From f4939128f4d8bd79dff56c9f80d6773ae5ac0d4e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 26 Mar 2025 12:32:02 +0000 Subject: [PATCH] Publish Advisories GHSA-22wf-h889-r7q7 GHSA-46f3-rc2x-p4jv GHSA-4c69-v677-qpvh GHSA-79v6-3rr4-h2q4 GHSA-7p7m-q926-gvc3 GHSA-7pgw-44rh-62wc GHSA-8h4g-52x5-5r4v GHSA-8qpj-ggqr-96fp GHSA-9m8m-6289-mfmf GHSA-9x23-xcrx-fq3q GHSA-c27w-wj98-h63p GHSA-cjm8-5v4m-pvxc GHSA-f4hc-mpg9-vm8w GHSA-jx2h-xcqm-jgfh GHSA-qw2f-592p-2xm4 GHSA-wpp5-gj35-j435 GHSA-xp6c-m5c6-ffrg --- .../GHSA-22wf-h889-r7q7.json | 40 +++++++++++++ .../GHSA-46f3-rc2x-p4jv.json | 35 ++++++++++++ .../GHSA-4c69-v677-qpvh.json | 40 +++++++++++++ .../GHSA-79v6-3rr4-h2q4.json | 48 ++++++++++++++++ .../GHSA-7p7m-q926-gvc3.json | 48 ++++++++++++++++ .../GHSA-7pgw-44rh-62wc.json | 44 +++++++++++++++ .../GHSA-8h4g-52x5-5r4v.json | 48 ++++++++++++++++ .../GHSA-8qpj-ggqr-96fp.json | 56 +++++++++++++++++++ .../GHSA-9m8m-6289-mfmf.json | 48 ++++++++++++++++ .../GHSA-9x23-xcrx-fq3q.json | 35 ++++++++++++ .../GHSA-c27w-wj98-h63p.json | 56 +++++++++++++++++++ .../GHSA-cjm8-5v4m-pvxc.json | 40 +++++++++++++ .../GHSA-f4hc-mpg9-vm8w.json | 36 ++++++++++++ .../GHSA-jx2h-xcqm-jgfh.json | 48 ++++++++++++++++ .../GHSA-qw2f-592p-2xm4.json | 40 +++++++++++++ .../GHSA-wpp5-gj35-j435.json | 44 +++++++++++++++ .../GHSA-xp6c-m5c6-ffrg.json | 52 +++++++++++++++++ 17 files changed, 758 insertions(+) create mode 100644 advisories/unreviewed/2025/03/GHSA-22wf-h889-r7q7/GHSA-22wf-h889-r7q7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-46f3-rc2x-p4jv/GHSA-46f3-rc2x-p4jv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4c69-v677-qpvh/GHSA-4c69-v677-qpvh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-79v6-3rr4-h2q4/GHSA-79v6-3rr4-h2q4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7p7m-q926-gvc3/GHSA-7p7m-q926-gvc3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7pgw-44rh-62wc/GHSA-7pgw-44rh-62wc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8h4g-52x5-5r4v/GHSA-8h4g-52x5-5r4v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8qpj-ggqr-96fp/GHSA-8qpj-ggqr-96fp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9m8m-6289-mfmf/GHSA-9m8m-6289-mfmf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9x23-xcrx-fq3q/GHSA-9x23-xcrx-fq3q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c27w-wj98-h63p/GHSA-c27w-wj98-h63p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cjm8-5v4m-pvxc/GHSA-cjm8-5v4m-pvxc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f4hc-mpg9-vm8w/GHSA-f4hc-mpg9-vm8w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jx2h-xcqm-jgfh/GHSA-jx2h-xcqm-jgfh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qw2f-592p-2xm4/GHSA-qw2f-592p-2xm4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wpp5-gj35-j435/GHSA-wpp5-gj35-j435.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xp6c-m5c6-ffrg/GHSA-xp6c-m5c6-ffrg.json diff --git a/advisories/unreviewed/2025/03/GHSA-22wf-h889-r7q7/GHSA-22wf-h889-r7q7.json b/advisories/unreviewed/2025/03/GHSA-22wf-h889-r7q7/GHSA-22wf-h889-r7q7.json new file mode 100644 index 00000000000..f4bcc41251a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-22wf-h889-r7q7/GHSA-22wf-h889-r7q7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22wf-h889-r7q7", + "modified": "2025-03-26T12:30:34Z", + "published": "2025-03-26T12:30:34Z", + "aliases": [ + "CVE-2025-1542" + ], + "details": "Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects OXARI ServiceDesk in versions before 2.0.324.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1542" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/03/CVE-2025-1542" + }, + { + "type": "WEB", + "url": "https://www.oxari.com/en/product/oxari-servicedesk" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T11:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-46f3-rc2x-p4jv/GHSA-46f3-rc2x-p4jv.json b/advisories/unreviewed/2025/03/GHSA-46f3-rc2x-p4jv/GHSA-46f3-rc2x-p4jv.json new file mode 100644 index 00000000000..7d5f33896fc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-46f3-rc2x-p4jv/GHSA-46f3-rc2x-p4jv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46f3-rc2x-p4jv", + "modified": "2025-03-26T12:30:34Z", + "published": "2025-03-26T12:30:33Z", + "aliases": [ + "CVE-2025-27551" + ], + "details": "DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes.\n\nThis vulnerability is associated with program files lib/DBIx/Class/EncodedColumn/Digest.pm.\n\nThis issue affects DBIx::Class::EncodedColumn until 0.00032.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27551" + }, + { + "type": "WEB", + "url": "https://metacpan.org/release/WREIS/DBIx-Class-EncodedColumn-0.00032/changes" + }, + { + "type": "WEB", + "url": "https://security.metacpan.org/docs/guides/random-data-for-security.