diff --git a/advisories/unreviewed/2025/04/GHSA-24w7-4342-c5ww/GHSA-24w7-4342-c5ww.json b/advisories/unreviewed/2025/04/GHSA-24w7-4342-c5ww/GHSA-24w7-4342-c5ww.json new file mode 100644 index 00000000000..dbb0b1e1f57 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-24w7-4342-c5ww/GHSA-24w7-4342-c5ww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24w7-4342-c5ww", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-32198" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy. This issue affects Brizy: from n/a through 2.6.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32198" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/brizy/vulnerability/wordpress-brizy-plugin-2-6-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-28wv-vf39-3r2q/GHSA-28wv-vf39-3r2q.json b/advisories/unreviewed/2025/04/GHSA-28wv-vf39-3r2q/GHSA-28wv-vf39-3r2q.json new file mode 100644 index 00000000000..6e134cba34b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-28wv-vf39-3r2q/GHSA-28wv-vf39-3r2q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28wv-vf39-3r2q", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32230" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS. This issue affects Tutor LMS: from n/a through 3.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32230" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tutor/vulnerability/wordpress-tutor-lms-plugin-3-4-0-html-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2wv7-wgx8-4hj7/GHSA-2wv7-wgx8-4hj7.json b/advisories/unreviewed/2025/04/GHSA-2wv7-wgx8-4hj7/GHSA-2wv7-wgx8-4hj7.json new file mode 100644 index 00000000000..239fb2d17ed --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2wv7-wgx8-4hj7/GHSA-2wv7-wgx8-4hj7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wv7-wgx8-4hj7", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-32116" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studi7 QR Master allows Reflected XSS. This issue affects QR Master: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32116" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/qr-master/vulnerability/wordpress-qr-master-plugin-1-0-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-32mq-5gxg-w4qc/GHSA-32mq-5gxg-w4qc.json b/advisories/unreviewed/2025/04/GHSA-32mq-5gxg-w4qc/GHSA-32mq-5gxg-w4qc.json new file mode 100644 index 00000000000..4146c8e0fe3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-32mq-5gxg-w4qc/GHSA-32mq-5gxg-w4qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32mq-5gxg-w4qc", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32214" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hive Support Hive Support allows Stored XSS. This issue affects Hive Support: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32214" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hive-support/vulnerability/wordpress-hive-support-plugin-1-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-35vx-vx6v-j9x7/GHSA-35vx-vx6v-j9x7.json b/advisories/unreviewed/2025/04/GHSA-35vx-vx6v-j9x7/GHSA-35vx-vx6v-j9x7.json new file mode 100644 index 00000000000..76f6550d83b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-35vx-vx6v-j9x7/GHSA-35vx-vx6v-j9x7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35vx-vx6v-j9x7", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32215" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite by Online ADA allows Stored XSS. This issue affects Accessibility Suite by Online ADA: from n/a through 4.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32215" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/online-accessibility/vulnerability/wordpress-accessibility-suite-plugin-4-17-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3698-cx82-84gv/GHSA-3698-cx82-84gv.json b/advisories/unreviewed/2025/04/GHSA-3698-cx82-84gv/GHSA-3698-cx82-84gv.json new file mode 100644 index 00000000000..53b51a70bb3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3698-cx82-84gv/GHSA-3698-cx82-84gv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3698-cx82-84gv", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32209" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Total processing card payments for WooCommerce allows Path Traversal. This issue affects Total processing card payments for WooCommerce: from n/a through 7.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32209" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/totalprocessing-card-payments/vulnerability/wordpress-total-processing-card-payments-for-woocommerce-plugin-7-1-3-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-379w-vvjw-9pqf/GHSA-379w-vvjw-9pqf.json b/advisories/unreviewed/2025/04/GHSA-379w-vvjw-9pqf/GHSA-379w-vvjw-9pqf.json new file mode 100644 index 00000000000..a26e556d51a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-379w-vvjw-9pqf/GHSA-379w-vvjw-9pqf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-379w-vvjw-9pqf", + "modified": "2025-04-10T09:30:26Z", + "published": "2025-04-10T09:30:26Z", + "aliases": [ + "CVE-2025-32687" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magnigenie Review Stars Count For WooCommerce allows SQL Injection. This issue affects Review Stars Count For WooCommerce: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32687" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/review-stars-count-for-woocommerce/vulnerability/wordpress-review-stars-count-for-woocommerce-2-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-37mx-229g-629x/GHSA-37mx-229g-629x.json b/advisories/unreviewed/2025/04/GHSA-37mx-229g-629x/GHSA-37mx-229g-629x.json new file mode 100644 index 00000000000..551ae72ff37 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-37mx-229g-629x/GHSA-37mx-229g-629x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37mx-229g-629x", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-32145" + ], + "details": "Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently allows Object Injection. This issue affects WpEvently: from n/a through 4.