diff --git a/advisories/unreviewed/2025/01/GHSA-2293-ph8w-45mf/GHSA-2293-ph8w-45mf.json b/advisories/unreviewed/2025/01/GHSA-2293-ph8w-45mf/GHSA-2293-ph8w-45mf.json new file mode 100644 index 00000000000..0850a6fecba --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2293-ph8w-45mf/GHSA-2293-ph8w-45mf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2293-ph8w-45mf", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56250" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GregRoss Just Writing Statistics allows SQL Injection.This issue affects Just Writing Statistics: from n/a through 4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56250" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/just-writing-statistics/vulnerability/wordpress-just-writing-statistics-plugin-4-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-22r9-5j98-76h8/GHSA-22r9-5j98-76h8.json b/advisories/unreviewed/2025/01/GHSA-22r9-5j98-76h8/GHSA-22r9-5j98-76h8.json new file mode 100644 index 00000000000..a86bdbc6c6e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-22r9-5j98-76h8/GHSA-22r9-5j98-76h8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22r9-5j98-76h8", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2023-47693" + ], + "details": "Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through 3.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47693" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-addons-for-contact-form-7/vulnerability/wordpress-ultimate-addons-for-contact-form-7-plugin-3-2-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-23vc-r48x-wwpp/GHSA-23vc-r48x-wwpp.json b/advisories/unreviewed/2025/01/GHSA-23vc-r48x-wwpp/GHSA-23vc-r48x-wwpp.json new file mode 100644 index 00000000000..e0b005fab51 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-23vc-r48x-wwpp/GHSA-23vc-r48x-wwpp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23vc-r48x-wwpp", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-45828" + ], + "details": "Missing Authorization vulnerability in RumbleTalk Ltd RumbleTalk Live Group Chat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RumbleTalk Live Group Chat: from n/a through 6.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45828" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rumbletalk-chat-a-chat-with-themes/vulnerability/wordpress-rumbletalk-live-group-chat-plugin-6-1-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2885-vc9p-8279/GHSA-2885-vc9p-8279.json b/advisories/unreviewed/2025/01/GHSA-2885-vc9p-8279/GHSA-2885-vc9p-8279.json new file mode 100644 index 00000000000..545816b937a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2885-vc9p-8279/GHSA-2885-vc9p-8279.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2885-vc9p-8279", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56251" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Event Espresso Event Espresso 4 Decaf allows Cross Site Request Forgery.This issue affects Event Espresso 4 Decaf: from n/a through 5.0.28.decaf.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56251" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/event-espresso-decaf/vulnerability/wordpress-event-espresso-plugin-5-0-28-decaf-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2gfq-j83r-h8jp/GHSA-2gfq-j83r-h8jp.json b/advisories/unreviewed/2025/01/GHSA-2gfq-j83r-h8jp/GHSA-2gfq-j83r-h8jp.json new file mode 100644 index 00000000000..a9482ae8290 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2gfq-j83r-h8jp/GHSA-2gfq-j83r-h8jp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gfq-j83r-h8jp", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-37518" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar The Events Calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n/a through 6.5.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37518" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-events-calendar/vulnerability/wordpress-the-events-calendar-plugin-6-5-1-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2h9c-gjwm-vfqx/GHSA-2h9c-gjwm-vfqx.json b/advisories/unreviewed/2025/01/GHSA-2h9c-gjwm-vfqx/GHSA-2h9c-gjwm-vfqx.json new file mode 100644 index 00000000000..cfefc1cb29e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2h9c-gjwm-vfqx/GHSA-2h9c-gjwm-vfqx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h9c-gjwm-vfqx", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-37937" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Rara Business allows Cross Site Request Forgery.This issue affects Rara Business: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37937" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/rara-business/vulnerability/wordpress-rara-business-theme-1-2-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2hj6-wmqq-6j5w/GHSA-2hj6-wmqq-6j5w.json b/advisories/unreviewed/2025/01/GHSA-2hj6-wmqq-6j5w/GHSA-2hj6-wmqq-6j5w.json new file mode 100644 index 00000000000..b7d965611e4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2hj6-wmqq-6j5w/GHSA-2hj6-wmqq-6j5w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hj6-wmqq-6j5w", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37490" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Royal Bard allows Cross Site Request Forgery.This issue affects Bard: from n/a through 2.210.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37490" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/bard/vulnerability/wordpress-bard-theme-2-210-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2m8g-rm4r-cx87/GHSA-2m8g-rm4r-cx87.json b/advisories/unreviewed/2025/01/GHSA-2m8g-rm4r-cx87/GHSA-2m8g-rm4r-cx87.json new file mode 100644 index 00000000000..de54bc67a37 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2m8g-rm4r-cx87/GHSA-2m8g-rm4r-cx87.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m8g-rm4r-cx87", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37242" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Automattic Newspack Newsletters allows Cross Site Request Forgery.This issue affects Newspack Newsletters: from n/a through 2.13.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37242" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/newspack-newsletters/vulnerability/wordpress-newspack-newsletters-plugin-2-13-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2p7v-6q2g-9wg5/GHSA-2p7v-6q2g-9wg5.json b/advisories/unreviewed/2025/01/GHSA-2p7v-6q2g-9wg5/GHSA-2p7v-6q2g-9wg5.json new file mode 100644 index 00000000000..08f4145b13c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2p7v-6q2g-9wg5/GHSA-2p7v-6q2g-9wg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p7v-6q2g-9wg5", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2023-47689" + ], + "details": "Missing Authorization vulnerability in Toast Plugins Animator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animator: from n/a through 3.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47689" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/scroll-triggered-animations/vulnerability/wordpress-animator-plugin-3-0-9-unauthenticated-plugin-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2vwv-6pp4-pj25/GHSA-2vwv-6pp4-pj25.json b/advisories/unreviewed/2025/01/GHSA-2vwv-6pp4-pj25/GHSA-2vwv-6pp4-pj25.json new file mode 100644 index 00000000000..7e3baf424f7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2vwv-6pp4-pj25/GHSA-2vwv-6pp4-pj25.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vwv-6pp4-pj25", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37426" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Elegant Pink allows Cross Site Request Forgery.This issue affects Elegant Pink: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37426" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/elegant-pink/vulnerability/wordpress-elegant-pink-theme-1-3-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2xv6-2j79-ghqr/GHSA-2xv6-2j79-ghqr.json b/advisories/unreviewed/2025/01/GHSA-2xv6-2j79-ghqr/GHSA-2xv6-2j79-ghqr.json new file mode 100644 index 00000000000..65c7291c97a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2xv6-2j79-ghqr/GHSA-2xv6-2j79-ghqr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xv6-2j79-ghqr", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56253" + ], + "details": "Missing Authorization vulnerability in supsystic.com Data Tables Generator by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.36.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56253" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/data-tables-generator-by-supsystic/vulnerability/wordpress-data-tables-generator-by-supsystic-plugin-1-10-36-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-324x-q2r5-4mrm/GHSA-324x-q2r5-4mrm.json b/advisories/unreviewed/2025/01/GHSA-324x-q2r5-4mrm/GHSA-324x-q2r5-4mrm.json new file mode 100644 index 00000000000..03631fc07e3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-324x-q2r5-4mrm/GHSA-324x-q2r5-4mrm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-324x-q2r5-4mrm", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-38691" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Metorik Metorik – Reports & Email Automation for WooCommerce allows Cross Site Request Forgery.This issue affects Metorik – Reports & Email Automation for WooCommerce: from n/a through 1.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38691" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/metorik-helper/vulnerability/wordpress-metorik-plugin-1-7-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-33hq-v9c2-967m/GHSA-33hq-v9c2-967m.json b/advisories/unreviewed/2025/01/GHSA-33hq-v9c2-967m/GHSA-33hq-v9c2-967m.json new file mode 100644 index 00000000000..25a341f5929 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-33hq-v9c2-967m/GHSA-33hq-v9c2-967m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33hq-v9c2-967m", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-37508" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Construction Landing Page allows Cross Site Request Forgery.This issue affects Construction Landing Page: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37508" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/construction-landing-page/vulnerability/wordpress-construction-landing-page-theme-1-3-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-35r5-j2wv-ff34/GHSA-35r5-j2wv-ff34.json b/advisories/unreviewed/2025/01/GHSA-35r5-j2wv-ff34/GHSA-35r5-j2wv-ff34.json new file mode 100644 index 00000000000..aaf9cc8a2bf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-35r5-j2wv-ff34/GHSA-35r5-j2wv-ff34.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35r5-j2wv-ff34", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46610" + ], + "details": "Missing Authorization vulnerability in quillforms.com Quill Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quill Forms: from n/a through 3.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46610" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quillforms/vulnerability/wordpress-quill-forms-plugin-3-3-0-broken-access-control-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-398x-j3p9-ffhp/GHSA-398x-j3p9-ffhp.json b/advisories/unreviewed/2025/01/GHSA-398x-j3p9-ffhp/GHSA-398x-j3p9-ffhp.json new file mode 100644 index 00000000000..db9f29882a7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-398x-j3p9-ffhp/GHSA-398x-j3p9-ffhp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-398x-j3p9-ffhp", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2023-44258" + ], + "details": "Missing Authorization vulnerability in Schema App Schema App Structured Data allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schema App Structured Data: from n/a through 1.23.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44258" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/schema-app-structured-data-for-schemaorg/vulnerability/wordpress-schema-app-structured-data-plugin-1-22-3-csrf-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3ffq-9w3m-8f4c/GHSA-3ffq-9w3m-8f4c.json b/advisories/unreviewed/2025/01/GHSA-3ffq-9w3m-8f4c/GHSA-3ffq-9w3m-8f4c.json new file mode 100644 index 00000000000..23d17ecdf9c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3ffq-9w3m-8f4c/GHSA-3ffq-9w3m-8f4c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3ffq-9w3m-8f4c", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46631" + ], + "details": "Missing Authorization vulnerability in RevenueHunt Product Recommendation Quiz for eCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Recommendation Quiz for eCommerce: from n/a through 2.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46631" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/product-recommendation-quiz-for-ecommerce/vulnerability/wordpress-product-recommendation-quiz-for-ecommerce-plugin-2-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3px9-vgqj-48v9/GHSA-3px9-vgqj-48v9.json b/advisories/unreviewed/2025/01/GHSA-3px9-vgqj-48v9/GHSA-3px9-vgqj-48v9.json new file mode 100644 index 00000000000..03ae3094a1b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3px9-vgqj-48v9/GHSA-3px9-vgqj-48v9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3px9-vgqj-48v9", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-45104" + ], + "details": "Missing Authorization vulnerability in WPDeveloper BetterLinks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterLinks: from n/a through 1.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45104" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/betterlinks/vulnerability/wordpress-betterlinks-plugin-1-6-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4359-xfqv-8jjj/GHSA-4359-xfqv-8jjj.json b/advisories/unreviewed/2025/01/GHSA-4359-xfqv-8jjj/GHSA-4359-xfqv-8jjj.json new file mode 100644 index 00000000000..7fc8300b01b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4359-xfqv-8jjj/GHSA-4359-xfqv-8jjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4359-xfqv-8jjj", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37413" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Preschool and Kindergarten allows Cross Site Request Forgery.This issue affects Preschool and Kindergarten: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37413" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/preschool-and-kindergarten/vulnerability/wordpress-preschool-and-kindergarten-theme-1-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-43fh-63xp-xhfw/GHSA-43fh-63xp-xhfw.json b/advisories/unreviewed/2025/01/GHSA-43fh-63xp-xhfw/GHSA-43fh-63xp-xhfw.json new file mode 100644 index 00000000000..5c49551bef1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-43fh-63xp-xhfw/GHSA-43fh-63xp-xhfw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43fh-63xp-xhfw", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2023-47692" + ], + "details": "Missing Authorization vulnerability in Flothemes Flo Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flo Forms: from n/a through 1.0.41.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47692" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flo-forms/vulnerability/wordpress-flo-forms-plugin-1-0-41-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-44p5-527f-xg43/GHSA-44p5-527f-xg43.json b/advisories/unreviewed/2025/01/GHSA-44p5-527f-xg43/GHSA-44p5-527f-xg43.json new file mode 100644 index 00000000000..adae91c4286 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-44p5-527f-xg43/GHSA-44p5-527f-xg43.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44p5-527f-xg43", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46195" + ], + "details": "Missing Authorization vulnerability in CoSchedule Headline Analyzer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Headline Analyzer: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46195" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/headline-analyzer/vulnerability/wordpress-headline-analyzer-plugin-1-3-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-45xc-4wjq-9987/GHSA-45xc-4wjq-9987.json b/advisories/unreviewed/2025/01/GHSA-45xc-4wjq-9987/GHSA-45xc-4wjq-9987.json new file mode 100644 index 00000000000..a204cdb5a8f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-45xc-4wjq-9987/GHSA-45xc-4wjq-9987.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45xc-4wjq-9987", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2024-56037" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md Maruf Adnan Sami User Referral allows Reflected XSS.This issue affects User Referral: from n/a through 8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56037" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/user-referral-free/vulnerability/wordpress-user-referral-plugin-8-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4777-367v-cc98/GHSA-4777-367v-cc98.json b/advisories/unreviewed/2025/01/GHSA-4777-367v-cc98/GHSA-4777-367v-cc98.json new file mode 100644 index 00000000000..86b0e186dbd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4777-367v-cc98/GHSA-4777-367v-cc98.