diff --git a/advisories/unreviewed/2025/04/GHSA-2f4r-6wjq-849q/GHSA-2f4r-6wjq-849q.json b/advisories/unreviewed/2025/04/GHSA-2f4r-6wjq-849q/GHSA-2f4r-6wjq-849q.json new file mode 100644 index 00000000000..71808be4122 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2f4r-6wjq-849q/GHSA-2f4r-6wjq-849q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f4r-6wjq-849q", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46246" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers allows Cross Site Request Forgery. This issue affects CM Answers: from n/a through 3.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46246" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cm-answers/vulnerability/wordpress-cm-answers-3-3-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2mf5-r62x-gr5c/GHSA-2mf5-r62x-gr5c.json b/advisories/unreviewed/2025/04/GHSA-2mf5-r62x-gr5c/GHSA-2mf5-r62x-gr5c.json new file mode 100644 index 00000000000..7317e8c1f4f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2mf5-r62x-gr5c/GHSA-2mf5-r62x-gr5c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mf5-r62x-gr5c", + "modified": "2025-04-22T12:31:24Z", + "published": "2025-04-22T12:31:24Z", + "aliases": [ + "CVE-2025-2092" + ], + "details": "Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 (EOL) causes remote site authentication secrets to be written to log files accessible to administrators.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2092" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17780" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3hgc-5x5v-4fp3/GHSA-3hgc-5x5v-4fp3.json b/advisories/unreviewed/2025/04/GHSA-3hgc-5x5v-4fp3/GHSA-3hgc-5x5v-4fp3.json new file mode 100644 index 00000000000..1a325c6e266 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3hgc-5x5v-4fp3/GHSA-3hgc-5x5v-4fp3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hgc-5x5v-4fp3", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46235" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks – Gutenberg based Page Builder allows Stored XSS. This issue affects SKT Blocks – Gutenberg based Page Builder: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46235" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/skt-blocks/vulnerability/wordpress-skt-blocks-gutenberg-based-page-builder-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4f53-4g54-q7jq/GHSA-4f53-4g54-q7jq.json b/advisories/unreviewed/2025/04/GHSA-4f53-4g54-q7jq/GHSA-4f53-4g54-q7jq.json new file mode 100644 index 00000000000..9b4b5e70c67 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4f53-4g54-q7jq/GHSA-4f53-4g54-q7jq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f53-4g54-q7jq", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46252" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kofimokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a through 1.6.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46252" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cf7-message-filter/vulnerability/wordpress-message-filter-for-contact-form-7-plugin-1-6-3-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6rp9-wqxg-vpc7/GHSA-6rp9-wqxg-vpc7.json b/advisories/unreviewed/2025/04/GHSA-6rp9-wqxg-vpc7/GHSA-6rp9-wqxg-vpc7.json new file mode 100644 index 00000000000..385cb94bf16 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6rp9-wqxg-vpc7/GHSA-6rp9-wqxg-vpc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rp9-wqxg-vpc7", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46243" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce allows Cross Site Request Forgery. This issue affects Recover abandoned cart for WooCommerce: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46243" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/recover-wc-abandoned-cart/vulnerability/wordpress-recover-abandoned-cart-for-woocommerce-2-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7q2v-j39v-mxfr/GHSA-7q2v-j39v-mxfr.json b/advisories/unreviewed/2025/04/GHSA-7q2v-j39v-mxfr/GHSA-7q2v-j39v-mxfr.json new file mode 100644 index 00000000000..c0e87e8a0f0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7q2v-j39v-mxfr/GHSA-7q2v-j39v-mxfr.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q2v-j39v-mxfr", + "modified": "2025-04-22T12:31:24Z", + "published": "2025-04-22T12:31:24Z", + "aliases": [ + "CVE-2025-3458" + ], + "details": "The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The Classic Editor plugin must be installed and activated to exploit the vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3458" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ocean-extra/tags/2.4.6/includes/metabox/gallery-metabox/gallery-metabox.php#L113" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ocean-extra/tags/2.4.6/includes/metabox/gallery-metabox/gallery-metabox.php#L162" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3277977" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7595a1f6-6923-4102-8efe-a414adebce65?