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32145" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mage-eventpress/vulnerability/wordpress-wpevently-plugin-4-3-5-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3qhq-q769-r2pc/GHSA-3qhq-q769-r2pc.json b/advisories/unreviewed/2025/04/GHSA-3qhq-q769-r2pc/GHSA-3qhq-q769-r2pc.json new file mode 100644 index 00000000000..3b65a33c2c1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3qhq-q769-r2pc/GHSA-3qhq-q769-r2pc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qhq-q769-r2pc", + "modified": "2025-04-10T09:30:26Z", + "published": "2025-04-10T09:30:26Z", + "aliases": [ + "CVE-2025-32259" + ], + "details": "Missing Authorization vulnerability in Alimir WP ULike. This issue affects WP ULike: from n/a through 4.7.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32259" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ulike/vulnerability/wordpress-wp-ulike-plugin-4-7-9-1-content-spoofing-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4923-g3qg-hvqc/GHSA-4923-g3qg-hvqc.json b/advisories/unreviewed/2025/04/GHSA-4923-g3qg-hvqc/GHSA-4923-g3qg-hvqc.json new file mode 100644 index 00000000000..7169b317e3b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4923-g3qg-hvqc/GHSA-4923-g3qg-hvqc.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4923-g3qg-hvqc", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-2873" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Further investigation showed that it was not a security issue. The issue relates to a session attribute used for login redirection. It poses no security risk and does not expose sensitive data. No vulnerability present.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2873" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4f47-qgv4-g7jp/GHSA-4f47-qgv4-g7jp.json b/advisories/unreviewed/2025/04/GHSA-4f47-qgv4-g7jp/GHSA-4f47-qgv4-g7jp.json new file mode 100644 index 00000000000..770b57bf3b4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4f47-qgv4-g7jp/GHSA-4f47-qgv4-g7jp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f47-qgv4-g7jp", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32202" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress allows Upload a Web Shell to a Web Server. This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32202" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/insert-or-embed-articulate-content-into-wordpress/vulnerability/wordpress-insert-or-embed-articulate-content-into-wordpress-plugin-4-3000000025-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-562x-pphr-6524/GHSA-562x-pphr-6524.json b/advisories/unreviewed/2025/04/GHSA-562x-pphr-6524/GHSA-562x-pphr-6524.json new file mode 100644 index 00000000000..0ec7dba6e5b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-562x-pphr-6524/GHSA-562x-pphr-6524.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-562x-pphr-6524", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32236" + ], + "details": "Missing Authorization vulnerability in Vagonic Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic. This issue affects Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic: from n/a through 1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32236" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vagonic-sortable/vulnerability/wordpress-woocommerce-products-reorder-drag-drop-multiple-sort-plugin-1-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5f2c-5gww-2fhf/GHSA-5f2c-5gww-2fhf.json b/advisories/unreviewed/2025/04/GHSA-5f2c-5gww-2fhf/GHSA-5f2c-5gww-2fhf.json new file mode 100644 index 00000000000..06fd49bde1c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5f2c-5gww-2fhf/GHSA-5f2c-5gww-2fhf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f2c-5gww-2fhf", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32227" + ], + "details": "Authentication Bypass by Spoofing vulnerability in Asgaros Asgaros Forum allows Identity Spoofing. This issue affects Asgaros Forum: from n/a through 3.