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4777-367v-cc98", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37240" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Faboba Falang multilanguage allows Cross Site Request Forgery.This issue affects Falang multilanguage: from n/a through 1.3.51.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37240" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/falang/vulnerability/wordpress-falang-multilanguage-for-wordpress-plugin-1-3-51-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4979-4xqf-m5vx/GHSA-4979-4xqf-m5vx.json b/advisories/unreviewed/2025/01/GHSA-4979-4xqf-m5vx/GHSA-4979-4xqf-m5vx.json new file mode 100644 index 00000000000..b565fe0be35 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4979-4xqf-m5vx/GHSA-4979-4xqf-m5vx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4979-4xqf-m5vx", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46611" + ], + "details": "Authentication Bypass by Primary Weakness vulnerability in yourownprogrammer YOP Poll allows Authentication Bypass.This issue affects YOP Poll: from n/a through 6.5.28.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46611" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/yop-poll/vulnerability/wordpress-yop-poll-plugin-6-5-28-vote-manipulation-due-to-broken-captcha-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-305" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4gm4-x57g-4vgj/GHSA-4gm4-x57g-4vgj.json b/advisories/unreviewed/2025/01/GHSA-4gm4-x57g-4vgj/GHSA-4gm4-x57g-4vgj.json new file mode 100644 index 00000000000..5265d099b8f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4gm4-x57g-4vgj/GHSA-4gm4-x57g-4vgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gm4-x57g-4vgj", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46608" + ], + "details": "Missing Authorization vulnerability in WPDO DoLogin Security allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DoLogin Security: from n/a through 3.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46608" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dologin/vulnerability/wordpress-dologin-security-plugin-3-7-1-multiple-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4gvq-p6q2-68qv/GHSA-4gvq-p6q2-68qv.json b/advisories/unreviewed/2025/01/GHSA-4gvq-p6q2-68qv/GHSA-4gvq-p6q2-68qv.json new file mode 100644 index 00000000000..a601f4dac76 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4gvq-p6q2-68qv/GHSA-4gvq-p6q2-68qv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gvq-p6q2-68qv", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2023-47187" + ], + "details": "Missing Authorization vulnerability in Labib Ahmed Animated Rotating Words allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animated Rotating Words: from n/a through 5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47187" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/css3-rotating-words/vulnerability/wordpress-animated-rotating-words-plugin-5-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4h5w-rfr3-39rp/GHSA-4h5w-rfr3-39rp.json b/advisories/unreviewed/2025/01/GHSA-4h5w-rfr3-39rp/GHSA-4h5w-rfr3-39rp.json new file mode 100644 index 00000000000..676d83495ce --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4h5w-rfr3-39rp/GHSA-4h5w-rfr3-39rp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h5w-rfr3-39rp", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46309" + ], + "details": "Missing Authorization vulnerability in gVectors Team wpDiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through 7.6.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46309" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpdiscuz/vulnerability/wordpress-wpdiscuz-plugin-7-6-10-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4v65-5rwc-6vwm/GHSA-4v65-5rwc-6vwm.json b/advisories/unreviewed/2025/01/GHSA-4v65-5rwc-6vwm/GHSA-4v65-5rwc-6vwm.json new file mode 100644 index 00000000000..9abdc298a0a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4v65-5rwc-6vwm/GHSA-4v65-5rwc-6vwm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v65-5rwc-6vwm", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37467" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThemeIsle Hestia allows Cross Site Request Forgery.This issue affects Hestia: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37467" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/hestia/vulnerability/wordpress-hestia-theme-3-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4w59-pwp7-whwv/GHSA-4w59-pwp7-whwv.json b/advisories/unreviewed/2025/01/GHSA-4w59-pwp7-whwv/GHSA-4w59-pwp7-whwv.json new file mode 100644 index 00000000000..660ea836b2a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4w59-pwp7-whwv/GHSA-4w59-pwp7-whwv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w59-pwp7-whwv", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-37511" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in SWTE Swift Performance Lite allows Cross Site Request Forgery.This issue affects Swift Performance Lite: from n/a through 2.3.6.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37511" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/swift-performance-lite/vulnerability/wordpress-swift-performance-lite-plugin-2-3-6-20-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4wmw-j845-2p25/GHSA-4wmw-j845-2p25.json b/advisories/unreviewed/2025/01/GHSA-4wmw-j845-2p25/GHSA-4wmw-j845-2p25.json new file mode 100644 index 00000000000..46db56a05d6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4wmw-j845-2p25/GHSA-4wmw-j845-2p25.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wmw-j845-2p25", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-38751" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Magazine3 Google Adsense & Banner Ads by AdsforWP allows Cross Site Request Forgery.This issue affects Google Adsense & Banner Ads by AdsforWP: from n/a through 1.9.28.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38751" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ads-for-wp/vulnerability/wordpress-adsforwp-plugin-1-9-28-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4xf5-7w4v-4xjr/GHSA-4xf5-7w4v-4xjr.json b/advisories/unreviewed/2025/01/GHSA-4xf5-7w4v-4xjr/GHSA-4xf5-7w4v-4xjr.json new file mode 100644 index 00000000000..ecd1586e56e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4xf5-7w4v-4xjr/GHSA-4xf5-7w4v-4xjr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xf5-7w4v-4xjr", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2024-13104" + ], + "details": "A vulnerability, which was classified as critical, was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. Affected is an unknown function of the file /goform/form2AdvanceSetup.cgi of the component WiFi Settings Handler. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13104" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Unauthorized_Vulnerability/D-Link/DIR-816/form2AdvanceSetup.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289920" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289920" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.472076" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T11:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-52j9-24vf-xr95/GHSA-52j9-24vf-xr95.json b/advisories/unreviewed/2025/01/GHSA-52j9-24vf-xr95/GHSA-52j9-24vf-xr95.json new file mode 100644 index 00000000000..20484589836 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-52j9-24vf-xr95/GHSA-52j9-24vf-xr95.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52j9-24vf-xr95", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56240" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pronamic Pronamic Google Maps allows Stored XSS.This issue affects Pronamic Google Maps: from n/a through 2.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56240" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pronamic-google-maps/vulnerability/wordpress-pronamic-google-maps-plugin-2-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-53gx-j362-742j/GHSA-53gx-j362-742j.json b/advisories/unreviewed/2025/01/GHSA-53gx-j362-742j/GHSA-53gx-j362-742j.json new file mode 100644 index 00000000000..fbea5806d18 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-53gx-j362-742j/GHSA-53gx-j362-742j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53gx-j362-742j", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56018" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boston University (IS&T) BU Section Editing allows Reflected XSS.This issue affects BU Section Editing: from n/a through 0.9.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56018" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bu-section-editing/vulnerability/wordpress-bu-section-editing-plugin-0-9-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5883-gq8w-cq5m/GHSA-5883-gq8w-cq5m.json b/advisories/unreviewed/2025/01/GHSA-5883-gq8w-cq5m/GHSA-5883-gq8w-cq5m.json new file mode 100644 index 00000000000..08e0f130239 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5883-gq8w-cq5m/GHSA-5883-gq8w-cq5m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5883-gq8w-cq5m", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56258" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBlockArt Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56258" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/magazine-blocks/vulnerability/wordpress-magazine-blocks-plugin-1-3-20-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5fww-f5vv-rrm9/GHSA-5fww-f5vv-rrm9.json b/advisories/unreviewed/2025/01/GHSA-5fww-f5vv-rrm9/GHSA-5fww-f5vv-rrm9.json new file mode 100644 index 00000000000..577b2144630 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5fww-f5vv-rrm9/GHSA-5fww-f5vv-rrm9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fww-f5vv-rrm9", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37469" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy allows Cross Site Request Forgery.This issue affects Blocksy: from n/a through 2.0.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37469" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/blocksy/vulnerability/wordpress-blocksy-theme-1-9-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5g8m-6vgv-qm45/GHSA-5g8m-6vgv-qm45.json b/advisories/unreviewed/2025/01/GHSA-5g8m-6vgv-qm45/GHSA-5g8m-6vgv-qm45.json new file mode 100644 index 00000000000..6a18966eb84 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5g8m-6vgv-qm45/GHSA-5g8m-6vgv-qm45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g8m-6vgv-qm45", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-45649" + ], + "details": "Missing Authorization vulnerability in CodePeople Appointment Hour Booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Appointment Hour Booking: from n/a through 1.4.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45649" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/appointment-hour-booking/vulnerability/wordpress-appointment-hour-booking-plugin-1-4-23-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5hmg-r352-55hf/GHSA-5hmg-r352-55hf.json b/advisories/unreviewed/2025/01/GHSA-5hmg-r352-55hf/GHSA-5hmg-r352-55hf.json new file mode 100644 index 00000000000..43a3d75c303 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5hmg-r352-55hf/GHSA-5hmg-r352-55hf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hmg-r352-55hf", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56252" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeLooks Enter Addons allows Stored XSS.This issue affects Enter Addons: from n/a through 2.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56252" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/enteraddons/vulnerability/wordpress-enter-addons-plugin-2-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5rp3-cgm7-4447/GHSA-5rp3-cgm7-4447.json b/advisories/unreviewed/2025/01/GHSA-5rp3-cgm7-4447/GHSA-5rp3-cgm7-4447.json new file mode 100644 index 00000000000..35e7a03f74b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5rp3-cgm7-4447/GHSA-5rp3-cgm7-4447.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rp3-cgm7-4447", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56026" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Priday Simple Proxy allows Reflected XSS.This issue affects Simple Proxy: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56026" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-proxy/vulnerability/wordpress-simple-proxy-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5w7q-6wwr-8pjp/GHSA-5w7q-6wwr-8pjp.json b/advisories/unreviewed/2025/01/GHSA-5w7q-6wwr-8pjp/GHSA-5w7q-6wwr-8pjp.json new file mode 100644 index 00000000000..8613bad39b0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5w7q-6wwr-8pjp/GHSA-5w7q-6wwr-8pjp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w7q-6wwr-8pjp", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-47183" + ], + "details": "Missing Authorization vulnerability in GiveWP GiveWP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through 2.33.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47183" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-2-33-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5wf9-7h86-fgr8/GHSA-5wf9-7h86-fgr8.json b/advisories/unreviewed/2025/01/GHSA-5wf9-7h86-fgr8/GHSA-5wf9-7h86-fgr8.json new file mode 100644 index 00000000000..27fff5f1dc6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5wf9-7h86-fgr8/GHSA-5wf9-7h86-fgr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wf9-7h86-fgr8", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2024-56060" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HTML Forms allows Reflected XSS.This issue affects HTML Forms: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56060" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/html-forms/vulnerability/wordpress-html-forms-plugin-1-4-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5xf4-4w8r-m546/GHSA-5xf4-4w8r-m546.json b/advisories/unreviewed/2025/01/GHSA-5xf4-4w8r-m546/GHSA-5xf4-4w8r-m546.json new file mode 100644 index 00000000000..0d73249d616 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5xf4-4w8r-m546/GHSA-5xf4-4w8r-m546.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xf4-4w8r-m546", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37235" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Groundhogg Inc. Groundhogg allows Cross Site Request Forgery.This issue affects Groundhogg: from n/a through 3.4.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37235" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/groundhogg/vulnerability/wordpress-groundhogg-plugin-3-4-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-639h-j5qr-w5v4/GHSA-639h-j5qr-w5v4.json b/advisories/unreviewed/2025/01/GHSA-639h-j5qr-w5v4/GHSA-639h-j5qr-w5v4.json new file mode 100644 index 00000000000..2422ae7222a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-639h-j5qr-w5v4/GHSA-639h-j5qr-w5v4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-639h-j5qr-w5v4", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37412" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Blossom Shop allows Cross Site Request Forgery.This issue affects Blossom Shop: from n/a through 1.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37412" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/blossom-shop/vulnerability/wordpress-blossom-shop-theme-1-1-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6m4x-qvp7-crf7/GHSA-6m4x-qvp7-crf7.json b/advisories/unreviewed/2025/01/GHSA-6m4x-qvp7-crf7/GHSA-6m4x-qvp7-crf7.json new file mode 100644 index 00000000000..608bb106c8b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6m4x-qvp7-crf7/GHSA-6m4x-qvp7-crf7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m4x-qvp7-crf7", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37435" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Perfect Portfolio allows Cross Site Request Forgery.This issue affects Perfect Portfolio: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37435" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/perfect-portfolio/vulnerability/wordpress-perfect-portfolio-theme-1-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6mjj-949w-m965/GHSA-6mjj-949w-m965.json b/advisories/unreviewed/2025/01/GHSA-6mjj-949w-m965/GHSA-6mjj-949w-m965.json new file mode 100644 index 00000000000..c3bcf528288 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6mjj-949w-m965/GHSA-6mjj-949w-m965.