From f71dfc0bf305283b6e22f7ab78278288bf5ead8f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 11 Apr 2024 15:32:16 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-g93r-rwcj-f35x.json | 7 ++- .../GHSA-mhr4-7h64-3vv5.json | 7 ++- .../GHSA-w5j4-gmch-jg5m.json | 11 ++-- .../GHSA-2pjw-f3qx-4fv2.json | 38 +++++++++++++ .../GHSA-3rq5-2g8h-59hc.json | 55 +++++++++++++++++++ .../GHSA-434v-9hrw-chfc.json | 38 +++++++++++++ .../GHSA-4hm5-5hxv-2486.json | 38 +++++++++++++ .../GHSA-64cr-7hgf-2vwv.json | 38 +++++++++++++ .../GHSA-6854-3fp5-fh9h.json | 38 +++++++++++++ .../GHSA-8gjp-676p-q8hj.json | 38 +++++++++++++ .../GHSA-9643-83mc-pxhh.json | 38 +++++++++++++ .../GHSA-98g9-33hv-jcxp.json | 38 +++++++++++++ .../GHSA-cv7f-2rm4-44r9.json | 38 +++++++++++++ .../GHSA-cwg6-2p35-rmg5.json | 38 +++++++++++++ .../GHSA-fv77-v4vq-cvm5.json | 38 +++++++++++++ .../GHSA-g539-33wv-mrqf.json | 38 +++++++++++++ .../GHSA-h322-r32h-qf8x.json | 38 +++++++++++++ .../GHSA-jrp9-fp9p-gf9q.json | 38 +++++++++++++ .../GHSA-mh57-xhqm-mxp9.json | 38 +++++++++++++ .../GHSA-p788-3h6g-7p3f.json | 38 +++++++++++++ .../GHSA-q846-3fgc-qhjr.json | 38 +++++++++++++ .../GHSA-r5vj-hjx4-mp69.json | 38 +++++++++++++ .../GHSA-v8pw-v275-vxvw.json | 38 +++++++++++++ .../GHSA-vj6v-pg66-4f9j.json | 38 +++++++++++++ .../GHSA-x6x2-3r7p-w8cx.json | 38 +++++++++++++ 25 files changed, 870 insertions(+), 8 deletions(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-2pjw-f3qx-4fv2/GHSA-2pjw-f3qx-4fv2.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3rq5-2g8h-59hc/GHSA-3rq5-2g8h-59hc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-434v-9hrw-chfc/GHSA-434v-9hrw-chfc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4hm5-5hxv-2486/GHSA-4hm5-5hxv-2486.json create mode 100644 advisories/unreviewed/2024/04/GHSA-64cr-7hgf-2vwv/GHSA-64cr-7hgf-2vwv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6854-3fp5-fh9h/GHSA-6854-3fp5-fh9h.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8gjp-676p-q8hj/GHSA-8gjp-676p-q8hj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9643-83mc-pxhh/GHSA-9643-83mc-pxhh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-98g9-33hv-jcxp/GHSA-98g9-33hv-jcxp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cv7f-2rm4-44r9/GHSA-cv7f-2rm4-44r9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-cwg6-2p35-rmg5/GHSA-cwg6-2p35-rmg5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-fv77-v4vq-cvm5/GHSA-fv77-v4vq-cvm5.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g539-33wv-mrqf/GHSA-g539-33wv-mrqf.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h322-r32h-qf8x/GHSA-h322-r32h-qf8x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jrp9-fp9p-gf9q/GHSA-jrp9-fp9p-gf9q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mh57-xhqm-mxp9/GHSA-mh57-xhqm-mxp9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p788-3h6g-7p3f/GHSA-p788-3h6g-7p3f.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q846-3fgc-qhjr/GHSA-q846-3fgc-qhjr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-r5vj-hjx4-mp69/GHSA-r5vj-hjx4-mp69.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v8pw-v275-vxvw/GHSA-v8pw-v275-vxvw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vj6v-pg66-4f9j/GHSA-vj6v-pg66-4f9j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-x6x2-3r7p-w8cx/GHSA-x6x2-3r7p-w8cx.json diff --git a/advisories/unreviewed/2022/05/GHSA-g93r-rwcj-f35x/GHSA-g93r-rwcj-f35x.json b/advisories/unreviewed/2022/05/GHSA-g93r-rwcj-f35x/GHSA-g93r-rwcj-f35x.json index 7a9713cbea6..5e78dae76dc 100644 --- a/advisories/unreviewed/2022/05/GHSA-g93r-rwcj-f35x/GHSA-g93r-rwcj-f35x.json +++ b/advisories/unreviewed/2022/05/GHSA-g93r-rwcj-f35x/GHSA-g93r-rwcj-f35x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g93r-rwcj-f35x", - "modified": "2022-05-24T17:39:12Z", + "modified": "2024-04-11T15:30:43Z", "published": "2022-05-24T17:39:12Z", "aliases": [ "CVE-2021-1311" ], "details": "A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute forcing of the host key. An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Webex Meetings Server site. A successful exploit would require the attacker to have access to join a Webex meeting, including applicable meeting join links and passwords. A successful exploit could allow the attacker to acquire or take over the host role for a meeting.