diff --git a/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json b/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json index 58569669bca..4b227096855 100644 --- a/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json +++ b/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xpw-6594-8f5m", - "modified": "2025-04-25T03:30:33Z", + "modified": "2025-04-30T06:30:22Z", "published": "2025-01-22T15:32:34Z", "aliases": [ "CVE-2025-0395" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0395" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00039.html" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20250228-0006" diff --git a/advisories/unreviewed/2025/04/GHSA-9xpp-wh6r-3gmg/GHSA-9xpp-wh6r-3gmg.json b/advisories/unreviewed/2025/04/GHSA-9xpp-wh6r-3gmg/GHSA-9xpp-wh6r-3gmg.json new file mode 100644 index 00000000000..05be5994fbf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9xpp-wh6r-3gmg/GHSA-9xpp-wh6r-3gmg.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xpp-wh6r-3gmg", + "modified": "2025-04-30T06:30:21Z", + "published": "2025-04-30T06:30:21Z", + "aliases": [ + "CVE-2025-3953" + ], + "details": "The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'optionUpdater' function in all versions up to, and including, 14.13.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary plugin settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3953" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.13.2/src/Service/Admin/AjaxOptionUpdater.php#L33" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3283791" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/07f7ef07-0f14-4b74-8d47-d5dece4954b0?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T06:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ppf8-hgp4-7rvj/GHSA-ppf8-hgp4-7rvj.json b/advisories/unreviewed/2025/04/GHSA-ppf8-hgp4-7rvj/GHSA-ppf8-hgp4-7rvj.json new file mode 100644 index 00000000000..df9902062b7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ppf8-hgp4-7rvj/GHSA-ppf8-hgp4-7rvj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppf8-hgp4-7rvj", + "modified": "2025-04-30T06:30:21Z", + "published": "2025-04-30T06:30:21Z", + "aliases": [ + "CVE-2025-3471" + ], + "details": "The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3471" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/aa21dd2b-1277-4cf9-b7f6-d4f8a6d518c1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-30T06:15:53Z" + } +} \ No newline at end of file