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-338" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T11:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4c69-v677-qpvh/GHSA-4c69-v677-qpvh.json b/advisories/unreviewed/2025/03/GHSA-4c69-v677-qpvh/GHSA-4c69-v677-qpvh.json new file mode 100644 index 00000000000..0ef49f7569c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4c69-v677-qpvh/GHSA-4c69-v677-qpvh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c69-v677-qpvh", + "modified": "2025-03-26T12:30:33Z", + "published": "2025-03-26T12:30:33Z", + "aliases": [ + "CVE-2025-1437" + ], + "details": "The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1437" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3255604%40advanced-iframe&new=3255604%40advanced-iframe&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/676b4768-98ea-4e55-87de-ef7ae1d7a113?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-79v6-3rr4-h2q4/GHSA-79v6-3rr4-h2q4.json b/advisories/unreviewed/2025/03/GHSA-79v6-3rr4-h2q4/GHSA-79v6-3rr4-h2q4.json new file mode 100644 index 00000000000..201aa7355b4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-79v6-3rr4-h2q4/GHSA-79v6-3rr4-h2q4.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79v6-3rr4-h2q4", + "modified": "2025-03-26T12:30:35Z", + "published": "2025-03-26T12:30:35Z", + "aliases": [ + "CVE-2025-1912" + ], + "details": "The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the validate_file() Function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1912" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/product-import-export-for-woo/trunk/admin/modules/import/classes/class-import-ajax.php#L175" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3261194" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/product-import-export-for-woo/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/406b52dc-3d36-4b03-a932-34f456395979?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7p7m-q926-gvc3/GHSA-7p7m-q926-gvc3.json b/advisories/unreviewed/2025/03/GHSA-7p7m-q926-gvc3/GHSA-7p7m-q926-gvc3.json new file mode 100644 index 00000000000..f597e2628b7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7p7m-q926-gvc3/GHSA-7p7m-q926-gvc3.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p7m-q926-gvc3", + "modified": "2025-03-26T12:30:34Z", + "published": "2025-03-26T12:30:34Z", + "aliases": [ + "CVE-2025-1769" + ], + "details": "The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1769" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/product-import-export-for-woo/trunk/admin/modules/history/history.php#L753" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3261194" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/product-import-export-for-woo/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4df60fbe-4475-4cbf-b497-a9c5251bc91f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7pgw-44rh-62wc/GHSA-7pgw-44rh-62wc.json b/advisories/unreviewed/2025/03/GHSA-7pgw-44rh-62wc/GHSA-7pgw-44rh-62wc.json new file mode 100644 index 00000000000..4a0ed594797 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7pgw-44rh-62wc/GHSA-7pgw-44rh-62wc.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pgw-44rh-62wc", + "modified": "2025-03-26T12:30:33Z", + "published": "2025-03-26T12:30:33Z", + "aliases": [ + "CVE-2025-1310" + ], + "details": "The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.7.11 via the 'job_postings_get_file' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1310" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/job-postings/tags/2.7.11/include/class-job-get-uploaded-file.php#L91" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3257145%40job-postings&new=3257145%40job-postings&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/408312d3-9a9e-4b6b-9991-aee6b77745b2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8h4g-52x5-5r4v/GHSA-8h4g-52x5-5r4v.json b/advisories/unreviewed/2025/03/GHSA-8h4g-52x5-5r4v/GHSA-8h4g-52x5-5r4v.json new file mode 100644 index 00000000000..ebff9258783 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8h4g-52x5-5r4v/GHSA-8h4g-52x5-5r4v.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h4g-52x5-5r4v", + "modified": "2025-03-26T12:30:35Z", + "published": "2025-03-26T12:30:35Z", + "aliases": [ + "CVE-2025-1913" + ], + "details": "The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via deserialization of untrusted input from the 'form_data' parameter This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1913" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/product-import-export-for-woo/trunk/admin/modules/import/classes/class-import-ajax.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3261194" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/product-import-export-for-woo/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d4464bb1-273a-42c4-a7ec-8e123d286963?