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mjj-949w-m965", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-45765" + ], + "details": "Missing Authorization vulnerability in weDevs WP ERP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through 1.12.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45765" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/erp/vulnerability/wordpress-wp-erp-plugin-1-12-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6rrq-cw26-cgx2/GHSA-6rrq-cw26-cgx2.json b/advisories/unreviewed/2025/01/GHSA-6rrq-cw26-cgx2/GHSA-6rrq-cw26-cgx2.json new file mode 100644 index 00000000000..41a5b470c8e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6rrq-cw26-cgx2/GHSA-6rrq-cw26-cgx2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rrq-cw26-cgx2", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-45271" + ], + "details": "Missing Authorization vulnerability in WowStore Team ProductX – Gutenberg WooCommerce Blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProductX – Gutenberg WooCommerce Blocks: from n/a through 2.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45271" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/product-blocks/vulnerability/wordpress-productx-gutenberg-woocommerce-blocks-plugin-2-7-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6w2w-p826-q9g6/GHSA-6w2w-p826-q9g6.json b/advisories/unreviewed/2025/01/GHSA-6w2w-p826-q9g6/GHSA-6w2w-p826-q9g6.json new file mode 100644 index 00000000000..029406f2678 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6w2w-p826-q9g6/GHSA-6w2w-p826-q9g6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w2w-p826-q9g6", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-38729" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in MBE Worldwide S.p.A. MBE eShip allows Cross Site Request Forgery.This issue affects MBE eShip: from n/a through 2.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38729" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mail-boxes-etc/vulnerability/wordpress-mbe-eship-plugin-2-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7cw5-pc98-mp64/GHSA-7cw5-pc98-mp64.json b/advisories/unreviewed/2025/01/GHSA-7cw5-pc98-mp64/GHSA-7cw5-pc98-mp64.json new file mode 100644 index 00000000000..5083bc918fe --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7cw5-pc98-mp64/GHSA-7cw5-pc98-mp64.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cw5-pc98-mp64", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56237" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contest Gallery Contest Gallery allows Stored XSS.This issue affects Contest Gallery: from n/a through 24.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56237" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contest-gallery/vulnerability/wordpress-contest-gallery-plugin-24-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7grv-gxhv-f4pm/GHSA-7grv-gxhv-f4pm.json b/advisories/unreviewed/2025/01/GHSA-7grv-gxhv-f4pm/GHSA-7grv-gxhv-f4pm.json new file mode 100644 index 00000000000..7ab54873a5f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7grv-gxhv-f4pm/GHSA-7grv-gxhv-f4pm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7grv-gxhv-f4pm", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2023-45002" + ], + "details": "Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through 3.6.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45002" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-user-frontend/vulnerability/wordpress-wp-user-frontend-plugin-3-6-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7p95-mcq4-234w/GHSA-7p95-mcq4-234w.json b/advisories/unreviewed/2025/01/GHSA-7p95-mcq4-234w/GHSA-7p95-mcq4-234w.json new file mode 100644 index 00000000000..36535bea912 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7p95-mcq4-234w/GHSA-7p95-mcq4-234w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p95-mcq4-234w", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2023-47648" + ], + "details": "Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through 2.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47648" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eazydocs/vulnerability/wordpress-eazydocs-plugin-2-3-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7qm9-jrj9-97qm/GHSA-7qm9-jrj9-97qm.json b/advisories/unreviewed/2025/01/GHSA-7qm9-jrj9-97qm/GHSA-7qm9-jrj9-97qm.json new file mode 100644 index 00000000000..b8e803e4b61 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7qm9-jrj9-97qm/GHSA-7qm9-jrj9-97qm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qm9-jrj9-97qm", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37421" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme JobScout allows Cross Site Request Forgery.This issue affects JobScout: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37421" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/jobscout/vulnerability/wordpress-jobscout-theme-1-1-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7wfp-728m-cc5p/GHSA-7wfp-728m-cc5p.json b/advisories/unreviewed/2025/01/GHSA-7wfp-728m-cc5p/GHSA-7wfp-728m-cc5p.json new file mode 100644 index 00000000000..97a94ce3c05 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7wfp-728m-cc5p/GHSA-7wfp-728m-cc5p.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wfp-728m-cc5p", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2024-13105" + ], + "details": "A vulnerability has been found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/form2Dhcpd.cgi of the component DHCPD Setting Handler. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13105" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Unauthorized_Vulnerability/D-Link/DIR-816/form2Dhcpd.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289921" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289921" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.472085" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7wvc-68qr-wgqx/GHSA-7wvc-68qr-wgqx.json b/advisories/unreviewed/2025/01/GHSA-7wvc-68qr-wgqx/GHSA-7wvc-68qr-wgqx.json new file mode 100644 index 00000000000..e8160717e98 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7wvc-68qr-wgqx/GHSA-7wvc-68qr-wgqx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wvc-68qr-wgqx", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-45631" + ], + "details": "Missing Authorization vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45631" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gallery-album/vulnerability/wordpress-gallery-image-and-video-gallery-with-thumbnails-plugin-2-0-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7xj3-8m97-m2jr/GHSA-7xj3-8m97-m2jr.json b/advisories/unreviewed/2025/01/GHSA-7xj3-8m97-m2jr/GHSA-7xj3-8m97-m2jr.json new file mode 100644 index 00000000000..c678e325f4f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7xj3-8m97-m2jr/GHSA-7xj3-8m97-m2jr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xj3-8m97-m2jr", + "modified": "2025-01-02T12:32:11Z", + "published": "2025-01-02T12:32:11Z", + "aliases": [ + "CVE-2024-13103" + ], + "details": "A vulnerability, which was classified as critical, has been found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. This issue affects some unknown processing of the file /goform/form2AddVrtsrv.cgi of the component Virtual Service Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13103" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Unauthorized_Vulnerability/D-Link/DIR-816/form2AddVrtsrv.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289919" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289919" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.472075" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-82g4-fhxw-v87v/GHSA-82g4-fhxw-v87v.json b/advisories/unreviewed/2025/01/GHSA-82g4-fhxw-v87v/GHSA-82g4-fhxw-v87v.json new file mode 100644 index 00000000000..7e2d2a331c9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-82g4-fhxw-v87v/GHSA-82g4-fhxw-v87v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82g4-fhxw-v87v", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-43927" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Till Krüss Email Address Encoder allows Cross Site Request Forgery.This issue affects Email Address Encoder: from n/a through 1.0.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43927" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/email-address-encoder/vulnerability/wordpress-email-address-encoder-plugin-1-0-23-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-84j8-p46v-9j5j/GHSA-84j8-p46v-9j5j.json b/advisories/unreviewed/2025/01/GHSA-84j8-p46v-9j5j/GHSA-84j8-p46v-9j5j.json new file mode 100644 index 00000000000..34bd5aa3916 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-84j8-p46v-9j5j/GHSA-84j8-p46v-9j5j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84j8-p46v-9j5j", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37272" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Travel Engine Travel Monster allows Cross Site Request Forgery.This issue affects Travel Monster: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37272" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/travel-monster/vulnerability/wordpress-travel-monster-theme-1-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8587-wh6h-pm78/GHSA-8587-wh6h-pm78.json b/advisories/unreviewed/2025/01/GHSA-8587-wh6h-pm78/GHSA-8587-wh6h-pm78.json new file mode 100644 index 00000000000..4db8db6741f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8587-wh6h-pm78/GHSA-8587-wh6h-pm78.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8587-wh6h-pm78", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56022" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress Monsters Preloader by WordPress Monsters allows Reflected XSS.This issue affects Preloader by WordPress Monsters: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56022" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/preloader-sws/vulnerability/wordpress-preloader-by-wordpress-monsters-plugin-1-2-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-86fm-wq4c-m3q9/GHSA-86fm-wq4c-m3q9.json b/advisories/unreviewed/2025/01/GHSA-86fm-wq4c-m3q9/GHSA-86fm-wq4c-m3q9.json new file mode 100644 index 00000000000..7e074b0313e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-86fm-wq4c-m3q9/GHSA-86fm-wq4c-m3q9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86fm-wq4c-m3q9", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2023-44988" + ], + "details": "Missing Authorization vulnerability in Martin Gibson WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.32.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44988" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-custom-admin-interface/vulnerability/wordpress-wp-custom-admin-interface-plugin-7-32-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-87px-jvx5-xhv4/GHSA-87px-jvx5-xhv4.json b/advisories/unreviewed/2025/01/GHSA-87px-jvx5-xhv4/GHSA-87px-jvx5-xhv4.json new file mode 100644 index 00000000000..75a5589a829 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-87px-jvx5-xhv4/GHSA-87px-jvx5-xhv4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87px-jvx5-xhv4", + "modified": "2025-01-02T12:32:11Z", + "published": "2025-01-02T12:32:11Z", + "aliases": [ + "CVE-2024-56029" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dreamwinner Easy Language Switcher allows Reflected XSS.This issue affects Easy Language Switcher: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56029" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-language-switcher/vulnerability/wordpress-easy-language-switcher-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8h26-c5c4-6x9m/GHSA-8h26-c5c4-6x9m.json b/advisories/unreviewed/2025/01/GHSA-8h26-c5c4-6x9m/GHSA-8h26-c5c4-6x9m.json new file mode 100644 index 00000000000..06498b850d7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8h26-c5c4-6x9m/GHSA-8h26-c5c4-6x9m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h26-c5c4-6x9m", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56249" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Webdeclic WPMasterToolKit allows Upload a Web Shell to a Web Server.This issue affects WPMasterToolKit: from n/a through 1.13.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56249" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpmastertoolkit/vulnerability/wordpress-wpmastertoolkit-plugin-1-13-1-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8vfh-c58r-php5/GHSA-8vfh-c58r-php5.json b/advisories/unreviewed/2025/01/GHSA-8vfh-c58r-php5/GHSA-8vfh-c58r-php5.json new file mode 100644 index 00000000000..11dc0b8ebb7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8vfh-c58r-php5/GHSA-8vfh-c58r-php5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vfh-c58r-php5", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-45101" + ], + "details": "Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customer Reviews for WooCommerce: from n/a through 5.36.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45101" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/customer-reviews-woocommerce/vulnerability/wordpress-customer-reviews-for-woocommerce-plugin-5-36-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8w3w-w736-7vh3/GHSA-8w3w-w736-7vh3.json b/advisories/unreviewed/2025/01/GHSA-8w3w-w736-7vh3/GHSA-8w3w-w736-7vh3.json new file mode 100644 index 00000000000..71efbcb4a9a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8w3w-w736-7vh3/GHSA-8w3w-w736-7vh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w3w-w736-7vh3", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56266" + ], + "details": "Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56266" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mp3-music-player-by-sonaar/vulnerability/wordpress-mp3-audio-player-plugin-5-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-94gq-r8c9-7q4x/GHSA-94gq-r8c9-7q4x.json b/advisories/unreviewed/2025/01/GHSA-94gq-r8c9-7q4x/GHSA-94gq-r8c9-7q4x.json new file mode 100644 index 00000000000..c4af6a8d663 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-94gq-r8c9-7q4x/GHSA-94gq-r8c9-7q4x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94gq-r8c9-7q4x", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46644" + ], + "details": "Missing Authorization vulnerability in WP CTA PRO WordPress CTA allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress CTA: from n/a through 1.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46644" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-sticky-sidebar/vulnerability/wordpress-wordpress-cta-wordpress-call-to-action-sticky-cta-floating-buttons-floating-tab-plugin-plugin-1-5-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9562-r8v7-4w2h/GHSA-9562-r8v7-4w2h.json b/advisories/unreviewed/2025/01/GHSA-9562-r8v7-4w2h/GHSA-9562-r8v7-4w2h.json new file mode 100644 index 00000000000..b9a61a4e9d6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9562-r8v7-4w2h/GHSA-9562-r8v7-4w2h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9562-r8v7-4w2h", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56255" + ], + "details": "Missing Authorization vulnerability in AyeCode AyeCode Connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AyeCode Connect: from n/a through 1.3.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56255" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ayecode-connect/vulnerability/wordpress-ayecode-connect-plugin-1-3-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-95fr-g64r-73f6/GHSA-95fr-g64r-73f6.json b/advisories/unreviewed/2025/01/GHSA-95fr-g64r-73f6/GHSA-95fr-g64r-73f6.json new file mode 100644 index 00000000000..39d4c9b8016 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-95fr-g64r-73f6/GHSA-95fr-g64r-73f6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95fr-g64r-73f6", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2024-56038" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendSMS allows Reflected XSS.This issue affects SendSMS: from n/a through 1.