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-86cf-9jhr-7969/GHSA-86cf-9jhr-7969.json b/advisories/unreviewed/2025/04/GHSA-86cf-9jhr-7969/GHSA-86cf-9jhr-7969.json new file mode 100644 index 00000000000..b59eda5943f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-86cf-9jhr-7969/GHSA-86cf-9jhr-7969.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86cf-9jhr-7969", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46231" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit allows Cross Site Request Forgery. This issue affects affiliate-toolkit: from n/a through 3.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46231" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/affiliate-toolkit-starter/vulnerability/wordpress-affiliate-toolkit-3-7-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-884c-w8q7-3ppv/GHSA-884c-w8q7-3ppv.json b/advisories/unreviewed/2025/04/GHSA-884c-w8q7-3ppv/GHSA-884c-w8q7-3ppv.json new file mode 100644 index 00000000000..b683022a8f6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-884c-w8q7-3ppv/GHSA-884c-w8q7-3ppv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-884c-w8q7-3ppv", + "modified": "2025-04-22T12:31:22Z", + "published": "2025-04-22T12:31:22Z", + "aliases": [ + "CVE-2025-46227" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brecht Custom Related Posts allows Stored XSS. This issue affects Custom Related Posts: from n/a through 1.7.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46227" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-related-posts/vulnerability/wordpress-custom-related-posts-1-7-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-89w7-ghxh-3v5x/GHSA-89w7-ghxh-3v5x.json b/advisories/unreviewed/2025/04/GHSA-89w7-ghxh-3v5x/GHSA-89w7-ghxh-3v5x.json new file mode 100644 index 00000000000..40271047de7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-89w7-ghxh-3v5x/GHSA-89w7-ghxh-3v5x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89w7-ghxh-3v5x", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46228" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows DOM-Based XSS. This issue affects Event post: from n/a through 5.9.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46228" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/event-post/vulnerability/wordpress-event-post-5-9-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-92h9-j7q8-mj88/GHSA-92h9-j7q8-mj88.json b/advisories/unreviewed/2025/04/GHSA-92h9-j7q8-mj88/GHSA-92h9-j7q8-mj88.json new file mode 100644 index 00000000000..1c8eaa70b14 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-92h9-j7q8-mj88/GHSA-92h9-j7q8-mj88.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92h9-j7q8-mj88", + "modified": "2025-04-22T12:31:22Z", + "published": "2025-04-22T12:31:22Z", + "aliases": [ + "CVE-2025-46226" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ferranfg MPL-Publisher allows Stored XSS. This issue affects MPL-Publisher: from n/a through 2.18.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46226" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mpl-publisher/vulnerability/wordpress-mpl-publisher-2-18-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9975-2xc8-286g/GHSA-9975-2xc8-286g.json b/advisories/unreviewed/2025/04/GHSA-9975-2xc8-286g/GHSA-9975-2xc8-286g.json new file mode 100644 index 00000000000..d77974f0a86 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9975-2xc8-286g/GHSA-9975-2xc8-286g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9975-2xc8-286g", + "modified": "2025-04-22T12:31:24Z", + "published": "2025-04-22T12:31:24Z", + "aliases": [ + "CVE-2024-11299" + ], + "details": "The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.37 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11299" + }, + { + "type": "WEB", + "url": "https://memberpress.com/change-log/#1.12.0" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/787cd2bb-489f-471a-82e0-073b4766b45a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c2fq-45hq-vjpg/GHSA-c2fq-45hq-vjpg.json b/advisories/unreviewed/2025/04/GHSA-c2fq-45hq-vjpg/GHSA-c2fq-45hq-vjpg.json new file mode 100644 index 00000000000..24eef00e886 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c2fq-45hq-vjpg/GHSA-c2fq-45hq-vjpg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2fq-45hq-vjpg", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46241" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar allows SQL Injection. This issue affects Appointment Booking Calendar: from n/a through 1.3.92.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46241" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/appointment-booking-calendar/vulnerability/wordpress-appointment-booking-calendar-plugin-1-3-92-csrf-to-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c86v-34qq-wvpw/GHSA-c86v-34qq-wvpw.json b/advisories/unreviewed/2025/04/GHSA-c86v-34qq-wvpw/GHSA-c86v-34qq-wvpw.json new file mode 100644 index 00000000000..fc100fcaa3d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c86v-34qq-wvpw/GHSA-c86v-34qq-wvpw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c86v-34qq-wvpw", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46237" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Stored XSS. This issue affects Link Library: from n/a through 7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46237" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/link-library/vulnerability/wordpress-link-library-7-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ccrh-3x3f-9w29/GHSA-ccrh-3x3f-9w29.json b/advisories/unreviewed/2025/04/GHSA-ccrh-3x3f-9w29/GHSA-ccrh-3x3f-9w29.json new file mode 100644 index 00000000000..1358dea90bc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ccrh-3x3f-9w29/GHSA-ccrh-3x3f-9w29.