whw-5h5g-gmvc/GHSA-7whw-5h5g-gmvc.json new file mode 100644 index 00000000000..75013a02a91 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7whw-5h5g-gmvc/GHSA-7whw-5h5g-gmvc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7whw-5h5g-gmvc", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2025-0809" + ], + "details": "The Link Fixer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via broken links in all versions up to, and including, 3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0809" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/permalink-finder" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/37198f2f-2b45-40d3-b4ae-aa94213996bd?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9986-pwmm-rjvr/GHSA-9986-pwmm-rjvr.json b/advisories/unreviewed/2025/01/GHSA-9986-pwmm-rjvr/GHSA-9986-pwmm-rjvr.json new file mode 100644 index 00000000000..863c50a6a4c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9986-pwmm-rjvr/GHSA-9986-pwmm-rjvr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9986-pwmm-rjvr", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13218" + ], + "details": "The Fast Tube WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13218" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/79eb9432-3e3c-4a23-88a8-05aa3146061c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9x2x-p5cv-5cgv/GHSA-9x2x-p5cv-5cgv.json b/advisories/unreviewed/2025/01/GHSA-9x2x-p5cv-5cgv/GHSA-9x2x-p5cv-5cgv.json new file mode 100644 index 00000000000..cbc416a91ad --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9x2x-p5cv-5cgv/GHSA-9x2x-p5cv-5cgv.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x2x-p5cv-5cgv", + "modified": "2025-01-31T06:30:52Z", + "published": "2025-01-31T06:30:52Z", + "aliases": [ + "CVE-2025-0507" + ], + "details": "The Ticketmeo – Sell Tickets – Event Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0507" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ploxel/tags/2.2.0/ploxel.php#L49" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3231203" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/149edbdf-4a27-4d79-8dd1-b5b3efbf648b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T05:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c7fv-9v9p-r765/GHSA-c7fv-9v9p-r765.json b/advisories/unreviewed/2025/01/GHSA-c7fv-9v9p-r765/GHSA-c7fv-9v9p-r765.json new file mode 100644 index 00000000000..1cee9b36287 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c7fv-9v9p-r765/GHSA-c7fv-9v9p-r765.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7fv-9v9p-r765", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13222" + ], + "details": "The User Messages WordPress plugin through 1.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13222" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/069e1f81-448d-4d27-b288-87111dade2f2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cfp2-gfv9-jqxx/GHSA-cfp2-gfv9-jqxx.json b/advisories/unreviewed/2025/01/GHSA-cfp2-gfv9-jqxx/GHSA-cfp2-gfv9-jqxx.json new file mode 100644 index 00000000000..70184f1454e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cfp2-gfv9-jqxx/GHSA-cfp2-gfv9-jqxx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfp2-gfv9-jqxx", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13220" + ], + "details": "The WordPress Google Map Professional (Map In Your Language) WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13220" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/33ef27b4-e88f-46ec-9b3f-0a3e16d6f82e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f68r-j6f2-hvjm/GHSA-f68r-j6f2-hvjm.json b/advisories/unreviewed/2025/01/GHSA-f68r-j6f2-hvjm/GHSA-f68r-j6f2-hvjm.json new file mode 100644 index 00000000000..56522fc01e9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f68r-j6f2-hvjm/GHSA-f68r-j6f2-hvjm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f68r-j6f2-hvjm", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13216" + ], + "details": "The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13216" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ht-event/trunk/includes/widgets/htevent_sponsor.php#L443" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/155f494b-be25-4269-9d3b-379309619bbe?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g5jx-5vrq-vrh6/GHSA-g5jx-5vrq-vrh6.json b/advisories/unreviewed/2025/01/GHSA-g5jx-5vrq-vrh6/GHSA-g5jx-5vrq-vrh6.json new file mode 100644 index 00000000000..207b49764c6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g5jx-5vrq-vrh6/GHSA-g5jx-5vrq-vrh6.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5jx-5vrq-vrh6", + "modified": "2025-01-31T06:30:51Z", + "published": "2025-01-31T06:30:51Z", + "aliases": [ + "CVE-2024-47898" + ], + "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47898" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g68x-c5mc-5vwr/GHSA-g68x-c5mc-5vwr.json b/advisories/unreviewed/2025/01/GHSA-g68x-c5mc-5vwr/GHSA-g68x-c5mc-5vwr.json new file mode 100644 index 00000000000..5670c74bb4f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g68x-c5mc-5vwr/GHSA-g68x-c5mc-5vwr.