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32227" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/asgaros-forum/vulnerability/wordpress-asgaros-forum-plugin-3-0-0-file-upload-numbers-bypass-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5jrg-6mrh-grq9/GHSA-5jrg-6mrh-grq9.json b/advisories/unreviewed/2025/04/GHSA-5jrg-6mrh-grq9/GHSA-5jrg-6mrh-grq9.json new file mode 100644 index 00000000000..eacedfe6f66 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5jrg-6mrh-grq9/GHSA-5jrg-6mrh-grq9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jrg-6mrh-grq9", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32212" + ], + "details": "Missing Authorization vulnerability in Specia Theme Specia Companion allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Specia Companion: from n/a through 4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32212" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/specia-companion/vulnerability/wordpress-specia-companion-plugin-4-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5mqr-58w3-g2gv/GHSA-5mqr-58w3-g2gv.json b/advisories/unreviewed/2025/04/GHSA-5mqr-58w3-g2gv/GHSA-5mqr-58w3-g2gv.json new file mode 100644 index 00000000000..1c20367839e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5mqr-58w3-g2gv/GHSA-5mqr-58w3-g2gv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mqr-58w3-g2gv", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:23Z", + "aliases": [ + "CVE-2025-3417" + ], + "details": "The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_set_global_option() function in versions 1.3 to 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3417" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/embedder/trunk/emb-admin-ajax.php#L41" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fa86bcb9-e558-4b60-9473-65cd6f9663fd?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T07:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5xfp-2339-j582/GHSA-5xfp-2339-j582.json b/advisories/unreviewed/2025/04/GHSA-5xfp-2339-j582/GHSA-5xfp-2339-j582.json new file mode 100644 index 00000000000..6ee1e03c438 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5xfp-2339-j582/GHSA-5xfp-2339-j582.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xfp-2339-j582", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32242" + ], + "details": "Missing Authorization vulnerability in Hive Support Hive Support allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Hive Support: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32242" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hive-support/vulnerability/wordpress-hive-support-plugin-1-2-2-broken-access-control-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6w76-cc53-2pjr/GHSA-6w76-cc53-2pjr.json b/advisories/unreviewed/2025/04/GHSA-6w76-cc53-2pjr/GHSA-6w76-cc53-2pjr.json new file mode 100644 index 00000000000..0284a76b1f7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6w76-cc53-2pjr/GHSA-6w76-cc53-2pjr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w76-cc53-2pjr", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32260" + ], + "details": "Missing Authorization vulnerability in Detheme DethemeKit For Elementor. This issue affects DethemeKit For Elementor: from n/a through 2.1.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32260" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dethemekit-for-elementor/vulnerability/wordpress-dethemekit-for-elementor-plugin-2-1-10-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-89vf-799v-8hrp/GHSA-89vf-799v-8hrp.json b/advisories/unreviewed/2025/04/GHSA-89vf-799v-8hrp/GHSA-89vf-799v-8hrp.json new file mode 100644 index 00000000000..d45398fa59e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-89vf-799v-8hrp/GHSA-89vf-799v-8hrp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89vf-799v-8hrp", + "modified": "2025-04-10T09:30:26Z", + "published": "2025-04-10T09:30:26Z", + "aliases": [ + "CVE-2025-32668" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager allows PHP Local File Inclusion. This issue affects Real Estate Manager: from n/a through 7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32668" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/real-estate-manager/vulnerability/wordpress-real-estate-manager-plugin-7-3-local-file-inclusion-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8h58-9hjg-3xqh/GHSA-8h58-9hjg-3xqh.json b/advisories/unreviewed/2025/04/GHSA-8h58-9hjg-3xqh/GHSA-8h58-9hjg-3xqh.json new file mode 100644 index 00000000000..6f1c594f6a8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8h58-9hjg-3xqh/GHSA-8h58-9hjg-3xqh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h58-9hjg-3xqh", + "modified": "2025-04-10T09:30:23Z", + "published": "2025-04-10T09:30:23Z", + "aliases": [ + "CVE-2024-13896" + ], + "details": "The WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages WordPress plugin through 1.4.3 processes user-supplied input as a regular expression via the wp_geshi_filter_replace_code() function, which could lead to Regular Expression Denial of Service (ReDoS) issue", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13896" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b8b622ea-e090-45ad-8755-b050fc055231" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T07:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8qcx-qr7w-9fq4/GHSA-8qcx-qr7w-9fq4.json b/advisories/unreviewed/2025/04/GHSA-8qcx-qr7w-9fq4/GHSA-8qcx-qr7w-9fq4.json new file mode 100644 index 00000000000..735743ed6ea --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8qcx-qr7w-9fq4/GHSA-8qcx-qr7w-9fq4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qcx-qr7w-9fq4", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32205" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Forms. This issue affects Piotnet Forms: from n/a through 1.0.30.