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56038" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sendsms/vulnerability/wordpress-sendsms-plugin-1-2-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-95hq-vp4x-2j4g/GHSA-95hq-vp4x-2j4g.json b/advisories/unreviewed/2025/01/GHSA-95hq-vp4x-2j4g/GHSA-95hq-vp4x-2j4g.json new file mode 100644 index 00000000000..1dab8abdbb6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-95hq-vp4x-2j4g/GHSA-95hq-vp4x-2j4g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95hq-vp4x-2j4g", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56025" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AdWorkMedia.com AdWork Media EZ Content Locker allows Reflected XSS.This issue affects AdWork Media EZ Content Locker: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56025" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/adwork-media-ez-content-locker/vulnerability/wordpress-adwork-media-ez-content-locker-plugin-3-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-95mj-c6wx-v37q/GHSA-95mj-c6wx-v37q.json b/advisories/unreviewed/2025/01/GHSA-95mj-c6wx-v37q/GHSA-95mj-c6wx-v37q.json new file mode 100644 index 00000000000..4910a29463e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-95mj-c6wx-v37q/GHSA-95mj-c6wx-v37q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95mj-c6wx-v37q", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-38762" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar Event Tickets allows Cross Site Request Forgery.This issue affects Event Tickets: from n/a through 5.11.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38762" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/event-tickets/vulnerability/wordpress-event-tickets-and-registration-plugin-5-11-0-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-98qp-x5rm-r37h/GHSA-98qp-x5rm-r37h.json b/advisories/unreviewed/2025/01/GHSA-98qp-x5rm-r37h/GHSA-98qp-x5rm-r37h.json new file mode 100644 index 00000000000..627d885628d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-98qp-x5rm-r37h/GHSA-98qp-x5rm-r37h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98qp-x5rm-r37h", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2023-47523" + ], + "details": "Missing Authorization vulnerability in Ecreate Infotech Auto Tag Creator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Tag Creator: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47523" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/auto-tag-creator/vulnerability/wordpress-auto-tag-creator-plugin-1-0-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9gjc-g99x-6m58/GHSA-9gjc-g99x-6m58.json b/advisories/unreviewed/2025/01/GHSA-9gjc-g99x-6m58/GHSA-9gjc-g99x-6m58.json new file mode 100644 index 00000000000..e6fa2fb9263 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9gjc-g99x-6m58/GHSA-9gjc-g99x-6m58.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gjc-g99x-6m58", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-13107" + ], + "details": "A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been classified as critical. This affects an unknown part of the file /goform/form2LocalAclEditcfg.cgi of the component ACL Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13107" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Unauthorized_Vulnerability/D-Link/DIR-816/form2LocalAclEditcfg.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289923" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289923" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.472087" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9h73-cr42-c392/GHSA-9h73-cr42-c392.json b/advisories/unreviewed/2025/01/GHSA-9h73-cr42-c392/GHSA-9h73-cr42-c392.json new file mode 100644 index 00000000000..975e26b6187 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9h73-cr42-c392/GHSA-9h73-cr42-c392.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h73-cr42-c392", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-47225" + ], + "details": "Missing Authorization vulnerability in KaizenCoders Short URL allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Short URL: from n/a through 1.6.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47225" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shorten-url/vulnerability/wordpress-short-url-plugin-1-6-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9mxr-x9pm-x97j/GHSA-9mxr-x9pm-x97j.json b/advisories/unreviewed/2025/01/GHSA-9mxr-x9pm-x97j/GHSA-9mxr-x9pm-x97j.json new file mode 100644 index 00000000000..9b111124840 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9mxr-x9pm-x97j/GHSA-9mxr-x9pm-x97j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mxr-x9pm-x97j", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2023-47661" + ], + "details": "Missing Authorization vulnerability in Dragfy Dragfy Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dragfy Addons for Elementor: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47661" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dragfy-addons-for-elementor/vulnerability/wordpress-dragfy-addons-for-elementor-plugin-1-0-2-broken-access-control-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9qjp-447w-pcqv/GHSA-9qjp-447w-pcqv.json b/advisories/unreviewed/2025/01/GHSA-9qjp-447w-pcqv/GHSA-9qjp-447w-pcqv.json new file mode 100644 index 00000000000..dce872a42cd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9qjp-447w-pcqv/GHSA-9qjp-447w-pcqv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qjp-447w-pcqv", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46616" + ], + "details": "Missing Authorization vulnerability in NSquared Draw Attention allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Draw Attention: from n/a through 2.0.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46616" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/draw-attention/vulnerability/wordpress-draw-attention-plugin-2-0-15-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9v86-5rhj-9qqc/GHSA-9v86-5rhj-9qqc.json b/advisories/unreviewed/2025/01/GHSA-9v86-5rhj-9qqc/GHSA-9v86-5rhj-9qqc.json new file mode 100644 index 00000000000..9484bdca421 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9v86-5rhj-9qqc/GHSA-9v86-5rhj-9qqc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v86-5rhj-9qqc", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2024-56033" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 FAQs allows Reflected XSS.This issue affects FAQs: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56033" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/faqs/vulnerability/wordpress-faqs-plugin-1-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c2x9-j4mv-ggw3/GHSA-c2x9-j4mv-ggw3.json b/advisories/unreviewed/2025/01/GHSA-c2x9-j4mv-ggw3/GHSA-c2x9-j4mv-ggw3.json new file mode 100644 index 00000000000..321c533c1c1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c2x9-j4mv-ggw3/GHSA-c2x9-j4mv-ggw3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2x9-j4mv-ggw3", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2023-45045" + ], + "details": "Missing Authorization vulnerability in Kishor Khambu WP Custom Widget area allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Widget area: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45045" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-custom-widget-area/vulnerability/wordpress-wp-custom-widget-area-plugin-1-2-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c956-q3cq-8j7r/GHSA-c956-q3cq-8j7r.json b/advisories/unreviewed/2025/01/GHSA-c956-q3cq-8j7r/GHSA-c956-q3cq-8j7r.json new file mode 100644 index 00000000000..73fee83c1b3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c956-q3cq-8j7r/GHSA-c956-q3cq-8j7r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c956-q3cq-8j7r", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2023-47557" + ], + "details": "Missing Authorization vulnerability in wp-buy Visitors Traffic Real Time Statistics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visitors Traffic Real Time Statistics: from n/a through 7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47557" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/visitors-traffic-real-time-statistics/vulnerability/wordpress-visitor-traffic-real-time-statistics-plugin-7-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c96j-rghc-r336/GHSA-c96j-rghc-r336.json b/advisories/unreviewed/2025/01/GHSA-c96j-rghc-r336/GHSA-c96j-rghc-r336.json new file mode 100644 index 00000000000..8c355f15c2c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c96j-rghc-r336/GHSA-c96j-rghc-r336.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c96j-rghc-r336", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-47180" + ], + "details": "Missing Authorization vulnerability in XLPlugins Finale Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Finale Lite: from n/a through 2.16.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47180" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/finale-woocommerce-sales-countdown-timer-discount/vulnerability/wordpress-finale-lite-sales-countdown-timer-discount-for-woocommerce-plugin-2-16-0-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c9vh-2mrj-c67x/GHSA-c9vh-2mrj-c67x.json b/advisories/unreviewed/2025/01/GHSA-c9vh-2mrj-c67x/GHSA-c9vh-2mrj-c67x.json new file mode 100644 index 00000000000..7a3f941f75a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c9vh-2mrj-c67x/GHSA-c9vh-2mrj-c67x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9vh-2mrj-c67x", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56261" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins Project Showcase allows Stored XSS.This issue affects Project Showcase: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56261" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gs-projects/vulnerability/wordpress-project-showcase-plugin-1-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cm96-944j-v9h3/GHSA-cm96-944j-v9h3.json b/advisories/unreviewed/2025/01/GHSA-cm96-944j-v9h3/GHSA-cm96-944j-v9h3.json new file mode 100644 index 00000000000..f2a6b7cb423 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cm96-944j-v9h3/GHSA-cm96-944j-v9h3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm96-944j-v9h3", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37473" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in BlazeThemes Trendy News allows Cross Site Request Forgery.This issue affects Trendy News: from n/a through 1.0.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37473" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/trendy-news/vulnerability/wordpress-trendy-news-theme-1-0-15-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cqc2-q9mp-rjwq/GHSA-cqc2-q9mp-rjwq.json b/advisories/unreviewed/2025/01/GHSA-cqc2-q9mp-rjwq/GHSA-cqc2-q9mp-rjwq.json new file mode 100644 index 00000000000..e44e5634418 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cqc2-q9mp-rjwq/GHSA-cqc2-q9mp-rjwq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqc2-q9mp-rjwq", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56263" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Shots for Dribbble allows DOM-Based XSS.This issue affects GS Shots for Dribbble: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56263" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gs-dribbble-portfolio/vulnerability/wordpress-gs-shots-for-dribbble-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cxw5-mxg9-j5x2/GHSA-cxw5-mxg9-j5x2.json b/advisories/unreviewed/2025/01/GHSA-cxw5-mxg9-j5x2/GHSA-cxw5-mxg9-j5x2.json new file mode 100644 index 00000000000..43000bd22f3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cxw5-mxg9-j5x2/GHSA-cxw5-mxg9-j5x2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxw5-mxg9-j5x2", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46073" + ], + "details": "Missing Authorization vulnerability in nofearinc DX Delete Attached Media allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DX Delete Attached Media: from n/a through 2.0.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46073" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dx-delete-attached-media/vulnerability/wordpress-dx-delete-attached-media-plugin-2-0-5-1-broken-access-control-vulnerability-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f5cm-hf7h-g464/GHSA-f5cm-hf7h-g464.json b/advisories/unreviewed/2025/01/GHSA-f5cm-hf7h-g464/GHSA-f5cm-hf7h-g464.json new file mode 100644 index 00000000000..34e90259336 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f5cm-hf7h-g464/GHSA-f5cm-hf7h-g464.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5cm-hf7h-g464", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-37493" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in SKT Themes Posterity allows Cross Site Request Forgery.This issue affects Posterity: from n/a through 3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37493" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/posterity/vulnerability/wordpress-posterity-theme-3-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f624-vp68-48vm/GHSA-f624-vp68-48vm.json b/advisories/unreviewed/2025/01/GHSA-f624-vp68-48vm/GHSA-f624-vp68-48vm.json new file mode 100644 index 00000000000..40b5d5a6b2d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f624-vp68-48vm/GHSA-f624-vp68-48vm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f624-vp68-48vm", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56264" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Beee ACF City Selector allows Upload a Web Shell to a Web Server.This issue affects ACF City Selector: from n/a through 1.14.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56264" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/acf-city-selector/vulnerability/wordpress-acf-city-selector-plugin-1-14-0-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f6hv-7v3m-4pr8/GHSA-f6hv-7v3m-4pr8.json b/advisories/unreviewed/2025/01/GHSA-f6hv-7v3m-4pr8/GHSA-f6hv-7v3m-4pr8.json new file mode 100644 index 00000000000..d35641f40ba --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f6hv-7v3m-4pr8/GHSA-f6hv-7v3m-4pr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6hv-7v3m-4pr8", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56238" + ], + "details": "Missing Authorization vulnerability in QunatumCloud Floating Action Buttons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Floating Action Buttons: from n/a through 0.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56238" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/floating-action-buttons/vulnerability/wordpress-floating-action-buttons-plugin-0-9-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f7ch-wh8v-hpwj/GHSA-f7ch-wh8v-hpwj.json b/advisories/unreviewed/2025/01/GHSA-f7ch-wh8v-hpwj/GHSA-f7ch-wh8v-hpwj.json new file mode 100644 index 00000000000..071233ce8d1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f7ch-wh8v-hpwj/GHSA-f7ch-wh8v-hpwj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7ch-wh8v-hpwj", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37448" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in FameThemes OnePress allows Cross Site Request Forgery.This issue affects OnePress: from n/a through 2.3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37448" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/onepress/vulnerability/wordpress-onepress-theme-2-3-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fff3-vjhw-jr2w/GHSA-fff3-vjhw-jr2w.json b/advisories/unreviewed/2025/01/GHSA-fff3-vjhw-jr2w/GHSA-fff3-vjhw-jr2w.json new file mode 100644 index 00000000000..b18ae3adf54 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fff3-vjhw-jr2w/GHSA-fff3-vjhw-jr2w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fff3-vjhw-jr2w", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56302" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ConvertCalculator ConvertCalculator for WordPress allows Stored XSS.This issue affects ConvertCalculator for WordPress: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56302" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/convertcalculator/vulnerability/wordpress-convertcalculator-for-wordpress-plugin-1-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fpgj-7jhh-pchm/GHSA-fpgj-7jhh-pchm.json b/advisories/unreviewed/2025/01/GHSA-fpgj-7jhh-pchm/GHSA-fpgj-7jhh-pchm.json new file mode 100644 index 00000000000..16c48637704 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fpgj-7jhh-pchm/GHSA-fpgj-7jhh-pchm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpgj-7jhh-pchm", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37417" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Coachify Coachify allows Cross Site Request Forgery.This issue affects Coachify: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37417" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/coachify/vulnerability/wordpress-coachify-theme-1-0-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fvcj-q933-vff3/GHSA-fvcj-q933-vff3.json b/advisories/unreviewed/2025/01/GHSA-fvcj-q933-vff3/GHSA-fvcj-q933-vff3.json new file mode 100644 index 00000000000..a3ab00715a5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fvcj-q933-vff3/GHSA-fvcj-q933-vff3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvcj-q933-vff3", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46079" + ], + "details": "Missing Authorization vulnerability in WP Royal Ashe Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ashe Extra: from n/a through 1.