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccrh-3x3f-9w29", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46244" + ], + "details": "Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced Linked Variations for Woocommerce: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46244" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/linked-variation/vulnerability/wordpress-advanced-linked-variations-for-woocommerce-1-0-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cpvv-6mq2-5cpj/GHSA-cpvv-6mq2-5cpj.json b/advisories/unreviewed/2025/04/GHSA-cpvv-6mq2-5cpj/GHSA-cpvv-6mq2-5cpj.json new file mode 100644 index 00000000000..55f04fc027a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cpvv-6mq2-5cpj/GHSA-cpvv-6mq2-5cpj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpvv-6mq2-5cpj", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46236" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms allows Stored XSS. This issue affects HTML Forms: from n/a through 1.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46236" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/html-forms/vulnerability/wordpress-html-forms-1-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-crfx-pgcg-vwwv/GHSA-crfx-pgcg-vwwv.json b/advisories/unreviewed/2025/04/GHSA-crfx-pgcg-vwwv/GHSA-crfx-pgcg-vwwv.json new file mode 100644 index 00000000000..e061a32ec5d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-crfx-pgcg-vwwv/GHSA-crfx-pgcg-vwwv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crfx-pgcg-vwwv", + "modified": "2025-04-22T12:31:22Z", + "published": "2025-04-22T12:31:22Z", + "aliases": [ + "CVE-2025-46225" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Post in page for Elementor allows DOM-Based XSS. This issue affects Post in page for Elementor: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46225" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-in-page-for-elementor/vulnerability/wordpress-post-in-page-for-elementor-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ff9j-c776-v8gw/GHSA-ff9j-c776-v8gw.json b/advisories/unreviewed/2025/04/GHSA-ff9j-c776-v8gw/GHSA-ff9j-c776-v8gw.json new file mode 100644 index 00000000000..566181fc854 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ff9j-c776-v8gw/GHSA-ff9j-c776-v8gw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff9j-c776-v8gw", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46232" + ], + "details": "Missing Authorization vulnerability in alttextai Download Alt Text AI allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Download Alt Text AI: from n/a through 1.9.93.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46232" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/alttext-ai/vulnerability/wordpress-download-alt-text-ai-1-9-93-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fwxv-fxgj-63xv/GHSA-fwxv-fxgj-63xv.json b/advisories/unreviewed/2025/04/GHSA-fwxv-fxgj-63xv/GHSA-fwxv-fxgj-63xv.json new file mode 100644 index 00000000000..545d3b68398 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fwxv-fxgj-63xv/GHSA-fwxv-fxgj-63xv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwxv-fxgj-63xv", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46229" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics allows Stored XSS. This issue affects Textmetrics: from n/a through 3.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46229" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/webtexttool/vulnerability/wordpress-textmetrics-3-6-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g4fm-73wh-j3m8/GHSA-g4fm-73wh-j3m8.json b/advisories/unreviewed/2025/04/GHSA-g4fm-73wh-j3m8/GHSA-g4fm-73wh-j3m8.json new file mode 100644 index 00000000000..67201ca25c1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g4fm-73wh-j3m8/GHSA-g4fm-73wh-j3m8.