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g68x-c5mc-5vwr", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2025-22216" + ], + "details": "A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22216" + }, + { + "type": "WEB", + "url": "https://www.cloudfoundry.org/blog/cve-2025-22216-uaa-missing-zone-validation" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hgx5-vhrf-2496/GHSA-hgx5-vhrf-2496.json b/advisories/unreviewed/2025/01/GHSA-hgx5-vhrf-2496/GHSA-hgx5-vhrf-2496.json new file mode 100644 index 00000000000..d9b2ecb5aa4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hgx5-vhrf-2496/GHSA-hgx5-vhrf-2496.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgx5-vhrf-2496", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-12275" + ], + "details": "The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12275" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ca5bf8bd-a124-4088-a267-fd8a01cb4f4a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j622-84gv-vx9m/GHSA-j622-84gv-vx9m.json b/advisories/unreviewed/2025/01/GHSA-j622-84gv-vx9m/GHSA-j622-84gv-vx9m.json new file mode 100644 index 00000000000..35eee6a324c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j622-84gv-vx9m/GHSA-j622-84gv-vx9m.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j622-84gv-vx9m", + "modified": "2025-01-31T06:30:52Z", + "published": "2025-01-31T06:30:52Z", + "aliases": [ + "CVE-2024-47900" + ], + "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47900" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j92h-624p-jhfp/GHSA-j92h-624p-jhfp.json b/advisories/unreviewed/2025/01/GHSA-j92h-624p-jhfp/GHSA-j92h-624p-jhfp.json new file mode 100644 index 00000000000..d04657c9073 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j92h-624p-jhfp/GHSA-j92h-624p-jhfp.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j92h-624p-jhfp", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13415" + ], + "details": "The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13415" + }, + { + "type": "WEB", + "url": "https://plugins.svn.wordpress.org/tlp-food-menu/tags/5.1.4/app/Controllers/Admin/Ajax/Settings.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3231030%40tlp-food-menu&new=3231030%40tlp-food-menu&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ab6dd645-8831-49bc-b6b1-bb153ef79204?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j9cv-wc33-7qhx/GHSA-j9cv-wc33-7qhx.json b/advisories/unreviewed/2025/01/GHSA-j9cv-wc33-7qhx/GHSA-j9cv-wc33-7qhx.json new file mode 100644 index 00000000000..f54a69e10f3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j9cv-wc33-7qhx/GHSA-j9cv-wc33-7qhx.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9cv-wc33-7qhx", + "modified": "2025-01-31T06:30:51Z", + "published": "2025-01-31T06:30:51Z", + "aliases": [ + "CVE-2024-47891" + ], + "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47891" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m92p-xxm4-35x6/GHSA-m92p-xxm4-35x6.json b/advisories/unreviewed/2025/01/GHSA-m92p-xxm4-35x6/GHSA-m92p-xxm4-35x6.json new file mode 100644 index 00000000000..cfd13bd7b64 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m92p-xxm4-35x6/GHSA-m92p-xxm4-35x6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m92p-xxm4-35x6", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13424" + ], + "details": "The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'niwoosc_ajax' AJAX endpoint in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins settings and modify commission amounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13424" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/ni-woo-sales-commission" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ac4a026b-ed1c-4864-8900-1d70d95af6f4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mwgx-87g3-23wm/GHSA-mwgx-87g3-23wm.json b/advisories/unreviewed/2025/01/GHSA-mwgx-87g3-23wm/GHSA-mwgx-87g3-23wm.json new file mode 100644 index 00000000000..75f4241b8e1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mwgx-87g3-23wm/GHSA-mwgx-87g3-23wm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwgx-87g3-23wm", + "modified": "2025-01-31T06:30:52Z", + "published": "2025-01-31T06:30:52Z", + "aliases": [ + "CVE-2024-10867" + ], + "details": "The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10867" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/borderless" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/88b0acee-f378-487d-8ab9-96146e0cde10?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T05:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p89p-pvgh-v347/GHSA-p89p-pvgh-v347.json b/advisories/unreviewed/2025/01/GHSA-p89p-pvgh-v347/GHSA-p89p-pvgh-v347.json new file mode 100644 index 00000000000..b7a4a5e6cad --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p89p-pvgh-v347/GHSA-p89p-pvgh-v347.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p89p-pvgh-v347", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13219" + ], + "details": "The Privacy Policy Genius WordPress plugin through 2.