Publish Advisories

GHSA-5pqp-q4fm-4p4h
GHSA-8r7f-vjf7-pvp7
GHSA-wcww-8mcp-8rx7
This commit is contained in:
advisory-database[bot]
2024-07-23 06:33:32 +00:00
parent 018e4b1c76
commit a447dd93fa
3 changed files with 105 additions and 0 deletions
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5pqp-q4fm-4p4h",
"modified": "2024-07-23T06:32:00Z",
"published": "2024-07-23T06:32:00Z",
"aliases": [
"CVE-2024-4260"
],
"details": "The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4260"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/69f33e20-8ff4-491c-8f37-a4eadd4ea8cf"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-23T06:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8r7f-vjf7-pvp7",
"modified": "2024-07-23T06:32:00Z",
"published": "2024-07-23T06:32:00Z",
"aliases": [
"CVE-2024-6231"
],
"details": "The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6231"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/75ad1d8f-edc3-4eb3-b4c0-73832c0a4ca0"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-23T06:15:11Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wcww-8mcp-8rx7",
"modified": "2024-07-23T06:32:00Z",
"published": "2024-07-23T06:32:00Z",
"aliases": [
"CVE-2024-6420"
],
"details": "The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6420"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/dfda6577-81aa-4397-a2d6-1d736f9ebd44"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-23T06:15:11Z"
}
}