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46079" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ashe-extra/vulnerability/wordpress-ashe-extra-plugin-1-2-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g446-hq84-rcq2/GHSA-g446-hq84-rcq2.json b/advisories/unreviewed/2025/01/GHSA-g446-hq84-rcq2/GHSA-g446-hq84-rcq2.json new file mode 100644 index 00000000000..9073b98acbe --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g446-hq84-rcq2/GHSA-g446-hq84-rcq2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g446-hq84-rcq2", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46605" + ], + "details": "Missing Authorization vulnerability in Ruslan Suhar Convertful – Your Ultimate On-Site Conversion Tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Convertful – Your Ultimate On-Site Conversion Tool: from n/a through 2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46605" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/convertful/vulnerability/wordpress-convertful-your-ultimate-on-site-conversion-tool-plugin-2-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g897-3wqh-xcj7/GHSA-g897-3wqh-xcj7.json b/advisories/unreviewed/2025/01/GHSA-g897-3wqh-xcj7/GHSA-g897-3wqh-xcj7.json new file mode 100644 index 00000000000..309f3770fe5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g897-3wqh-xcj7/GHSA-g897-3wqh-xcj7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g897-3wqh-xcj7", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-38766" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Matomo Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from n/a through 5.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38766" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/matomo/vulnerability/wordpress-matomo-analytics-plugin-5-1-0-cross-site-request-forgery-csrf-leading-to-notice-dismissal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gjpw-5w4x-fpq5/GHSA-gjpw-5w4x-fpq5.json b/advisories/unreviewed/2025/01/GHSA-gjpw-5w4x-fpq5/GHSA-gjpw-5w4x-fpq5.json new file mode 100644 index 00000000000..06b8b7a49d8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gjpw-5w4x-fpq5/GHSA-gjpw-5w4x-fpq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjpw-5w4x-fpq5", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-45766" + ], + "details": "Missing Authorization vulnerability in Poll Maker Team Poll Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through 4.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45766" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/poll-maker/vulnerability/wordpress-poll-maker-plugin-4-7-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gqcq-9xjx-87r8/GHSA-gqcq-9xjx-87r8.json b/advisories/unreviewed/2025/01/GHSA-gqcq-9xjx-87r8/GHSA-gqcq-9xjx-87r8.json new file mode 100644 index 00000000000..1860aed38a6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gqcq-9xjx-87r8/GHSA-gqcq-9xjx-87r8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqcq-9xjx-87r8", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46637" + ], + "details": "Missing Authorization vulnerability in Saurav Sharma Generate Dummy Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Generate Dummy Posts: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46637" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/generate-dummy-posts/vulnerability/wordpress-generate-dummy-posts-plugin-1-0-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gv3f-5fhv-4rw6/GHSA-gv3f-5fhv-4rw6.json b/advisories/unreviewed/2025/01/GHSA-gv3f-5fhv-4rw6/GHSA-gv3f-5fhv-4rw6.json new file mode 100644 index 00000000000..683afb3f616 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gv3f-5fhv-4rw6/GHSA-gv3f-5fhv-4rw6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv3f-5fhv-4rw6", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46609" + ], + "details": "Missing Authorization vulnerability in FeedFocal FeedFocal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FeedFocal: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46609" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/feedfocal/vulnerability/wordpress-feedfocal-plugin-1-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gvvj-6xq6-cmcv/GHSA-gvvj-6xq6-cmcv.json b/advisories/unreviewed/2025/01/GHSA-gvvj-6xq6-cmcv/GHSA-gvvj-6xq6-cmcv.json new file mode 100644 index 00000000000..b09ff1444d7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gvvj-6xq6-cmcv/GHSA-gvvj-6xq6-cmcv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvvj-6xq6-cmcv", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-38754" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tagbox Taggbox allows Cross Site Request Forgery.This issue affects Taggbox: from n/a through 3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38754" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/taggbox-widget/vulnerability/wordpress-tagbox-plugin-3-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h897-v8rp-9crr/GHSA-h897-v8rp-9crr.json b/advisories/unreviewed/2025/01/GHSA-h897-v8rp-9crr/GHSA-h897-v8rp-9crr.json new file mode 100644 index 00000000000..3bdeae7b1ad --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h897-v8rp-9crr/GHSA-h897-v8rp-9crr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h897-v8rp-9crr", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-47241" + ], + "details": "Missing Authorization vulnerability in CoCart Headless, LLC CoCart – Headless ecommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CoCart – Headless ecommerce: from n/a through 3.11.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47241" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cart-rest-api-for-woocommerce/vulnerability/wordpress-cocart-headless-ecommerce-plugin-3-9-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h9jw-57f3-c84w/GHSA-h9jw-57f3-c84w.json b/advisories/unreviewed/2025/01/GHSA-h9jw-57f3-c84w/GHSA-h9jw-57f3-c84w.json new file mode 100644 index 00000000000..9a64f654143 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h9jw-57f3-c84w/GHSA-h9jw-57f3-c84w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9jw-57f3-c84w", + "modified": "2025-01-02T12:32:10Z", + "published": "2025-01-02T12:32:10Z", + "aliases": [ + "CVE-2024-13062" + ], + "details": "An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution.\nRefer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13062" + }, + { + "type": "WEB", + "url": "https://www.asus.com/content/asus-product-security-advisory" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hc8g-v96w-mf8v/GHSA-hc8g-v96w-mf8v.json b/advisories/unreviewed/2025/01/GHSA-hc8g-v96w-mf8v/GHSA-hc8g-v96w-mf8v.json new file mode 100644 index 00000000000..51524945cf1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hc8g-v96w-mf8v/GHSA-hc8g-v96w-mf8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc8g-v96w-mf8v", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37274" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Freshlight Lab WP Mobile Menu allows Cross Site Request Forgery.This issue affects WP Mobile Menu: from n/a through 2.8.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37274" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mobile-menu/vulnerability/wordpress-wp-mobile-menu-the-mobile-friendly-responsive-menu-plugin-2-8-4-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hhqv-x28f-vvq4/GHSA-hhqv-x28f-vvq4.json b/advisories/unreviewed/2025/01/GHSA-hhqv-x28f-vvq4/GHSA-hhqv-x28f-vvq4.json new file mode 100644 index 00000000000..90bbf77f872 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hhqv-x28f-vvq4/GHSA-hhqv-x28f-vvq4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhqv-x28f-vvq4", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56023" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Perfect Solution WP eCommerce Quickpay allows Reflected XSS.This issue affects WP eCommerce Quickpay: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56023" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ecommerce-quickpay/vulnerability/wordpress-wp-ecommerce-quickpay-plugin-1-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hhr2-qf7f-4f46/GHSA-hhr2-qf7f-4f46.json b/advisories/unreviewed/2025/01/GHSA-hhr2-qf7f-4f46/GHSA-hhr2-qf7f-4f46.json new file mode 100644 index 00000000000..9a78b4b2203 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hhr2-qf7f-4f46/GHSA-hhr2-qf7f-4f46.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhr2-qf7f-4f46", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2024-56035" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kurt Payne Upload Scanner allows Reflected XSS.This issue affects Upload Scanner: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56035" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/upload-scanner/vulnerability/wordpress-upload-scanner-plugin-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hjcq-2c9r-x27g/GHSA-hjcq-2c9r-x27g.json b/advisories/unreviewed/2025/01/GHSA-hjcq-2c9r-x27g/GHSA-hjcq-2c9r-x27g.json new file mode 100644 index 00000000000..67fdeda44d6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hjcq-2c9r-x27g/GHSA-hjcq-2c9r-x27g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjcq-2c9r-x27g", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-37503" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Lawyer Landing Page allows Cross Site Request Forgery.This issue affects Lawyer Landing Page: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37503" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/lawyer-landing-page/vulnerability/wordpress-lawyer-landing-page-theme-1-2-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hwh4-8qxm-jfp4/GHSA-hwh4-8qxm-jfp4.json b/advisories/unreviewed/2025/01/GHSA-hwh4-8qxm-jfp4/GHSA-hwh4-8qxm-jfp4.json new file mode 100644 index 00000000000..9762962b5fd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hwh4-8qxm-jfp4/GHSA-hwh4-8qxm-jfp4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwh4-8qxm-jfp4", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56241" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WPKoi Templates for Elementor allows Stored XSS.This issue affects WPKoi Templates for Elementor: from n/a through 3.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56241" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpkoi-templates-for-elementor/vulnerability/wordpress-wpkoi-templates-for-elementor-plugin-3-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j5xx-pcvm-w86j/GHSA-j5xx-pcvm-w86j.json b/advisories/unreviewed/2025/01/GHSA-j5xx-pcvm-w86j/GHSA-j5xx-pcvm-w86j.json new file mode 100644 index 00000000000..cd9442c3a4f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j5xx-pcvm-w86j/GHSA-j5xx-pcvm-w86j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5xx-pcvm-w86j", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56259" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AyeCode - WP Business Directory Plugins GeoDirectory allows Stored XSS.This issue affects GeoDirectory: from n/a through 2.3.84.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56259" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/geodirectory/vulnerability/wordpress-geodirectory-plugin-2-3-84-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j6jr-vx73-jqf3/GHSA-j6jr-vx73-jqf3.json b/advisories/unreviewed/2025/01/GHSA-j6jr-vx73-jqf3/GHSA-j6jr-vx73-jqf3.json new file mode 100644 index 00000000000..ce7a21cca52 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j6jr-vx73-jqf3/GHSA-j6jr-vx73-jqf3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6jr-vx73-jqf3", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-38765" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Freelancelot Oceanic allows Cross Site Request Forgery.This issue affects Oceanic: from n/a through 1.0.48.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38765" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/oceanic/vulnerability/wordpress-oceanic-theme-1-0-48-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jcfm-5jqr-9j9r/GHSA-jcfm-5jqr-9j9r.json b/advisories/unreviewed/2025/01/GHSA-jcfm-5jqr-9j9r/GHSA-jcfm-5jqr-9j9r.json new file mode 100644 index 00000000000..8a602062070 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jcfm-5jqr-9j9r/GHSA-jcfm-5jqr-9j9r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcfm-5jqr-9j9r", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-45636" + ], + "details": "Missing Authorization vulnerability in WebToffee WordPress Backup & Migration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Backup & Migration: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45636" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-migration-duplicator/vulnerability/wordpress-wordpress-backup-migration-plugin-1-4-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jw36-r882-v3f9/GHSA-jw36-r882-v3f9.json b/advisories/unreviewed/2025/01/GHSA-jw36-r882-v3f9/GHSA-jw36-r882-v3f9.json new file mode 100644 index 00000000000..7c94b42c127 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jw36-r882-v3f9/GHSA-jw36-r882-v3f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw36-r882-v3f9", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56262" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Coaches allows Stored XSS.This issue affects GS Coaches: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56262" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gs-coach/vulnerability/wordpress-gs-coaches-plugin-1-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jx6p-7q85-jcpj/GHSA-jx6p-7q85-jcpj.json b/advisories/unreviewed/2025/01/GHSA-jx6p-7q85-jcpj/GHSA-jx6p-7q85-jcpj.json new file mode 100644 index 00000000000..b4a0dacff38 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jx6p-7q85-jcpj/GHSA-jx6p-7q85-jcpj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx6p-7q85-jcpj", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-37491" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Apollo13Themes Rife Free allows Cross Site Request Forgery.This issue affects Rife Free: from n/a through 2.4.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37491" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/rife-free/vulnerability/wordpress-rife-free-theme-2-4-18-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m2x6-ffx8-32q3/GHSA-m2x6-ffx8-32q3.json b/advisories/unreviewed/2025/01/GHSA-m2x6-ffx8-32q3/GHSA-m2x6-ffx8-32q3.json new file mode 100644 index 00000000000..2d363ca0cea --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m2x6-ffx8-32q3/GHSA-m2x6-ffx8-32q3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2x6-ffx8-32q3", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46206" + ], + "details": "Missing Authorization vulnerability in websoudan MW WP Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MW WP Form: from n/a through 4.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46206" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mw-wp-form/vulnerability/wordpress-mw-wp-form-plugin-4-4-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m4p9-jj4g-gvgx/GHSA-m4p9-jj4g-gvgx.json b/advisories/unreviewed/2025/01/GHSA-m4p9-jj4g-gvgx/GHSA-m4p9-jj4g-gvgx.json new file mode 100644 index 00000000000..5fd63b98222 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m4p9-jj4g-gvgx/GHSA-m4p9-jj4g-gvgx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4p9-jj4g-gvgx", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46606" + ], + "details": "Missing Authorization vulnerability in AtomChat AtomChat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AtomChat: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46606" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/atomchat/vulnerability/wordpress-atomchat-plugin-1-1-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mfvg-hp2g-pr6f/GHSA-mfvg-hp2g-pr6f.json b/advisories/unreviewed/2025/01/GHSA-mfvg-hp2g-pr6f/GHSA-mfvg-hp2g-pr6f.json new file mode 100644 index 00000000000..d04292e40a9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mfvg-hp2g-pr6f/GHSA-mfvg-hp2g-pr6f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfvg-hp2g-pr6f", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46082" + ], + "details": "Missing Authorization vulnerability in Cyberlord92 Broken Link Checker | Finder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broken Link Checker | Finder: from n/a through 2.