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32205" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/piotnetforms/vulnerability/wordpress-piotnetforms-plugin-1-0-30-path-traversal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9r3j-xmvw-9j69/GHSA-9r3j-xmvw-9j69.json b/advisories/unreviewed/2025/04/GHSA-9r3j-xmvw-9j69/GHSA-9r3j-xmvw-9j69.json new file mode 100644 index 00000000000..86eda6a0481 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9r3j-xmvw-9j69/GHSA-9r3j-xmvw-9j69.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r3j-xmvw-9j69", + "modified": "2025-04-10T09:30:26Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32275" + ], + "details": "Authentication Bypass by Spoofing vulnerability in Ays Pro Survey Maker allows Identity Spoofing. This issue affects Survey Maker: from n/a through 5.1.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32275" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/survey-maker/vulnerability/wordpress-survey-maker-plugin-5-1-5-0-bypass-vulnerability-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cc76-vj8r-jr9w/GHSA-cc76-vj8r-jr9w.json b/advisories/unreviewed/2025/04/GHSA-cc76-vj8r-jr9w/GHSA-cc76-vj8r-jr9w.json new file mode 100644 index 00000000000..c774c8694a6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cc76-vj8r-jr9w/GHSA-cc76-vj8r-jr9w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc76-vj8r-jr9w", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2024-38865" + ], + "details": "Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to originate from a host with the same contact group or from an event generated with an unknown host.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38865" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17028" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-140" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ccc3-69g9-36mx/GHSA-ccc3-69g9-36mx.json b/advisories/unreviewed/2025/04/GHSA-ccc3-69g9-36mx/GHSA-ccc3-69g9-36mx.json new file mode 100644 index 00000000000..b1bb15e6c12 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ccc3-69g9-36mx/GHSA-ccc3-69g9-36mx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccc3-69g9-36mx", + "modified": "2025-04-10T09:30:26Z", + "published": "2025-04-10T09:30:26Z", + "aliases": [ + "CVE-2025-22279" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetCompareWishlist allows PHP Local File Inclusion.This issue affects JetCompareWishlist: from n/a through 1.5.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22279" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-compare-wishlist/vulnerability/wordpress-jetcomparewishlist-plugin-1-5-9-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cg22-jcvj-c26m/GHSA-cg22-jcvj-c26m.json b/advisories/unreviewed/2025/04/GHSA-cg22-jcvj-c26m/GHSA-cg22-jcvj-c26m.json new file mode 100644 index 00000000000..72087ebf2db --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cg22-jcvj-c26m/GHSA-cg22-jcvj-c26m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg22-jcvj-c26m", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-32128" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aaronfrey Nearby Locations allows SQL Injection. This issue affects Nearby Locations: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32128" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nearby-locations/vulnerability/wordpress-nearby-locations-plugin-1-1-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cghx-64gx-q48x/GHSA-cghx-64gx-q48x.json b/advisories/unreviewed/2025/04/GHSA-cghx-64gx-q48x/GHSA-cghx-64gx-q48x.json new file mode 100644 index 00000000000..facb883ae54 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cghx-64gx-q48x/GHSA-cghx-64gx-q48x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cghx-64gx-q48x", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-32115" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Popping Content Light allows Reflected XSS. This issue affects Popping Content Light: from n/a through 2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32115" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/popping-content-light/vulnerability/wordpress-popping-content-light-plugin-2-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ch72-mh4v-433q/GHSA-ch72-mh4v-433q.json b/advisories/unreviewed/2025/04/GHSA-ch72-mh4v-433q/GHSA-ch72-mh4v-433q.json new file mode 100644 index 00000000000..c79582a45e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ch72-mh4v-433q/GHSA-ch72-mh4v-433q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch72-mh4v-433q", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-32140" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail allows Upload a Web Shell to a Web Server. This issue affects WP Remote Thumbnail: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32140" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-remote-thumbnail/vulnerability/wordpress-wp-remote-thumbnail-plugin-1-3-1-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f987-2cfv-rc2w/GHSA-f987-2cfv-rc2w.json b/advisories/unreviewed/2025/04/GHSA-f987-2cfv-rc2w/GHSA-f987-2cfv-rc2w.json new file mode 100644 index 00000000000..e2177b41ffb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f987-2cfv-rc2w/GHSA-f987-2cfv-rc2w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f987-2cfv-rc2w", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-32199" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyale-vc Contact Form Builder by vcita. This issue affects Contact Form Builder by vcita: from n/a through 4.10.