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4fm-73wh-j3m8", + "modified": "2025-04-22T12:31:24Z", + "published": "2025-04-22T12:31:24Z", + "aliases": [ + "CVE-2025-3472" + ], + "details": "The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3472" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ocean-extra/trunk/includes/shortcodes/shortcodes.php#L618" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3277977" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/74428e76-1946-408f-8adc-24ab4b7e46c5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g8xh-7qqw-v35m/GHSA-g8xh-7qqw-v35m.json b/advisories/unreviewed/2025/04/GHSA-g8xh-7qqw-v35m/GHSA-g8xh-7qqw-v35m.json new file mode 100644 index 00000000000..131488dc477 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g8xh-7qqw-v35m/GHSA-g8xh-7qqw-v35m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8xh-7qqw-v35m", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46240" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter allows Stored XSS. This issue affects Simple Download Counter: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46240" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-download-counter/vulnerability/wordpress-simple-download-counter-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gr97-qmmw-4mf6/GHSA-gr97-qmmw-4mf6.json b/advisories/unreviewed/2025/04/GHSA-gr97-qmmw-4mf6/GHSA-gr97-qmmw-4mf6.json new file mode 100644 index 00000000000..f7fcaf9eb05 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gr97-qmmw-4mf6/GHSA-gr97-qmmw-4mf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr97-qmmw-4mf6", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46250" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Stored XSS. This issue affects VForm: from n/a through 3.1.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46250" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/v-form/vulnerability/wordpress-vform-3-1-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jmxv-f3f6-m6vw/GHSA-jmxv-f3f6-m6vw.json b/advisories/unreviewed/2025/04/GHSA-jmxv-f3f6-m6vw/GHSA-jmxv-f3f6-m6vw.json new file mode 100644 index 00000000000..78360276a9c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jmxv-f3f6-m6vw/GHSA-jmxv-f3f6-m6vw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmxv-f3f6-m6vw", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46249" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor allows Cross Site Request Forgery. This issue affects Simple calendar for Elementor: from n/a through 1.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46249" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-calendar-for-elementor/vulnerability/wordpress-simple-calendar-for-elementor-1-6-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mjj4-vf2r-hmm2/GHSA-mjj4-vf2r-hmm2.json b/advisories/unreviewed/2025/04/GHSA-mjj4-vf2r-hmm2/GHSA-mjj4-vf2r-hmm2.json new file mode 100644 index 00000000000..81f0e0d0011 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mjj4-vf2r-hmm2/GHSA-mjj4-vf2r-hmm2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjj4-vf2r-hmm2", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46254" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder allows Stored XSS. This issue affects Visual Composer Website Builder: from n/a through 45.10.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46254" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/visualcomposer/vulnerability/wordpress-visual-composer-website-builder-plugin-45-10-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mprw-38c7-fpfv/GHSA-mprw-38c7-fpfv.json b/advisories/unreviewed/2025/04/GHSA-mprw-38c7-fpfv/GHSA-mprw-38c7-fpfv.json new file mode 100644 index 00000000000..51e72629494 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mprw-38c7-fpfv/GHSA-mprw-38c7-fpfv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mprw-38c7-fpfv", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46251" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants Table Reservations and Take-Away allows Cross Site Request Forgery. This issue affects VikRestaurants Table Reservations and Take-Away: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46251" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vikrestaurants/vulnerability/wordpress-vikrestaurants-table-reservations-and-take-away-plugin-1-3-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ppp4-2jh7-8hfx/GHSA-ppp4-2jh7-8hfx.json b/advisories/unreviewed/2025/04/GHSA-ppp4-2jh7-8hfx/GHSA-ppp4-2jh7-8hfx.json new file mode 100644 index 00000000000..b48753c8182 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ppp4-2jh7-8hfx/GHSA-ppp4-2jh7-8hfx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppp4-2jh7-8hfx", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46253" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit allows Stored XSS. This issue affects GutenKit: from n/a through 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46253" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gutenkit-blocks-addon/vulnerability/wordpress-gutenkit-plugin-2-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qq89-8329-mrxh/GHSA-qq89-8329-mrxh.json b/advisories/unreviewed/2025/04/GHSA-qq89-8329-mrxh/GHSA-qq89-8329-mrxh.json new file mode 100644 index 00000000000..20d667d4409 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qq89-8329-mrxh/GHSA-qq89-8329-mrxh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq89-8329-mrxh", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46233" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv allows Stored XSS. This issue affects Sirv: from n/a through 7.