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8qpj-ggqr-96fp/GHSA-8qpj-ggqr-96fp.json b/advisories/unreviewed/2025/03/GHSA-8qpj-ggqr-96fp/GHSA-8qpj-ggqr-96fp.json new file mode 100644 index 00000000000..88ecf164255 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8qpj-ggqr-96fp/GHSA-8qpj-ggqr-96fp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qpj-ggqr-96fp", + "modified": "2025-03-26T12:30:34Z", + "published": "2025-03-26T12:30:34Z", + "aliases": [ + "CVE-2024-13411" + ], + "details": "The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5.1 via the updated_user() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13411" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/zapier/trunk/zapier.php#L114" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/zapier/trunk/zapier.php#L210" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/zapier/trunk/zapier.php#L284" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3257975" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/zapier/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/701dc461-88e7-40bf-a4fb-f92723b6e05e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9m8m-6289-mfmf/GHSA-9m8m-6289-mfmf.json b/advisories/unreviewed/2025/03/GHSA-9m8m-6289-mfmf/GHSA-9m8m-6289-mfmf.json new file mode 100644 index 00000000000..a32410f9fd9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9m8m-6289-mfmf/GHSA-9m8m-6289-mfmf.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m8m-6289-mfmf", + "modified": "2025-03-26T12:30:34Z", + "published": "2025-03-26T12:30:34Z", + "aliases": [ + "CVE-2025-1911" + ], + "details": "The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.5.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary log files on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1911" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/product-import-export-for-woo/trunk/admin/modules/history/history.php#L248" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3261194" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/product-import-export-for-woo/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d222ef6d-cdec-482e-92ba-65eeabbcdeae?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9x23-xcrx-fq3q/GHSA-9x23-xcrx-fq3q.json b/advisories/unreviewed/2025/03/GHSA-9x23-xcrx-fq3q/GHSA-9x23-xcrx-fq3q.json new file mode 100644 index 00000000000..15790bb3217 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9x23-xcrx-fq3q/GHSA-9x23-xcrx-fq3q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x23-xcrx-fq3q", + "modified": "2025-03-26T12:30:34Z", + "published": "2025-03-26T12:30:34Z", + "aliases": [ + "CVE-2025-27552" + ], + "details": "DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes.\n\nThis vulnerability is associated with program files Crypt/Eksblowfish/Bcrypt.pm.\n\nThis issue affects DBIx::Class::EncodedColumn until 0.00032.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27552" + }, + { + "type": "WEB", + "url": "https://metacpan.org/release/WREIS/DBIx-Class-EncodedColumn-0.00032/changes" + }, + { + "type": "WEB", + "url": "https://security.metacpan.org/docs/guides/random-data-for-security.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-338" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T11:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c27w-wj98-h63p/GHSA-c27w-wj98-h63p.json b/advisories/unreviewed/2025/03/GHSA-c27w-wj98-h63p/GHSA-c27w-wj98-h63p.json new file mode 100644 index 00000000000..f48637a0938 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c27w-wj98-h63p/GHSA-c27w-wj98-h63p.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c27w-wj98-h63p", + "modified": "2025-03-26T12:30:34Z", + "published": "2025-03-26T12:30:34Z", + "aliases": [ + "CVE-2024-13889" + ], + "details": "The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of untrusted input in the 'maybe_unserialize' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13889" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wordpress-importer/trunk/class-wp-import.php#L602" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wordpress-importer/trunk/class-wp-import.php#L857" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wordpress-importer/trunk/class-wp-import.php#L891" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wordpress-importer/trunk/class-wp-import.php#L975" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3261419" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5f0795f7-6eba-4ff0-b0da-5d2b544adf14?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cjm8-5v4m-pvxc/GHSA-cjm8-5v4m-pvxc.json b/advisories/unreviewed/2025/03/GHSA-cjm8-5v4m-pvxc/GHSA-cjm8-5v4m-pvxc.json new file mode 100644 index 00000000000..403cf887088 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cjm8-5v4m-pvxc/GHSA-cjm8-5v4m-pvxc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjm8-5v4m-pvxc", + "modified": "2025-03-26T12:30:33Z", + "published": "2025-03-26T12:30:33Z", + "aliases": [ + "CVE-2025-1440" + ], + "details": "The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option with an excessive amount of unvalidated data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1440" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3255604%40advanced-iframe&new=3255604%40advanced-iframe&sfp_email=&sfph_mail=#file1" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b92913fa-aa1e-40a0-9a48-d730b2102217?