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32199" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-form-with-a-meeting-scheduler-by-vcita/vulnerability/wordpress-contact-form-builder-by-vcita-plugin-4-10-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ff7v-488g-c894/GHSA-ff7v-488g-c894.json b/advisories/unreviewed/2025/04/GHSA-ff7v-488g-c894/GHSA-ff7v-488g-c894.json new file mode 100644 index 00000000000..4471985ccf8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ff7v-488g-c894/GHSA-ff7v-488g-c894.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff7v-488g-c894", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-32139" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bradvin FooBox Image Lightbox . This issue affects FooBox Image Lightbox : from n/a through 2.7.33.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32139" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/foobox-image-lightbox/vulnerability/wordpress-lightbox-modal-popup-wordpress-plugin-foobox-plugin-2-7-33-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fgvc-pmvm-xpxw/GHSA-fgvc-pmvm-xpxw.json b/advisories/unreviewed/2025/04/GHSA-fgvc-pmvm-xpxw/GHSA-fgvc-pmvm-xpxw.json new file mode 100644 index 00000000000..fe7f0984ea4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fgvc-pmvm-xpxw/GHSA-fgvc-pmvm-xpxw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgvc-pmvm-xpxw", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32213" + ], + "details": "Missing Authorization vulnerability in flothemesplugins Flo Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Flo Forms: from n/a through 1.0.43.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32213" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flo-forms/vulnerability/wordpress-flo-forms-plugin-1-0-43-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fjrr-5cxp-m5h2/GHSA-fjrr-5cxp-m5h2.json b/advisories/unreviewed/2025/04/GHSA-fjrr-5cxp-m5h2/GHSA-fjrr-5cxp-m5h2.json new file mode 100644 index 00000000000..4d8b84c8ad7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fjrr-5cxp-m5h2/GHSA-fjrr-5cxp-m5h2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjrr-5cxp-m5h2", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-31524" + ], + "details": "Incorrect Privilege Assignment vulnerability in NotFound WP User Profiles allows Privilege Escalation. This issue affects WP User Profiles: from n/a through 2.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31524" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-users-profiles/vulnerability/wordpress-wp-user-profiles-plugin-2-6-2-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fp86-6g64-xw6f/GHSA-fp86-6g64-xw6f.json b/advisories/unreviewed/2025/04/GHSA-fp86-6g64-xw6f/GHSA-fp86-6g64-xw6f.json new file mode 100644 index 00000000000..b1ec6a99dae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fp86-6g64-xw6f/GHSA-fp86-6g64-xw6f.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp86-6g64-xw6f", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-2805" + ], + "details": "The ORDER POST plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2805" + }, + { + "type": "WEB", + "url": "https://plugins.svn.wordpress.org/order-post/trunk/wp_post_order.php" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/order-post/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d35ea739-5ee9-4779-87d5-3f13b11229cf?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T07:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fqh7-g3q7-cj68/GHSA-fqh7-g3q7-cj68.json b/advisories/unreviewed/2025/04/GHSA-fqh7-g3q7-cj68/GHSA-fqh7-g3q7-cj68.json new file mode 100644 index 00000000000..b95a6a15a6b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fqh7-g3q7-cj68/GHSA-fqh7-g3q7-cj68.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqh7-g3q7-cj68", + "modified": "2025-04-10T09:30:26Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32282" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ShareThis ShareThis Dashboard for Google Analytics. This issue affects ShareThis Dashboard for Google Analytics: from n/a through 3.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32282" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/googleanalytics/vulnerability/wordpress-sharethis-dashboard-for-google-analytics-plugin-3-2-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gh74-fmpx-h5cx/GHSA-gh74-fmpx-h5cx.json b/advisories/unreviewed/2025/04/GHSA-gh74-fmpx-h5cx/GHSA-gh74-fmpx-h5cx.json new file mode 100644 index 00000000000..b22708888d0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gh74-fmpx-h5cx/GHSA-gh74-fmpx-h5cx.