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46082" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/broken-link-finder/vulnerability/wordpress-broken-link-checker-finder-plugin-2-4-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mhhf-6vwh-c57m/GHSA-mhhf-6vwh-c57m.json b/advisories/unreviewed/2025/01/GHSA-mhhf-6vwh-c57m/GHSA-mhhf-6vwh-c57m.json new file mode 100644 index 00000000000..caa7f19e3e1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mhhf-6vwh-c57m/GHSA-mhhf-6vwh-c57m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhhf-6vwh-c57m", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-47179" + ], + "details": "Missing Authorization vulnerability in ByConsole WooODT Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooODT Lite: from n/a through 2.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47179" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/byconsole-woo-order-delivery-time/vulnerability/wordpress-wooodt-lite-plugin-2-4-6-arbitrary-site-option-update-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mm26-fwx4-9mg6/GHSA-mm26-fwx4-9mg6.json b/advisories/unreviewed/2025/01/GHSA-mm26-fwx4-9mg6/GHSA-mm26-fwx4-9mg6.json new file mode 100644 index 00000000000..8217f2452b6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mm26-fwx4-9mg6/GHSA-mm26-fwx4-9mg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm26-fwx4-9mg6", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37431" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Horea Radu Mesmerize allows Cross Site Request Forgery.This issue affects Mesmerize: from n/a through 1.6.120.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37431" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/mesmerize/vulnerability/wordpress-mesmerize-theme-1-6-120-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mpg4-hgp7-97mq/GHSA-mpg4-hgp7-97mq.json b/advisories/unreviewed/2025/01/GHSA-mpg4-hgp7-97mq/GHSA-mpg4-hgp7-97mq.json new file mode 100644 index 00000000000..1b914837958 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mpg4-hgp7-97mq/GHSA-mpg4-hgp7-97mq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpg4-hgp7-97mq", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56267" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fla-shop.com Interactive UK Map allows Stored XSS.This issue affects Interactive UK Map: from n/a through 3.4.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56267" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/interactive-uk-map/vulnerability/wordpress-interactive-uk-map-plugin-3-4-8-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mvfr-rhh2-r262/GHSA-mvfr-rhh2-r262.json b/advisories/unreviewed/2025/01/GHSA-mvfr-rhh2-r262/GHSA-mvfr-rhh2-r262.json new file mode 100644 index 00000000000..4ca8e010fa5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mvfr-rhh2-r262/GHSA-mvfr-rhh2-r262.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvfr-rhh2-r262", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-38790" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Smartsupp Smartsupp – live chat, chatbots, AI and lead generation allows Cross Site Request Forgery.This issue affects Smartsupp – live chat, chatbots, AI and lead generation: from n/a through 3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38790" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smartsupp-live-chat/vulnerability/wordpress-smartsupp-plugin-3-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p5vr-hv88-pcmq/GHSA-p5vr-hv88-pcmq.json b/advisories/unreviewed/2025/01/GHSA-p5vr-hv88-pcmq/GHSA-p5vr-hv88-pcmq.json new file mode 100644 index 00000000000..e6c2636b8db --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p5vr-hv88-pcmq/GHSA-p5vr-hv88-pcmq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5vr-hv88-pcmq", + "modified": "2025-01-02T12:32:11Z", + "published": "2025-01-02T12:32:11Z", + "aliases": [ + "CVE-2024-56027" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BizSwoop a CPF Concepts, LLC Brand Leads CRM allows Reflected XSS.This issue affects Leads CRM: from n/a through 2.0.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56027" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/leads-crm/vulnerability/wordpress-leads-crm-plugin-2-0-13-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p6h6-cxwm-jqh5/GHSA-p6h6-cxwm-jqh5.json b/advisories/unreviewed/2025/01/GHSA-p6h6-cxwm-jqh5/GHSA-p6h6-cxwm-jqh5.json new file mode 100644 index 00000000000..4ce16053059 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p6h6-cxwm-jqh5/GHSA-p6h6-cxwm-jqh5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6h6-cxwm-jqh5", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56244" + ], + "details": "Missing Authorization vulnerability in WP Royal Ashe Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ashe Extra: from n/a through 1.2.92.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56244" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ashe-extra/vulnerability/wordpress-ashe-extra-plugin-1-2-92-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pc38-jx4p-rvj5/GHSA-pc38-jx4p-rvj5.json b/advisories/unreviewed/2025/01/GHSA-pc38-jx4p-rvj5/GHSA-pc38-jx4p-rvj5.json new file mode 100644 index 00000000000..08433f92704 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pc38-jx4p-rvj5/GHSA-pc38-jx4p-rvj5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc38-jx4p-rvj5", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46635" + ], + "details": "Missing Authorization vulnerability in YITH YITH WooCommerce Product Add-Ons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46635" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/yith-woocommerce-product-add-ons/vulnerability/wordpress-yith-woocommerce-product-add-ons-plugin-4-2-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pfcx-4w69-8v9p/GHSA-pfcx-4w69-8v9p.json b/advisories/unreviewed/2025/01/GHSA-pfcx-4w69-8v9p/GHSA-pfcx-4w69-8v9p.json new file mode 100644 index 00000000000..cf3f2f21e31 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pfcx-4w69-8v9p/GHSA-pfcx-4w69-8v9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfcx-4w69-8v9p", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:11Z", + "aliases": [ + "CVE-2024-56032" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision FV Descriptions allows Reflected XSS.This issue affects FV Descriptions: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56032" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fv-descriptions/vulnerability/wordpress-fv-descriptions-plugin-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pfxc-xwc8-3rwv/GHSA-pfxc-xwc8-3rwv.json b/advisories/unreviewed/2025/01/GHSA-pfxc-xwc8-3rwv/GHSA-pfxc-xwc8-3rwv.json new file mode 100644 index 00000000000..b4d49c72e44 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pfxc-xwc8-3rwv/GHSA-pfxc-xwc8-3rwv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfxc-xwc8-3rwv", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-38789" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Telegram Bot & Channel allows Cross Site Request Forgery.This issue affects Telegram Bot & Channel: from n/a through 3.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38789" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/telegram-bot/vulnerability/wordpress-telegram-bot-channel-plugin-3-8-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pp23-h25j-hwj6/GHSA-pp23-h25j-hwj6.json b/advisories/unreviewed/2025/01/GHSA-pp23-h25j-hwj6/GHSA-pp23-h25j-hwj6.json new file mode 100644 index 00000000000..82651897e68 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pp23-h25j-hwj6/GHSA-pp23-h25j-hwj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp23-h25j-hwj6", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2024-56069" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Azzaroco WP SuperBackup allows Reflected XSS.This issue affects WP SuperBackup: from n/a through 2.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56069" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/indeed-wp-superbackup/vulnerability/wordpress-wp-superbackup-plugin-2-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-prjv-6q89-p458/GHSA-prjv-6q89-p458.json b/advisories/unreviewed/2025/01/GHSA-prjv-6q89-p458/GHSA-prjv-6q89-p458.json new file mode 100644 index 00000000000..e2240ad9eb5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-prjv-6q89-p458/GHSA-prjv-6q89-p458.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prjv-6q89-p458", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-13106" + ], + "details": "A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/form2IPQoSTcAdd of the component IP QoS Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13106" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Unauthorized_Vulnerability/D-Link/DIR-816/form2IPQoSTcAdd.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289922" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289922" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.472086" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-prw5-xj65-rw25/GHSA-prw5-xj65-rw25.json b/advisories/unreviewed/2025/01/GHSA-prw5-xj65-rw25/GHSA-prw5-xj65-rw25.json new file mode 100644 index 00000000000..da63432943b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-prw5-xj65-rw25/GHSA-prw5-xj65-rw25.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prw5-xj65-rw25", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2023-45110" + ], + "details": "Missing Authorization vulnerability in BoldThemes Bold Timeline Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bold Timeline Lite: from n/a through 1.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45110" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bold-timeline-lite/vulnerability/wordpress-bold-timeline-lite-plugin-1-1-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q2jw-m262-j467/GHSA-q2jw-m262-j467.json b/advisories/unreviewed/2025/01/GHSA-q2jw-m262-j467/GHSA-q2jw-m262-j467.json new file mode 100644 index 00000000000..1b36c4d15ec --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q2jw-m262-j467/GHSA-q2jw-m262-j467.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2jw-m262-j467", + "modified": "2025-01-02T12:32:11Z", + "published": "2025-01-02T12:32:11Z", + "aliases": [ + "CVE-2024-56019" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gavin Rehkemper Inline Footnotes allows Stored XSS.This issue affects Inline Footnotes: from n/a through 2.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56019" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/inline-footnotes/vulnerability/wordpress-inline-footnotes-plugin-2-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q52w-pcvj-5fw4/GHSA-q52w-pcvj-5fw4.json b/advisories/unreviewed/2025/01/GHSA-q52w-pcvj-5fw4/GHSA-q52w-pcvj-5fw4.json new file mode 100644 index 00000000000..143594fff41 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q52w-pcvj-5fw4/GHSA-q52w-pcvj-5fw4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q52w-pcvj-5fw4", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56243" + ], + "details": "Missing Authorization vulnerability in JS Morisset WPSSO Core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSSO Core: from n/a through 18.18.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56243" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpsso/vulnerability/wordpress-wpsso-core-plugin-18-18-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q5p8-jqfw-mr9j/GHSA-q5p8-jqfw-mr9j.json b/advisories/unreviewed/2025/01/GHSA-q5p8-jqfw-mr9j/GHSA-q5p8-jqfw-mr9j.json new file mode 100644 index 00000000000..2f57a3aa380 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q5p8-jqfw-mr9j/GHSA-q5p8-jqfw-mr9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5p8-jqfw-mr9j", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37104" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Chic Lite allows Cross Site Request Forgery.This issue affects Chic Lite: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37104" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/chic-lite/vulnerability/wordpress-chic-lite-theme-1-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q6w6-r2x5-ppvh/GHSA-q6w6-r2x5-ppvh.json b/advisories/unreviewed/2025/01/GHSA-q6w6-r2x5-ppvh/GHSA-q6w6-r2x5-ppvh.json new file mode 100644 index 00000000000..0a7eeb90c24 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q6w6-r2x5-ppvh/GHSA-q6w6-r2x5-ppvh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6w6-r2x5-ppvh", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37093" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes MasterStudy LMS allows Cross Site Request Forgery.This issue affects MasterStudy LMS: from n/a through 3.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37093" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/masterstudy-lms-learning-management-system/vulnerability/wordpress-masterstudy-lms-wordpress-plugin-plugin-3-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q78g-rq83-x9jw/GHSA-q78g-rq83-x9jw.json b/advisories/unreviewed/2025/01/GHSA-q78g-rq83-x9jw/GHSA-q78g-rq83-x9jw.json new file mode 100644 index 00000000000..c6c17345d7a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q78g-rq83-x9jw/GHSA-q78g-rq83-x9jw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q78g-rq83-x9jw", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56236" + ], + "details": "Missing Authorization vulnerability in Jakob Bouchard Hestia Nginx Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hestia Nginx Cache: from n/a through 2.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56236" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hestia-nginx-cache/vulnerability/wordpress-hestia-nginx-cache-plugin-2-4-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q89w-jhff-mgwg/GHSA-q89w-jhff-mgwg.json b/advisories/unreviewed/2025/01/GHSA-q89w-jhff-mgwg/GHSA-q89w-jhff-mgwg.json new file mode 100644 index 00000000000..539a752c45f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q89w-jhff-mgwg/GHSA-q89w-jhff-mgwg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q89w-jhff-mgwg", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56254" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56254" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/move-addons/vulnerability/wordpress-move-addons-for-elementor-plugin-1-3-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qchh-53jp-gf92/GHSA-qchh-53jp-gf92.json b/advisories/unreviewed/2025/01/GHSA-qchh-53jp-gf92/GHSA-qchh-53jp-gf92.json new file mode 100644 index 00000000000..9338064acaf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qchh-53jp-gf92/GHSA-qchh-53jp-gf92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qchh-53jp-gf92", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37478" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Royal Ashe allows Cross Site Request Forgery.This issue affects Ashe: from n/a through 2.233.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37478" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/ashe/vulnerability/wordpress-ashe-theme-2-233-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qcxq-2rpp-xc55/GHSA-qcxq-2rpp-xc55.json b/advisories/unreviewed/2025/01/GHSA-qcxq-2rpp-xc55/GHSA-qcxq-2rpp-xc55.json new file mode 100644 index 00000000000..26ee415313e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qcxq-2rpp-xc55/GHSA-qcxq-2rpp-xc55.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcxq-2rpp-xc55", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2024-56034" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Irshad Services updates for customers allows Reflected XSS.This issue affects Services updates for customers: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56034" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/service-updates-for-customers/vulnerability/wordpress-services-updates-for-customers-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qm8g-c4wj-c733/GHSA-qm8g-c4wj-c733.json b/advisories/unreviewed/2025/01/GHSA-qm8g-c4wj-c733/GHSA-qm8g-c4wj-c733.json new file mode 100644 index 00000000000..a732869efdc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qm8g-c4wj-c733/GHSA-qm8g-c4wj-c733.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm8g-c4wj-c733", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2024-56036" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ondrej Donek odPhotogallery allows Reflected XSS.This issue affects odPhotogallery: from n/a through 0.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56036" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/od-photogallery-plugin/vulnerability/wordpress-odphotogallery-plugin-0-5-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qq73-pjw7-j745/GHSA-qq73-pjw7-j745.json b/advisories/unreviewed/2025/01/GHSA-qq73-pjw7-j745/GHSA-qq73-pjw7-j745.json new file mode 100644 index 00000000000..a543b0645f6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qq73-pjw7-j745/GHSA-qq73-pjw7-j745.