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-mhr4-7h64-3vv5/GHSA-mhr4-7h64-3vv5.json b/advisories/unreviewed/2022/05/GHSA-mhr4-7h64-3vv5/GHSA-mhr4-7h64-3vv5.json index d41c9e086db..035cf9526e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-mhr4-7h64-3vv5/GHSA-mhr4-7h64-3vv5.json +++ b/advisories/unreviewed/2022/05/GHSA-mhr4-7h64-3vv5/GHSA-mhr4-7h64-3vv5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhr4-7h64-3vv5", - "modified": "2022-05-24T17:39:12Z", + "modified": "2024-04-11T15:30:43Z", "published": "2022-05-24T17:39:12Z", "aliases": [ "CVE-2021-1310" ], "details": "A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page, bypassing the warning mechanism that should prompt the user before the redirection. This vulnerability is due to improper input validation of the URL parameters in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website, bypassing the Webex URL check that should result in a warning before the redirection to the web page. Attackers may use this type of vulnerability, known as an open redirect attack, as part of a phishing attack to convince users to unknowingly visit malicious sites.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2024/02/GHSA-w5j4-gmch-jg5m/GHSA-w5j4-gmch-jg5m.json b/advisories/unreviewed/2024/02/GHSA-w5j4-gmch-jg5m/GHSA-w5j4-gmch-jg5m.json index 9da7971815a..6c4b6febcba 100644 --- a/advisories/unreviewed/2024/02/GHSA-w5j4-gmch-jg5m/GHSA-w5j4-gmch-jg5m.json +++ b/advisories/unreviewed/2024/02/GHSA-w5j4-gmch-jg5m/GHSA-w5j4-gmch-jg5m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w5j4-gmch-jg5m", - "modified": "2024-02-17T06:30:36Z", + "modified": "2024-04-11T15:30:44Z", "published": "2024-02-17T06:30:36Z", "aliases": [ "CVE-2024-25297" ], "details": "Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain sensitive information via edit-content.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-17T06:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2pjw-f3qx-4fv2/GHSA-2pjw-f3qx-4fv2.json b/advisories/unreviewed/2024/04/GHSA-2pjw-f3qx-4fv2/GHSA-2pjw-f3qx-4fv2.json new file mode 100644 index 00000000000..5b2a655303d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2pjw-f3qx-4fv2/GHSA-2pjw-f3qx-4fv2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pjw-f3qx-4fv2", + "modified": "2024-04-11T15:30:47Z", + "published": "2024-04-11T15:30:47Z", + "aliases": [ + "CVE-2024-31925" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FAKTOR VIER F4 Improvements allows Stored XSS.This issue affects F4 Improvements: from n/a through 1.8.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31925" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/f4-improvements/wordpress-f4-improvements-plugin-1-8-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3rq5-2g8h-59hc/GHSA-3rq5-2g8h-59hc.json b/advisories/unreviewed/2024/04/GHSA-3rq5-2g8h-59hc/GHSA-3rq5-2g8h-59hc.json new file mode 100644 index 00000000000..dfaadae302b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3rq5-2g8h-59hc/GHSA-3rq5-2g8h-59hc.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rq5-2g8h-59hc", + "modified": "2024-04-11T15:30:48Z", + "published": "2024-04-11T15:30:48Z", + "aliases": [ + "CVE-2023-29483" + ], + "details": "eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a \"TuDoor\" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29483" + }, + { + "type": "WEB", + "url": "https://github.com/eventlet/eventlet/issues/913" + }, + { + "type": "WEB", + "url": "https://github.com/rthalley/dnspython/issues/1045" + }, + { + "type": "WEB", + "url": "https://github.com/eventlet/eventlet/releases/tag/v0.35.2" + }, + { + "type": "WEB", + "url": "https://github.com/rthalley/dnspython/releases/tag/v2.6.0" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713" + }, + { + "type": "WEB", + "url": "https://www.dnspython.org" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-434v-9hrw-chfc/GHSA-434v-9hrw-chfc.json b/advisories/unreviewed/2024/04/GHSA-434v-9hrw-chfc/GHSA-434v-9hrw-chfc.json new file mode 100644 index 00000000000..87ca16f2080 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-434v-9hrw-chfc/GHSA-434v-9hrw-chfc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-434v-9hrw-chfc", + "modified": "2024-04-11T15:30:48Z", + "published": "2024-04-11T15:30:48Z", + "aliases": [ + "CVE-2024-31935" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in BracketSpace Simple Post Notes.This issue affects Simple Post Notes: from n/a through 1.7.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31935" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-post-notes/wordpress-simple-post-notes-plugin-1-7-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4hm5-5hxv-2486/GHSA-4hm5-5hxv-2486.json b/advisories/unreviewed/2024/04/GHSA-4hm5-5hxv-2486/GHSA-4hm5-5hxv-2486.json new file mode 100644 index 00000000000..be33afce2e8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4hm5-5hxv-2486/GHSA-4hm5-5hxv-2486.