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh74-fmpx-h5cx", + "modified": "2025-04-10T09:30:23Z", + "published": "2025-04-10T09:30:23Z", + "aliases": [ + "CVE-2024-10894" + ], + "details": "The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'datepicker', 'textarea', and 'text' in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10894" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/payment-forms-for-paystack/tags/4.0.0/includes/classes/class-field-shortcodes.php#L218" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/payment-forms-for-paystack/tags/4.0.0/includes/classes/class-field-shortcodes.php#L62" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/payment-forms-for-paystack/tags/4.0.0/includes/classes/class-field-shortcodes.php#L99" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3210130%40payment-forms-for-paystack&new=3210130%40payment-forms-for-paystack&sfp_email=&sfph_mail=#file7" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/20b0a946-f429-4615-9d16-4a95a9120c3d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T07:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gqqp-7v9r-jwf2/GHSA-gqqp-7v9r-jwf2.json b/advisories/unreviewed/2025/04/GHSA-gqqp-7v9r-jwf2/GHSA-gqqp-7v9r-jwf2.json new file mode 100644 index 00000000000..69f7e2fb1dd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gqqp-7v9r-jwf2/GHSA-gqqp-7v9r-jwf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqqp-7v9r-jwf2", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-32160" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON. This issue affects EventON: from n/a through 2.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32160" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eventon-lite/vulnerability/wordpress-eventon-plugin-2-3-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gwjc-9mv6-q8q2/GHSA-gwjc-9mv6-q8q2.json b/advisories/unreviewed/2025/04/GHSA-gwjc-9mv6-q8q2/GHSA-gwjc-9mv6-q8q2.json new file mode 100644 index 00000000000..523f49c8385 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gwjc-9mv6-q8q2/GHSA-gwjc-9mv6-q8q2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwjc-9mv6-q8q2", + "modified": "2025-04-10T09:30:23Z", + "published": "2025-04-10T09:30:23Z", + "aliases": [ + "CVE-2024-13874" + ], + "details": "The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13874" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c808e7cf-3285-402b-ab4f-a40ab822b12e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T07:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h24r-9jj7-jw68/GHSA-h24r-9jj7-jw68.json b/advisories/unreviewed/2025/04/GHSA-h24r-9jj7-jw68/GHSA-h24r-9jj7-jw68.json new file mode 100644 index 00000000000..63850c09b8a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h24r-9jj7-jw68/GHSA-h24r-9jj7-jw68.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h24r-9jj7-jw68", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32221" + ], + "details": "Missing Authorization vulnerability in Spider Themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EazyDocs: from n/a through 2.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32221" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eazydocs/vulnerability/wordpress-eazydocs-plugin-2-6-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hchj-r5q6-j5p3/GHSA-hchj-r5q6-j5p3.json b/advisories/unreviewed/2025/04/GHSA-hchj-r5q6-j5p3/GHSA-hchj-r5q6-j5p3.json new file mode 100644 index 00000000000..1211fdf6973 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hchj-r5q6-j5p3/GHSA-hchj-r5q6-j5p3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hchj-r5q6-j5p3", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-32119" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CardGate CardGate Payments for WooCommerce allows Blind SQL Injection. This issue affects CardGate Payments for WooCommerce: from n/a through 3.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32119" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cardgate/vulnerability/wordpress-cardgate-payments-for-woocommerce-plugin-3-2-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j3q6-2vww-g93w/GHSA-j3q6-2vww-g93w.json b/advisories/unreviewed/2025/04/GHSA-j3q6-2vww-g93w/GHSA-j3q6-2vww-g93w.json new file mode 100644 index 00000000000..4a2b099f718 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j3q6-2vww-g93w/GHSA-j3q6-2vww-g93w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3q6-2vww-g93w", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32243" + ], + "details": "Missing Authorization vulnerability in Toast Plugins Internal Link Optimiser allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Internal Link Optimiser: from n/a through 5.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32243" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/internal-link-finder/vulnerability/wordpress-internal-link-optimiser-plugin-5-1-2-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j6q8-9xcm-qvmj/GHSA-j6q8-9xcm-qvmj.json b/advisories/unreviewed/2025/04/GHSA-j6q8-9xcm-qvmj/GHSA-j6q8-9xcm-qvmj.json new file mode 100644 index 00000000000..57d70d094ab --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j6q8-9xcm-qvmj/GHSA-j6q8-9xcm-qvmj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6q8-9xcm-qvmj", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-32158" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in aThemes aThemes Addons for Elementor. This issue affects aThemes Addons for Elementor: from n/a through 1.0.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32158" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/athemes-addons-for-elementor-lite/vulnerability/wordpress-athemes-addons-for-elementor-plugin-1-0-15-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jpr3-g2j4-m8cp/GHSA-jpr3-g2j4-m8cp.json b/advisories/unreviewed/2025/04/GHSA-jpr3-g2j4-m8cp/GHSA-jpr3-g2j4-m8cp.json new file mode 100644 index 00000000000..25a981324c0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jpr3-g2j4-m8cp/GHSA-jpr3-g2j4-m8cp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpr3-g2j4-m8cp", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32244" + ], + "details": "Missing Authorization vulnerability in QuantumCloud SEO Help allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SEO Help: from n/a through 6.