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f4hc-mpg9-vm8w/GHSA-f4hc-mpg9-vm8w.json b/advisories/unreviewed/2025/03/GHSA-f4hc-mpg9-vm8w/GHSA-f4hc-mpg9-vm8w.json new file mode 100644 index 00000000000..34b7766c841 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f4hc-mpg9-vm8w/GHSA-f4hc-mpg9-vm8w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4hc-mpg9-vm8w", + "modified": "2025-03-26T12:30:34Z", + "published": "2025-03-26T12:30:34Z", + "aliases": [ + "CVE-2025-2596" + ], + "details": "Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL)", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2596" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17808" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T11:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jx2h-xcqm-jgfh/GHSA-jx2h-xcqm-jgfh.json b/advisories/unreviewed/2025/03/GHSA-jx2h-xcqm-jgfh/GHSA-jx2h-xcqm-jgfh.json new file mode 100644 index 00000000000..cba440a877e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jx2h-xcqm-jgfh/GHSA-jx2h-xcqm-jgfh.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx2h-xcqm-jgfh", + "modified": "2025-03-26T12:30:34Z", + "published": "2025-03-26T12:30:34Z", + "aliases": [ + "CVE-2025-2110" + ], + "details": "The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on its on its AJAX functions in all versions up to, and including, 6.30.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to compromise the site in various ways depending on the specific function exploited - for example, by retrieving sensitive settings and configuration details, or by altering and deleting them, thereby disclosing sensitive information, disrupting the plugin’s functionality, and potentially impacting overall site performance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2110" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-compress-image-optimizer/tags/6.30.15/classes/ajax.class.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3254259" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-compress-image-optimizer/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2bb4ead4-b2ad-42b4-92a0-fb7293f6df06?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qw2f-592p-2xm4/GHSA-qw2f-592p-2xm4.json b/advisories/unreviewed/2025/03/GHSA-qw2f-592p-2xm4/GHSA-qw2f-592p-2xm4.json new file mode 100644 index 00000000000..4c3384dcc40 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qw2f-592p-2xm4/GHSA-qw2f-592p-2xm4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw2f-592p-2xm4", + "modified": "2025-03-26T12:30:33Z", + "published": "2025-03-26T12:30:33Z", + "aliases": [ + "CVE-2025-1439" + ], + "details": "The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due to insufficient input sanitization and output escaping on user supplied attributes through the 'src' attribute when the src supplied returns a header with an injected value . This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1439" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3255604%40advanced-iframe&new=3255604%40advanced-iframe&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5ac1145b-5ab1-47a9-9117-4870c52a70fc?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wpp5-gj35-j435/GHSA-wpp5-gj35-j435.json b/advisories/unreviewed/2025/03/GHSA-wpp5-gj35-j435/GHSA-wpp5-gj35-j435.json new file mode 100644 index 00000000000..c5c3b97860b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wpp5-gj35-j435/GHSA-wpp5-gj35-j435.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpp5-gj35-j435", + "modified": "2025-03-26T12:30:34Z", + "published": "2025-03-26T12:30:34Z", + "aliases": [ + "CVE-2025-1312" + ], + "details": "The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttonTextColor’ parameter in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1312" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ultimate-blocks/trunk/src/blocks/call-to-action/block.php#L32" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3260377" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ac422162-be05-4420-9877-d6d41b83e881?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xp6c-m5c6-ffrg/GHSA-xp6c-m5c6-ffrg.json b/advisories/unreviewed/2025/03/GHSA-xp6c-m5c6-ffrg/GHSA-xp6c-m5c6-ffrg.json new file mode 100644 index 00000000000..09ad09ac462 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xp6c-m5c6-ffrg/GHSA-xp6c-m5c6-ffrg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp6c-m5c6-ffrg", + "modified": "2025-03-26T12:30:33Z", + "published": "2025-03-26T12:30:33Z", + "aliases": [ + "CVE-2025-1703" + ], + "details": "The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1703" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ultimate-blocks/trunk/src/extensions/responsive-control/class-responsive-control.php#L46" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3260377" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3260377/ultimate-blocks/trunk/src/extensions/responsive-control/class-responsive-control.php" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/ultimate-blocks/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a2520d98-3cee-4431-bf9c-b2fd01a584ce?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T10:15:15Z" + } +} \ No newline at end of file