diff --git a/advisories/unreviewed/2024/07/GHSA-5pqp-q4fm-4p4h/GHSA-5pqp-q4fm-4p4h.json b/advisories/unreviewed/2024/07/GHSA-5pqp-q4fm-4p4h/GHSA-5pqp-q4fm-4p4h.json new file mode 100644 index 00000000000..165fe498aa1 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-5pqp-q4fm-4p4h/GHSA-5pqp-q4fm-4p4h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pqp-q4fm-4p4h", + "modified": "2024-07-23T06:32:00Z", + "published": "2024-07-23T06:32:00Z", + "aliases": [ + "CVE-2024-4260" + ], + "details": "The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4260" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/69f33e20-8ff4-491c-8f37-a4eadd4ea8cf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8r7f-vjf7-pvp7/GHSA-8r7f-vjf7-pvp7.json b/advisories/unreviewed/2024/07/GHSA-8r7f-vjf7-pvp7/GHSA-8r7f-vjf7-pvp7.json new file mode 100644 index 00000000000..bb6f5e0fd3d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8r7f-vjf7-pvp7/GHSA-8r7f-vjf7-pvp7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r7f-vjf7-pvp7", + "modified": "2024-07-23T06:32:00Z", + "published": "2024-07-23T06:32:00Z", + "aliases": [ + "CVE-2024-6231" + ], + "details": "The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6231" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/75ad1d8f-edc3-4eb3-b4c0-73832c0a4ca0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-wcww-8mcp-8rx7/GHSA-wcww-8mcp-8rx7.json b/advisories/unreviewed/2024/07/GHSA-wcww-8mcp-8rx7/GHSA-wcww-8mcp-8rx7.json new file mode 100644 index 00000000000..d4bf9a6646e --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wcww-8mcp-8rx7/GHSA-wcww-8mcp-8rx7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcww-8mcp-8rx7", + "modified": "2024-07-23T06:32:00Z", + "published": "2024-07-23T06:32:00Z", + "aliases": [ + "CVE-2024-6420" + ], + "details": "The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6420" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/dfda6577-81aa-4397-a2d6-1d736f9ebd44" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-23T06:15:11Z" + } +} \ No newline at end of file