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13219" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3ad02238-dce1-48ce-986f-fef36b110b2d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pcg2-q4m6-c75w/GHSA-pcg2-q4m6-c75w.json b/advisories/unreviewed/2025/01/GHSA-pcg2-q4m6-c75w/GHSA-pcg2-q4m6-c75w.json new file mode 100644 index 00000000000..12fad88a9d6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pcg2-q4m6-c75w/GHSA-pcg2-q4m6-c75w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcg2-q4m6-c75w", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13225" + ], + "details": "The ECT Home Page Products WordPress plugin through 1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13225" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8efd7d62-3f74-4108-970e-bd5ed24914ff" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qg2j-qw7w-fx96/GHSA-qg2j-qw7w-fx96.json b/advisories/unreviewed/2025/01/GHSA-qg2j-qw7w-fx96/GHSA-qg2j-qw7w-fx96.json new file mode 100644 index 00000000000..b710b2d1e77 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qg2j-qw7w-fx96/GHSA-qg2j-qw7w-fx96.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg2j-qw7w-fx96", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13504" + ], + "details": "The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the dfxp file. This issue affects only Apache-based environments, where dfxp files are handled by default.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13504" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/shared-files/tags/1.7.40" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3231372%40shared-files%2Ftrunk&old=3229309%40shared-files%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9f4210a0-5448-4ff6-876a-37db4ad9b23a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rc29-mm29-hmq2/GHSA-rc29-mm29-hmq2.json b/advisories/unreviewed/2025/01/GHSA-rc29-mm29-hmq2/GHSA-rc29-mm29-hmq2.json new file mode 100644 index 00000000000..827b8bf3aee --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rc29-mm29-hmq2/GHSA-rc29-mm29-hmq2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc29-mm29-hmq2", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13101" + ], + "details": "The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13101" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/03f51b54-0ec2-40ce-a0fa-ef0c4ab0ea99" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rj7j-qmvg-v343/GHSA-rj7j-qmvg-v343.json b/advisories/unreviewed/2025/01/GHSA-rj7j-qmvg-v343/GHSA-rj7j-qmvg-v343.json new file mode 100644 index 00000000000..9273109be12 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rj7j-qmvg-v343/GHSA-rj7j-qmvg-v343.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj7j-qmvg-v343", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13100" + ], + "details": "The OPSI Israel Domestic Shipments WordPress plugin through 2.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13100" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b9261010-ab55-4d18-8fd2-2003f8692ae8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rwvh-cvf4-h99r/GHSA-rwvh-cvf4-h99r.json b/advisories/unreviewed/2025/01/GHSA-rwvh-cvf4-h99r/GHSA-rwvh-cvf4-h99r.json new file mode 100644 index 00000000000..380815cedcf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rwvh-cvf4-h99r/GHSA-rwvh-cvf4-h99r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwvh-cvf4-h99r", + "modified": "2025-01-31T06:30:51Z", + "published": "2025-01-31T06:30:51Z", + "aliases": [ + "CVE-2024-13463" + ], + "details": "The SeatReg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'seatreg' shortcode in all versions up to, and including, 1.56.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13463" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3227873%40seatreg&new=3227873%40seatreg&sfp_email=&sfph_mail=#file1224" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/769bc1fa-4f41-431e-9907-6e03d2c921be?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ww97-66vh-2j8j/GHSA-ww97-66vh-2j8j.json b/advisories/unreviewed/2025/01/GHSA-ww97-66vh-2j8j/GHSA-ww97-66vh-2j8j.json new file mode 100644 index 00000000000..c96ec208470 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ww97-66vh-2j8j/GHSA-ww97-66vh-2j8j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww97-66vh-2j8j", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13717" + ], + "details": "The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae and vcita_ajax_toggle_contact functions in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to enabled and disable widgets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13717" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/lead-capturing-call-to-actions-by-vcita/trunk/vcita-ajax-function.php#L5" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/93800bd9-5d11-4d5b-99b2-4c5c78510af7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x3vp-whxw-pj5c/GHSA-x3vp-whxw-pj5c.json b/advisories/unreviewed/2025/01/GHSA-x3vp-whxw-pj5c/GHSA-x3vp-whxw-pj5c.json new file mode 100644 index 00000000000..1b03d4bd009 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x3vp-whxw-pj5c/GHSA-x3vp-whxw-pj5c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3vp-whxw-pj5c", + "modified": "2025-01-31T06:30:53Z", + "published": "2025-01-31T06:30:53Z", + "aliases": [ + "CVE-2024-13221" + ], + "details": "The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13221" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/693f4cc4-a082-46bc-abc9-a08919f70157" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T06:15:28Z" + } +} \ No newline at end of file