Publish Advisories

GHSA-fvwj-582j-236v
GHSA-q975-8hh3-m9wj
This commit is contained in:
advisory-database[bot]
2025-06-07 06:31:34 +00:00
parent 704ba78151
commit 8ba9c31578
2 changed files with 76 additions and 0 deletions
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvwj-582j-236v",
"modified": "2025-06-07T06:30:18Z",
"published": "2025-06-07T06:30:18Z",
"aliases": [
"CVE-2025-47601"
],
"details": "Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a through 2.1.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47601"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/maxi-blocks/vulnerability/wordpress-maxiblocks-plugin-2-1-0-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-07T05:15:24Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q975-8hh3-m9wj",
"modified": "2025-06-07T06:30:18Z",
"published": "2025-06-07T06:30:18Z",
"aliases": [
"CVE-2025-5814"
],
"details": "The Profiler What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsd_plugin_control() function in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to reactivate previously deactivated plugins after accessing the \"Profiler\" page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5814"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/profiler-what-slowing-down/trunk/actions.php#L31"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9213db60-c0c1-44a9-9b8c-621029c3a08f?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-07T05:15:24Z"
}
}