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq73-pjw7-j745", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56247" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author allows SQL Injection.This issue affects WP Post Author: from n/a through 3.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56247" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-post-author/vulnerability/wordpress-wp-post-author-plugin-3-8-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qv7f-cx6j-fr56/GHSA-qv7f-cx6j-fr56.json b/advisories/unreviewed/2025/01/GHSA-qv7f-cx6j-fr56/GHSA-qv7f-cx6j-fr56.json new file mode 100644 index 00000000000..9294e651813 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qv7f-cx6j-fr56/GHSA-qv7f-cx6j-fr56.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv7f-cx6j-fr56", + "modified": "2025-01-02T12:32:10Z", + "published": "2025-01-02T12:32:10Z", + "aliases": [ + "CVE-2024-13102" + ], + "details": "A vulnerability classified as critical was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. This vulnerability affects unknown code of the file /goform/DDNS of the component DDNS Service. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13102" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Unauthorized_Vulnerability/D-Link/DIR-816/DDNS.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289918" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289918" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.472074" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qvxg-q7w7-8727/GHSA-qvxg-q7w7-8727.json b/advisories/unreviewed/2025/01/GHSA-qvxg-q7w7-8727/GHSA-qvxg-q7w7-8727.json new file mode 100644 index 00000000000..0003f4a999b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qvxg-q7w7-8727/GHSA-qvxg-q7w7-8727.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvxg-q7w7-8727", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56248" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Webdeclic WPMasterToolKit allows Path Traversal.This issue affects WPMasterToolKit: from n/a through 1.13.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56248" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpmastertoolkit/vulnerability/wordpress-wpmastertoolkit-plugin-1-13-1-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qxpg-92h3-8vjc/GHSA-qxpg-92h3-8vjc.json b/advisories/unreviewed/2025/01/GHSA-qxpg-92h3-8vjc/GHSA-qxpg-92h3-8vjc.json new file mode 100644 index 00000000000..741d75b3b35 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qxpg-92h3-8vjc/GHSA-qxpg-92h3-8vjc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxpg-92h3-8vjc", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-47188" + ], + "details": "Missing Authorization vulnerability in PressTigers Simple Job Board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Job Board: from n/a through 2.10.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47188" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-job-board/vulnerability/wordpress-simple-job-board-plugin-2-10-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r258-m6wf-fq8v/GHSA-r258-m6wf-fq8v.json b/advisories/unreviewed/2025/01/GHSA-r258-m6wf-fq8v/GHSA-r258-m6wf-fq8v.json new file mode 100644 index 00000000000..aa4d6c0fbfb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r258-m6wf-fq8v/GHSA-r258-m6wf-fq8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r258-m6wf-fq8v", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56239" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Themify Audio Dock allows Stored XSS.This issue affects Themify Audio Dock: from n/a through 2.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56239" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/themify-audio-dock/vulnerability/wordpress-themify-audio-dock-plugin-2-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r297-8r34-c73v/GHSA-r297-8r34-c73v.json b/advisories/unreviewed/2025/01/GHSA-r297-8r34-c73v/GHSA-r297-8r34-c73v.json new file mode 100644 index 00000000000..83bc7b1f1ae --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r297-8r34-c73v/GHSA-r297-8r34-c73v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r297-8r34-c73v", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37102" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Vilva allows Cross Site Request Forgery.This issue affects Vilva: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37102" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/vilva/vulnerability/wordpress-vilva-theme-1-2-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r2vj-9427-ph5q/GHSA-r2vj-9427-ph5q.json b/advisories/unreviewed/2025/01/GHSA-r2vj-9427-ph5q/GHSA-r2vj-9427-ph5q.json new file mode 100644 index 00000000000..a7fc2d9a113 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r2vj-9427-ph5q/GHSA-r2vj-9427-ph5q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2vj-9427-ph5q", + "modified": "2025-01-02T12:32:16Z", + "published": "2025-01-02T12:32:16Z", + "aliases": [ + "CVE-2024-56260" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StorePlugin ShopElement allows Stored XSS.This issue affects ShopElement: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56260" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shopelement/vulnerability/wordpress-shopelement-plugin-2-0-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r95p-3cgx-x6w2/GHSA-r95p-3cgx-x6w2.json b/advisories/unreviewed/2025/01/GHSA-r95p-3cgx-x6w2/GHSA-r95p-3cgx-x6w2.json new file mode 100644 index 00000000000..92a33256956 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r95p-3cgx-x6w2/GHSA-r95p-3cgx-x6w2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r95p-3cgx-x6w2", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37243" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Vandana Lite allows Cross Site Request Forgery.This issue affects Vandana Lite: from n/a through 1.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37243" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/vandana-lite/vulnerability/wordpress-vandana-lite-theme-1-1-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rfmf-6824-3rxj/GHSA-rfmf-6824-3rxj.json b/advisories/unreviewed/2025/01/GHSA-rfmf-6824-3rxj/GHSA-rfmf-6824-3rxj.json new file mode 100644 index 00000000000..6263feb1e4d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rfmf-6824-3rxj/GHSA-rfmf-6824-3rxj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfmf-6824-3rxj", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56024" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Dashboard Widget allows Reflected XSS.This issue affects Custom Dashboard Widget: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56024" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/create-custom-dashboard-widget/vulnerability/wordpress-custom-dashboard-widget-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rg78-hx6j-92j4/GHSA-rg78-hx6j-92j4.json b/advisories/unreviewed/2025/01/GHSA-rg78-hx6j-92j4/GHSA-rg78-hx6j-92j4.json new file mode 100644 index 00000000000..64dd0c4c38c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rg78-hx6j-92j4/GHSA-rg78-hx6j-92j4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg78-hx6j-92j4", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37103" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Education Zone allows Cross Site Request Forgery.This issue affects Education Zone: from n/a through 1.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37103" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/education-zone/vulnerability/wordpress-education-zone-theme-1-3-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rr83-cj5r-76xg/GHSA-rr83-cj5r-76xg.json b/advisories/unreviewed/2025/01/GHSA-rr83-cj5r-76xg/GHSA-rr83-cj5r-76xg.json new file mode 100644 index 00000000000..0ed74f25f85 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rr83-cj5r-76xg/GHSA-rr83-cj5r-76xg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr83-cj5r-76xg", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46612" + ], + "details": "Missing Authorization vulnerability in codedrafty Mediabay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mediabay: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46612" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mediabay-lite/vulnerability/wordpress-mediabay-plugin-1-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rrv4-98wq-7v85/GHSA-rrv4-98wq-7v85.json b/advisories/unreviewed/2025/01/GHSA-rrv4-98wq-7v85/GHSA-rrv4-98wq-7v85.json new file mode 100644 index 00000000000..59f4bb21def --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rrv4-98wq-7v85/GHSA-rrv4-98wq-7v85.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrv4-98wq-7v85", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-47515" + ], + "details": "Missing Authorization vulnerability in Seers Seers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seers: from n/a through 8.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47515" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/seers-cookie-consent-banner-privacy-policy/vulnerability/wordpress-seers-gdpr-ccpa-cookie-consent-compliance-plugin-8-0-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rvq2-3c2g-vvqc/GHSA-rvq2-3c2g-vvqc.json b/advisories/unreviewed/2025/01/GHSA-rvq2-3c2g-vvqc/GHSA-rvq2-3c2g-vvqc.json new file mode 100644 index 00000000000..b7fdb6f7488 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rvq2-3c2g-vvqc/GHSA-rvq2-3c2g-vvqc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvq2-3c2g-vvqc", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37458" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ExtendThemes Highlight allows Cross Site Request Forgery.This issue affects Highlight: from n/a through 1.0.29.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37458" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/highlight/vulnerability/wordpress-highlight-theme-1-0-29-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rwvg-86h3-6xfg/GHSA-rwvg-86h3-6xfg.json b/advisories/unreviewed/2025/01/GHSA-rwvg-86h3-6xfg/GHSA-rwvg-86h3-6xfg.json new file mode 100644 index 00000000000..e1011699a4a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rwvg-86h3-6xfg/GHSA-rwvg-86h3-6xfg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwvg-86h3-6xfg", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46628" + ], + "details": "Missing Authorization vulnerability in RedLettuce Plugins WP Word Count allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Word Count: from n/a through 3.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46628" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-word-count/vulnerability/wordpress-wp-word-count-plugin-3-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rxj2-8fr9-hwcq/GHSA-rxj2-8fr9-hwcq.json b/advisories/unreviewed/2025/01/GHSA-rxj2-8fr9-hwcq/GHSA-rxj2-8fr9-hwcq.json new file mode 100644 index 00000000000..5b9406d2ef4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rxj2-8fr9-hwcq/GHSA-rxj2-8fr9-hwcq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxj2-8fr9-hwcq", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46639" + ], + "details": "Missing Authorization vulnerability in FeedbackWP kk Star Ratings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects kk Star Ratings: from n/a through 5.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46639" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kk-star-ratings/vulnerability/wordpress-kk-star-ratings-plugin-5-4-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v2cv-56x5-vrg8/GHSA-v2cv-56x5-vrg8.json b/advisories/unreviewed/2025/01/GHSA-v2cv-56x5-vrg8/GHSA-v2cv-56x5-vrg8.json new file mode 100644 index 00000000000..4956ad54401 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v2cv-56x5-vrg8/GHSA-v2cv-56x5-vrg8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2cv-56x5-vrg8", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37441" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in DesertThemes NewsMash allows Cross Site Request Forgery.This issue affects NewsMash: from n/a through 1.0.34.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37441" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/newsmash/vulnerability/wordpress-newsmash-theme-1-0-34-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v3ch-c23g-q3jm/GHSA-v3ch-c23g-q3jm.json b/advisories/unreviewed/2025/01/GHSA-v3ch-c23g-q3jm/GHSA-v3ch-c23g-q3jm.json new file mode 100644 index 00000000000..4fa651ca59a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v3ch-c23g-q3jm/GHSA-v3ch-c23g-q3jm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3ch-c23g-q3jm", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37238" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Greg Winiarski WPAdverts – Classifieds Plugin allows Cross Site Request Forgery.This issue affects WPAdverts – Classifieds Plugin: from n/a through 2.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37238" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpadverts/vulnerability/wordpress-wpadverts-classifieds-plugin-2-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v3p2-wr4v-2xm7/GHSA-v3p2-wr4v-2xm7.json b/advisories/unreviewed/2025/01/GHSA-v3p2-wr4v-2xm7/GHSA-v3p2-wr4v-2xm7.json new file mode 100644 index 00000000000..322d5311394 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v3p2-wr4v-2xm7/GHSA-v3p2-wr4v-2xm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3p2-wr4v-2xm7", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46196" + ], + "details": "Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social proof testimonials and reviews by Repuso: from n/a through 4.97.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46196" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-testimonials-and-reviews-widget/vulnerability/wordpress-social-proof-testimonials-and-reviews-by-repuso-plugin-4-97-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v3xg-ppxj-3hq6/GHSA-v3xg-ppxj-3hq6.json b/advisories/unreviewed/2025/01/GHSA-v3xg-ppxj-3hq6/GHSA-v3xg-ppxj-3hq6.json new file mode 100644 index 00000000000..31b4406cc83 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v3xg-ppxj-3hq6/GHSA-v3xg-ppxj-3hq6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3xg-ppxj-3hq6", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46633" + ], + "details": "Missing Authorization vulnerability in TCBarrett Glossary allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Glossary: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46633" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-glossary/vulnerability/wordpress-wp-glossary-plugin-3-1-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v5jp-hvcv-p53f/GHSA-v5jp-hvcv-p53f.json b/advisories/unreviewed/2025/01/GHSA-v5jp-hvcv-p53f/GHSA-v5jp-hvcv-p53f.json new file mode 100644 index 00000000000..008b94bb1ef --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v5jp-hvcv-p53f/GHSA-v5jp-hvcv-p53f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5jp-hvcv-p53f", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46632" + ], + "details": "Missing Authorization vulnerability in David Cramer My Shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Shortcodes: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46632" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/my-shortcodes/vulnerability/wordpress-my-shortcodes-plugin-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v926-q2pq-xwfc/GHSA-v926-q2pq-xwfc.json b/advisories/unreviewed/2025/01/GHSA-v926-q2pq-xwfc/GHSA-v926-q2pq-xwfc.json new file mode 100644 index 00000000000..929e752910e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v926-q2pq-xwfc/GHSA-v926-q2pq-xwfc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v926-q2pq-xwfc", + "modified": "2025-01-02T12:32:11Z", + "published": "2025-01-02T12:32:11Z", + "aliases": [ + "CVE-2024-56030" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10CentMail allows Reflected XSS.This issue affects 10CentMail: from n/a through 2.1.50.