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32244" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/seo-help/vulnerability/wordpress-seo-help-plugin-6-6-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m6j4-f8cm-gcq2/GHSA-m6j4-f8cm-gcq2.json b/advisories/unreviewed/2025/04/GHSA-m6j4-f8cm-gcq2/GHSA-m6j4-f8cm-gcq2.json new file mode 100644 index 00000000000..ce5015f51d4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m6j4-f8cm-gcq2/GHSA-m6j4-f8cm-gcq2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6j4-f8cm-gcq2", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-2719" + ], + "details": "The Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swatches) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in versions 1.2.8 to 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to 1/true on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny access to legitimate users or be used to set some values to true, such as registration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2719" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/swatchly/tags/1.2.8/includes/Admin/Notices.php#L59" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/39336115-5993-49e1-b810-80a712e8e42b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T07:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mh43-rrpq-hq9g/GHSA-mh43-rrpq-hq9g.json b/advisories/unreviewed/2025/04/GHSA-mh43-rrpq-hq9g/GHSA-mh43-rrpq-hq9g.json new file mode 100644 index 00000000000..3fd94123c73 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mh43-rrpq-hq9g/GHSA-mh43-rrpq-hq9g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh43-rrpq-hq9g", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-32114" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 5sterrenspecialist 5sterrenspecialist allows Reflected XSS. This issue affects 5sterrenspecialist: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32114" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/5-sterrenspecialist/vulnerability/wordpress-5sterrenspecialist-plugin-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p7hf-xm76-fx3q/GHSA-p7hf-xm76-fx3q.json b/advisories/unreviewed/2025/04/GHSA-p7hf-xm76-fx3q/GHSA-p7hf-xm76-fx3q.json new file mode 100644 index 00000000000..13370466a69 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p7hf-xm76-fx3q/GHSA-p7hf-xm76-fx3q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7hf-xm76-fx3q", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32240" + ], + "details": "Missing Authorization vulnerability in NotFound Site Notify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Site Notify: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32240" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/site-notify/vulnerability/wordpress-site-notify-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pcq4-g857-j48f/GHSA-pcq4-g857-j48f.json b/advisories/unreviewed/2025/04/GHSA-pcq4-g857-j48f/GHSA-pcq4-g857-j48f.json new file mode 100644 index 00000000000..a59b7049c9d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pcq4-g857-j48f/GHSA-pcq4-g857-j48f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcq4-g857-j48f", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32216" + ], + "details": "Missing Authorization vulnerability in Spider Themes Spider Elements – Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Spider Elements – Addons for Elementor: from n/a through 1.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32216" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/spider-elements/vulnerability/wordpress-spider-elements-addons-for-elementor-plugin-1-6-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q322-wwm4-jwg5/GHSA-q322-wwm4-jwg5.json b/advisories/unreviewed/2025/04/GHSA-q322-wwm4-jwg5/GHSA-q322-wwm4-jwg5.json new file mode 100644 index 00000000000..b45426465dc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q322-wwm4-jwg5/GHSA-q322-wwm4-jwg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q322-wwm4-jwg5", + "modified": "2025-04-10T09:30:26Z", + "published": "2025-04-10T09:30:26Z", + "aliases": [ + "CVE-2025-27081" + ], + "details": "A potential security vulnerability in HPE NonStop OSM Service Connection Suite could potentially be exploited to allow a local Denial of Service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27081" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbns04836en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r297-g992-2jwc/GHSA-r297-g992-2jwc.json b/advisories/unreviewed/2025/04/GHSA-r297-g992-2jwc/GHSA-r297-g992-2jwc.json new file mode 100644 index 00000000000..dcb711411a7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r297-g992-2jwc/GHSA-r297-g992-2jwc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r297-g992-2jwc", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32228" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah Ai Image Alt Text Generator for WP. This issue affects Ai Image Alt Text Generator for WP: from n/a through 1.