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46233" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sirv/vulnerability/wordpress-sirv-7-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qqjf-wq8v-xgch/GHSA-qqjf-wq8v-xgch.json b/advisories/unreviewed/2025/04/GHSA-qqjf-wq8v-xgch/GHSA-qqjf-wq8v-xgch.json new file mode 100644 index 00000000000..4320726fc81 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qqjf-wq8v-xgch/GHSA-qqjf-wq8v-xgch.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqjf-wq8v-xgch", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46242" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz allows SQL Injection. This issue affects Watu Quiz: from n/a through 3.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46242" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/watu/vulnerability/wordpress-watu-quiz-3-4-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rv5v-m6qh-69fq/GHSA-rv5v-m6qh-69fq.json b/advisories/unreviewed/2025/04/GHSA-rv5v-m6qh-69fq/GHSA-rv5v-m6qh-69fq.json new file mode 100644 index 00000000000..88d61762b88 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rv5v-m6qh-69fq/GHSA-rv5v-m6qh-69fq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv5v-m6qh-69fq", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46239" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Theme Switcha allows Stored XSS. This issue affects Theme Switcha: from n/a through 3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46239" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/theme-switcha/vulnerability/wordpress-theme-switcha-3-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v53g-6436-39wp/GHSA-v53g-6436-39wp.json b/advisories/unreviewed/2025/04/GHSA-v53g-6436-39wp/GHSA-v53g-6436-39wp.json new file mode 100644 index 00000000000..973cfbcc017 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v53g-6436-39wp/GHSA-v53g-6436-39wp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v53g-6436-39wp", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46238" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer List Last Changes allows Stored XSS. This issue affects List Last Changes: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46238" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/list-last-changes/vulnerability/wordpress-list-last-changes-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v6r8-vw53-vqwp/GHSA-v6r8-vw53-vqwp.json b/advisories/unreviewed/2025/04/GHSA-v6r8-vw53-vqwp/GHSA-v6r8-vw53-vqwp.json new file mode 100644 index 00000000000..a696d0d06eb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v6r8-vw53-vqwp/GHSA-v6r8-vw53-vqwp.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6r8-vw53-vqwp", + "modified": "2025-04-22T12:31:24Z", + "published": "2025-04-22T12:31:24Z", + "aliases": [ + "CVE-2025-3457" + ], + "details": "The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortcode in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3457" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ocean-extra/tags/2.4.5/includes/shortcodes/shortcodes.php#L838" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3277977" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/browser/oceanwp/4.0.6/inc/oceanwp-theme-icons.php#L819" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/browser/oceanwp/4.0.6/inc/oceanwp-theme-icons.php#L866" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/362a01c0-8b97-40dc-8af5-0d904da96576?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v9xw-qh54-24j3/GHSA-v9xw-qh54-24j3.json b/advisories/unreviewed/2025/04/GHSA-v9xw-qh54-24j3/GHSA-v9xw-qh54-24j3.json new file mode 100644 index 00000000000..b81805fc767 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v9xw-qh54-24j3/GHSA-v9xw-qh54-24j3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9xw-qh54-24j3", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46247" + ], + "details": "Missing Authorization vulnerability in codepeople Appointment Booking Calendar allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Appointment Booking Calendar: from n/a through 1.3.92.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46247" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/appointment-booking-calendar/vulnerability/wordpress-appointment-booking-calendar-1-3-92-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xm7m-4vx5-9ww4/GHSA-xm7m-4vx5-9ww4.json b/advisories/unreviewed/2025/04/GHSA-xm7m-4vx5-9ww4/GHSA-xm7m-4vx5-9ww4.json new file mode 100644 index 00000000000..21d4862e7b2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xm7m-4vx5-9ww4/GHSA-xm7m-4vx5-9ww4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm7m-4vx5-9ww4", + "modified": "2025-04-22T12:31:23Z", + "published": "2025-04-22T12:31:23Z", + "aliases": [ + "CVE-2025-46245" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer allows Cross Site Request Forgery. This issue affects CM Ad Changer: from n/a through 2.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46245" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cm-ad-changer/vulnerability/wordpress-cm-ad-changer-2-0-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-22T10:15:18Z" + } +} \ No newline at end of file