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56030" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/10centmail-subscription-management-and-analytics/vulnerability/wordpress-10centmail-plugin-2-1-50-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v96p-r3h8-9gxj/GHSA-v96p-r3h8-9gxj.json b/advisories/unreviewed/2025/01/GHSA-v96p-r3h8-9gxj/GHSA-v96p-r3h8-9gxj.json new file mode 100644 index 00000000000..14678de571f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v96p-r3h8-9gxj/GHSA-v96p-r3h8-9gxj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v96p-r3h8-9gxj", + "modified": "2025-01-02T12:32:11Z", + "published": "2025-01-02T12:32:11Z", + "aliases": [ + "CVE-2024-56028" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lemonade Coding Studio Lemonade Social Networks Autoposter Pinterest allows Reflected XSS.This issue affects Lemonade Social Networks Autoposter Pinterest: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56028" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lemonade-sna-pinterest-edition/vulnerability/wordpress-lemonade-social-networks-autoposter-pinterest-plugin-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vw4h-wjj3-qg3g/GHSA-vw4h-wjj3-qg3g.json b/advisories/unreviewed/2025/01/GHSA-vw4h-wjj3-qg3g/GHSA-vw4h-wjj3-qg3g.json new file mode 100644 index 00000000000..92aeffeca0a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vw4h-wjj3-qg3g/GHSA-vw4h-wjj3-qg3g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw4h-wjj3-qg3g", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37450" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Benevolent allows Cross Site Request Forgery.This issue affects Benevolent: from n/a through 1.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37450" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/benevolent/vulnerability/wordpress-benevolent-theme-1-3-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vwj6-j9jf-c8g6/GHSA-vwj6-j9jf-c8g6.json b/advisories/unreviewed/2025/01/GHSA-vwj6-j9jf-c8g6/GHSA-vwj6-j9jf-c8g6.json new file mode 100644 index 00000000000..920ffdd696a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vwj6-j9jf-c8g6/GHSA-vwj6-j9jf-c8g6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwj6-j9jf-c8g6", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56245" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress allows Stored XSS.This issue affects Premium Blocks – Gutenberg Blocks for WordPress: from n/a through 2.1.42.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56245" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/premium-blocks-for-gutenberg/vulnerability/wordpress-premium-blocks-plugin-2-1-42-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w4m2-8qxq-h2wj/GHSA-w4m2-8qxq-h2wj.json b/advisories/unreviewed/2025/01/GHSA-w4m2-8qxq-h2wj/GHSA-w4m2-8qxq-h2wj.json new file mode 100644 index 00000000000..adf23e9f93e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w4m2-8qxq-h2wj/GHSA-w4m2-8qxq-h2wj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4m2-8qxq-h2wj", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46080" + ], + "details": "Missing Authorization vulnerability in Farhan Noor ApplyOnline – Application Form Builder and Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ApplyOnline – Application Form Builder and Manager: from n/a through 2.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46080" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/apply-online/vulnerability/wordpress-applyonline-application-form-builder-and-manager-plugin-2-5-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w7jw-mp2h-ch44/GHSA-w7jw-mp2h-ch44.json b/advisories/unreviewed/2025/01/GHSA-w7jw-mp2h-ch44/GHSA-w7jw-mp2h-ch44.json new file mode 100644 index 00000000000..3c8be1337d7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w7jw-mp2h-ch44/GHSA-w7jw-mp2h-ch44.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7jw-mp2h-ch44", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46607" + ], + "details": "Missing Authorization vulnerability in WP iCal Availability WP iCal Availability allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP iCal Availability: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46607" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ical-availability/vulnerability/wordpress-wp-ical-availability-plugin-1-0-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wfxr-4mfh-gqq9/GHSA-wfxr-4mfh-gqq9.json b/advisories/unreviewed/2025/01/GHSA-wfxr-4mfh-gqq9/GHSA-wfxr-4mfh-gqq9.json new file mode 100644 index 00000000000..a7723cbc299 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wfxr-4mfh-gqq9/GHSA-wfxr-4mfh-gqq9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfxr-4mfh-gqq9", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56242" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tyche Softwares Arconix Shortcodes allows Stored XSS.This issue affects Arconix Shortcodes: from n/a through 2.1.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56242" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arconix-shortcodes/vulnerability/wordpress-arconix-shortcodes-plugin-2-1-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wg89-q26p-7q23/GHSA-wg89-q26p-7q23.json b/advisories/unreviewed/2025/01/GHSA-wg89-q26p-7q23/GHSA-wg89-q26p-7q23.json new file mode 100644 index 00000000000..ad47aabbc0e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wg89-q26p-7q23/GHSA-wg89-q26p-7q23.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg89-q26p-7q23", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-56246" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Blocks allows DOM-Based XSS.This issue affects Nexter Blocks: from n/a through 4.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56246" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-plus-addons-for-block-editor/vulnerability/wordpress-nexter-blocks-plugin-4-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wgg3-6fhx-57cc/GHSA-wgg3-6fhx-57cc.json b/advisories/unreviewed/2025/01/GHSA-wgg3-6fhx-57cc/GHSA-wgg3-6fhx-57cc.json new file mode 100644 index 00000000000..c8aa5cc9c11 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wgg3-6fhx-57cc/GHSA-wgg3-6fhx-57cc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgg3-6fhx-57cc", + "modified": "2025-01-02T12:32:12Z", + "published": "2025-01-02T12:32:12Z", + "aliases": [ + "CVE-2023-45061" + ], + "details": "Missing Authorization vulnerability in AWSM Innovations WP Job Openings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Openings: from n/a through 3.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45061" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-job-openings/vulnerability/wordpress-wp-job-openings-plugin-3-4-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wj3g-6pcr-3c9p/GHSA-wj3g-6pcr-3c9p.json b/advisories/unreviewed/2025/01/GHSA-wj3g-6pcr-3c9p/GHSA-wj3g-6pcr-3c9p.json new file mode 100644 index 00000000000..ee9fdf24558 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wj3g-6pcr-3c9p/GHSA-wj3g-6pcr-3c9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj3g-6pcr-3c9p", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2023-47647" + ], + "details": "Missing Authorization vulnerability in LearningTimes BadgeOS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BadgeOS: from n/a through 3.7.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47647" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/badgeos/vulnerability/wordpress-badgeos-plugin-3-7-1-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wm2j-9vcx-h349/GHSA-wm2j-9vcx-h349.json b/advisories/unreviewed/2025/01/GHSA-wm2j-9vcx-h349/GHSA-wm2j-9vcx-h349.json new file mode 100644 index 00000000000..5b44a7a51c0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wm2j-9vcx-h349/GHSA-wm2j-9vcx-h349.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm2j-9vcx-h349", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46083" + ], + "details": "Missing Authorization vulnerability in Kali Forms Contact Form builder with drag & drop - Kali Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form builder with drag & drop - Kali Forms: from n/a through 2.3.27.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46083" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kali-forms/vulnerability/wordpress-kali-forms-plugin-2-3-27-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wqm4-fxvj-mgpg/GHSA-wqm4-fxvj-mgpg.json b/advisories/unreviewed/2025/01/GHSA-wqm4-fxvj-mgpg/GHSA-wqm4-fxvj-mgpg.json new file mode 100644 index 00000000000..fd56c4cb7a5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wqm4-fxvj-mgpg/GHSA-wqm4-fxvj-mgpg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqm4-fxvj-mgpg", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-38763" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Themes4WP Popularis Verse allows Cross Site Request Forgery.This issue affects Popularis Verse: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38763" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/popularis-verse/vulnerability/wordpress-popularis-verse-theme-1-0-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wrj7-mjp6-xvf3/GHSA-wrj7-mjp6-xvf3.json b/advisories/unreviewed/2025/01/GHSA-wrj7-mjp6-xvf3/GHSA-wrj7-mjp6-xvf3.json new file mode 100644 index 00000000000..8b70ecf4d02 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wrj7-mjp6-xvf3/GHSA-wrj7-mjp6-xvf3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrj7-mjp6-xvf3", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-37540" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Leaky Paywall Leaky Paywall allows Cross Site Request Forgery.This issue affects Leaky Paywall: from n/a through 4.21.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37540" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/leaky-paywall/vulnerability/wordpress-leaky-paywall-plugin-4-21-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x2x5-r83x-hffv/GHSA-x2x5-r83x-hffv.json b/advisories/unreviewed/2025/01/GHSA-x2x5-r83x-hffv/GHSA-x2x5-r83x-hffv.json new file mode 100644 index 00000000000..8de27b72a8a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x2x5-r83x-hffv/GHSA-x2x5-r83x-hffv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2x5-r83x-hffv", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-38753" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Labib Ahmed Animated Rotating Words allows Cross Site Request Forgery.This issue affects Animated Rotating Words: from n/a through 5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38753" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/css3-rotating-words/vulnerability/wordpress-animated-rotating-words-plugin-5-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x322-j5qj-m76r/GHSA-x322-j5qj-m76r.json b/advisories/unreviewed/2025/01/GHSA-x322-j5qj-m76r/GHSA-x322-j5qj-m76r.json new file mode 100644 index 00000000000..50fd80c47ae --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x322-j5qj-m76r/GHSA-x322-j5qj-m76r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x322-j5qj-m76r", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-45275" + ], + "details": "Missing Authorization vulnerability in Kali Forms Contact Form builder with drag & drop - Kali Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form builder with drag & drop - Kali Forms: from n/a through 2.3.28.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45275" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kali-forms/vulnerability/wordpress-contact-form-builder-with-drag-drop-plugin-2-3-27-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x39g-98hm-frjw/GHSA-x39g-98hm-frjw.json b/advisories/unreviewed/2025/01/GHSA-x39g-98hm-frjw/GHSA-x39g-98hm-frjw.json new file mode 100644 index 00000000000..827af230609 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x39g-98hm-frjw/GHSA-x39g-98hm-frjw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x39g-98hm-frjw", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-45760" + ], + "details": "Missing Authorization vulnerability in gVectors Team wpDiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through 7.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45760" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpdiscuz/vulnerability/wordpress-wpdiscuz-plugin-7-6-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x5w7-pqwc-pv6m/GHSA-x5w7-pqwc-pv6m.json b/advisories/unreviewed/2025/01/GHSA-x5w7-pqwc-pv6m/GHSA-x5w7-pqwc-pv6m.json new file mode 100644 index 00000000000..2d91ac2a9aa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x5w7-pqwc-pv6m/GHSA-x5w7-pqwc-pv6m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5w7-pqwc-pv6m", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46203" + ], + "details": "Missing Authorization vulnerability in JustCoded / Alex Prokopenko Just Custom Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Just Custom Fields: from n/a through 3.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46203" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/just-custom-fields/vulnerability/wordpress-just-custom-fields-plugin-3-3-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x7wg-r5rh-h8c8/GHSA-x7wg-r5rh-h8c8.json b/advisories/unreviewed/2025/01/GHSA-x7wg-r5rh-h8c8/GHSA-x7wg-r5rh-h8c8.json new file mode 100644 index 00000000000..419fe43435e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x7wg-r5rh-h8c8/GHSA-x7wg-r5rh-h8c8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7wg-r5rh-h8c8", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37451" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Travel Agency allows Cross Site Request Forgery.This issue affects Travel Agency: from n/a through 1.4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37451" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/travel-agency/vulnerability/wordpress-travel-agency-theme-1-4-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xggq-f45p-384m/GHSA-xggq-f45p-384m.json b/advisories/unreviewed/2025/01/GHSA-xggq-f45p-384m/GHSA-xggq-f45p-384m.json new file mode 100644 index 00000000000..272faf6623f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xggq-f45p-384m/GHSA-xggq-f45p-384m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xggq-f45p-384m", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-46188" + ], + "details": "Missing Authorization vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager and cleanup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Freesoul Deactivate Plugins – Plugin manager and cleanup: from n/a through 2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46188" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/freesoul-deactivate-plugins/vulnerability/wordpress-freesoul-deactivate-plugins-plugin-2-1-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xm6c-q2rq-qg8p/GHSA-xm6c-q2rq-qg8p.json b/advisories/unreviewed/2025/01/GHSA-xm6c-q2rq-qg8p/GHSA-xm6c-q2rq-qg8p.json new file mode 100644 index 00000000000..c5d35671dcf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xm6c-q2rq-qg8p/GHSA-xm6c-q2rq-qg8p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm6c-q2rq-qg8p", + "modified": "2025-01-02T12:32:15Z", + "published": "2025-01-02T12:32:15Z", + "aliases": [ + "CVE-2024-37543" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Nitesh Singh Ultimate Auction allows Cross Site Request Forgery.This issue affects Ultimate Auction : from n/a through 4.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37543" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-auction/vulnerability/wordpress-ultimate-auction-plugin-4-2-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xrpc-hpq7-f7wx/GHSA-xrpc-hpq7-f7wx.json b/advisories/unreviewed/2025/01/GHSA-xrpc-hpq7-f7wx/GHSA-xrpc-hpq7-f7wx.json new file mode 100644 index 00000000000..7a7910de37d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xrpc-hpq7-f7wx/GHSA-xrpc-hpq7-f7wx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrpc-hpq7-f7wx", + "modified": "2025-01-02T12:32:13Z", + "published": "2025-01-02T12:32:13Z", + "aliases": [ + "CVE-2023-47224" + ], + "details": "Missing Authorization vulnerability in WP Travel WP Travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through 7.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47224" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-travel/vulnerability/wordpress-wp-travel-plugin-7-5-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xrqh-hpg9-64g6/GHSA-xrqh-hpg9-64g6.json b/advisories/unreviewed/2025/01/GHSA-xrqh-hpg9-64g6/GHSA-xrqh-hpg9-64g6.json new file mode 100644 index 00000000000..1d6083ce8b0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xrqh-hpg9-64g6/GHSA-xrqh-hpg9-64g6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrqh-hpg9-64g6", + "modified": "2025-01-02T12:32:14Z", + "published": "2025-01-02T12:32:14Z", + "aliases": [ + "CVE-2024-37236" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tim Whitlock Loco Translate allows Cross Site Request Forgery.This issue affects Loco Translate: from n/a through 2.6.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37236" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/loco-translate/vulnerability/wordpress-loco-translate-plugin-2-6-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T12:15:18Z" + } +} \ No newline at end of file