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32228" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-image-alt-text-generator-for-wp/vulnerability/wordpress-ai-image-alt-text-generator-for-wp-plugin-1-0-8-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rfm6-fgv5-9666/GHSA-rfm6-fgv5-9666.json b/advisories/unreviewed/2025/04/GHSA-rfm6-fgv5-9666/GHSA-rfm6-fgv5-9666.json new file mode 100644 index 00000000000..afbbee57ba9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rfm6-fgv5-9666/GHSA-rfm6-fgv5-9666.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfm6-fgv5-9666", + "modified": "2025-04-10T09:30:23Z", + "published": "2025-04-10T09:30:23Z", + "aliases": [ + "CVE-2024-13909" + ], + "details": "The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13909" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/accredible-certificates/tags/1.4.9/users_list.php#L48" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/accredible-certificates/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f96d3773-29a1-44bd-904a-905aff2b345e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T07:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rg3m-w4gr-f838/GHSA-rg3m-w4gr-f838.json b/advisories/unreviewed/2025/04/GHSA-rg3m-w4gr-f838/GHSA-rg3m-w4gr-f838.json new file mode 100644 index 00000000000..dc18654cae5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rg3m-w4gr-f838/GHSA-rg3m-w4gr-f838.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg3m-w4gr-f838", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32208" + ], + "details": "Missing Authorization vulnerability in Hive Support Hive Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hive Support: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32208" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hive-support/vulnerability/wordpress-hive-support-plugin-1-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w37h-538q-9xm7/GHSA-w37h-538q-9xm7.json b/advisories/unreviewed/2025/04/GHSA-w37h-538q-9xm7/GHSA-w37h-538q-9xm7.json new file mode 100644 index 00000000000..e44fa461fcf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w37h-538q-9xm7/GHSA-w37h-538q-9xm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w37h-538q-9xm7", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32206" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects allows Upload a Web Shell to a Web Server. This issue affects Processing Projects: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32206" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/processing-projects/vulnerability/wordpress-processing-projects-plugin-1-0-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-whp3-jch4-j52c/GHSA-whp3-jch4-j52c.json b/advisories/unreviewed/2025/04/GHSA-whp3-jch4-j52c/GHSA-whp3-jch4-j52c.json new file mode 100644 index 00000000000..8b79140d42e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-whp3-jch4-j52c/GHSA-whp3-jch4-j52c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whp3-jch4-j52c", + "modified": "2025-04-10T09:30:25Z", + "published": "2025-04-10T09:30:25Z", + "aliases": [ + "CVE-2025-32210" + ], + "details": "Missing Authorization vulnerability in CreativeMindsSolutions CM Registration and Invitation Codes allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CM Registration and Invitation Codes: from n/a through 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32210" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cm-invitation-codes/vulnerability/wordpress-cm-registration-and-invitation-codes-plugin-2-5-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x8w8-g4xf-jwpw/GHSA-x8w8-g4xf-jwpw.json b/advisories/unreviewed/2025/04/GHSA-x8w8-g4xf-jwpw/GHSA-x8w8-g4xf-jwpw.json new file mode 100644 index 00000000000..5201ffba6c2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x8w8-g4xf-jwpw/GHSA-x8w8-g4xf-jwpw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8w8-g4xf-jwpw", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:24Z", + "aliases": [ + "CVE-2025-30582" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aytechnet DyaPress ERP/CRM allows PHP Local File Inclusion. This issue affects DyaPress ERP/CRM: from n/a through 18.0.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30582" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dyapress/vulnerability/wordpress-dyapress-erp-crm-18-0-2-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xwxx-v4g2-q5p4/GHSA-xwxx-v4g2-q5p4.json b/advisories/unreviewed/2025/04/GHSA-xwxx-v4g2-q5p4/GHSA-xwxx-v4g2-q5p4.json new file mode 100644 index 00000000000..4656bb88121 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xwxx-v4g2-q5p4/GHSA-xwxx-v4g2-q5p4.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwxx-v4g2-q5p4", + "modified": "2025-04-10T09:30:24Z", + "published": "2025-04-10T09:30:23Z", + "aliases": [ + "CVE-2025-2809" + ], + "details": "The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2809" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/azurecurve-shortcodes-in-comments/trunk/azurecurve-shortcodes-in-comments.php#L35" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/azurecurve-shortcodes-in-comments/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/22cc6da1-fd22-4b2a-90ab-24086879f0f6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T07:15:41Z" + } +} \ No newline at end of file