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hm5-5hxv-2486", + "modified": "2024-04-11T15:30:47Z", + "published": "2024-04-11T15:30:47Z", + "aliases": [ + "CVE-2024-31932" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy Companion.This issue affects Blocksy Companion: from n/a through 2.0.28.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31932" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/blocksy-companion/wordpress-blocksy-companion-plugin-2-0-28-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-64cr-7hgf-2vwv/GHSA-64cr-7hgf-2vwv.json b/advisories/unreviewed/2024/04/GHSA-64cr-7hgf-2vwv/GHSA-64cr-7hgf-2vwv.json new file mode 100644 index 00000000000..8fb7d3d3d2c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-64cr-7hgf-2vwv/GHSA-64cr-7hgf-2vwv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64cr-7hgf-2vwv", + "modified": "2024-04-11T15:30:48Z", + "published": "2024-04-11T15:30:48Z", + "aliases": [ + "CVE-2024-32105" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ELEXtensions ELEX WooCommerce Dynamic Pricing and Discounts.This issue affects ELEX WooCommerce Dynamic Pricing and Discounts: from n/a through 2.1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32105" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/elex-woocommerce-dynamic-pricing-and-discounts/wordpress-elex-woocommerce-dynamic-pricing-and-discounts-plugin-2-1-2-cross-site-request-forgery-csrf-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6854-3fp5-fh9h/GHSA-6854-3fp5-fh9h.json b/advisories/unreviewed/2024/04/GHSA-6854-3fp5-fh9h/GHSA-6854-3fp5-fh9h.json new file mode 100644 index 00000000000..9b67f2f31f2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6854-3fp5-fh9h/GHSA-6854-3fp5-fh9h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6854-3fp5-fh9h", + "modified": "2024-04-11T15:30:47Z", + "published": "2024-04-11T15:30:47Z", + "aliases": [ + "CVE-2024-31934" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.6.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31934" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/link-whisper/wordpress-link-whisper-free-plugin-0-6-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8gjp-676p-q8hj/GHSA-8gjp-676p-q8hj.json b/advisories/unreviewed/2024/04/GHSA-8gjp-676p-q8hj/GHSA-8gjp-676p-q8hj.json new file mode 100644 index 00000000000..c0f282c9832 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8gjp-676p-q8hj/GHSA-8gjp-676p-q8hj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gjp-676p-q8hj", + "modified": "2024-04-11T15:30:48Z", + "published": "2024-04-11T15:30:48Z", + "aliases": [ + "CVE-2024-32108" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Stephanie Leary Convert Post Types.This issue affects Convert Post Types: from n/a through 1.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32108" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/convert-post-types/wordpress-convert-post-types-plugin-1-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9643-83mc-pxhh/GHSA-9643-83mc-pxhh.json b/advisories/unreviewed/2024/04/GHSA-9643-83mc-pxhh/GHSA-9643-83mc-pxhh.json new file mode 100644 index 00000000000..e99d380ccf1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9643-83mc-pxhh/GHSA-9643-83mc-pxhh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9643-83mc-pxhh", + "modified": "2024-04-11T15:30:45Z", + "published": "2024-04-11T15:30:45Z", + "aliases": [ + "CVE-2024-31285" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tooltip WordPress Tooltips allows Stored XSS.This issue affects WordPress Tooltips: from n/a through 9.5.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31285" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wordpress-tooltips/wordpress-wordpress-tooltips-plugin-9-5-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-98g9-33hv-jcxp/GHSA-98g9-33hv-jcxp.json b/advisories/unreviewed/2024/04/GHSA-98g9-33hv-jcxp/GHSA-98g9-33hv-jcxp.json new file mode 100644 index 00000000000..e7905d16e8a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-98g9-33hv-jcxp/GHSA-98g9-33hv-jcxp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98g9-33hv-jcxp", + "modified": "2024-04-11T15:30:47Z", + "published": "2024-04-11T15:30:47Z", + "aliases": [ + "CVE-2024-31928" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Darko Top Bar allows Stored XSS.This issue affects Top Bar: from n/a through 3.0.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31928" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/top-bar/wordpress-top-bar-plugin-3-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cv7f-2rm4-44r9/GHSA-cv7f-2rm4-44r9.json b/advisories/unreviewed/2024/04/GHSA-cv7f-2rm4-44r9/GHSA-cv7f-2rm4-44r9.json new file mode 100644 index 00000000000..8996ac6c2c4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cv7f-2rm4-44r9/GHSA-cv7f-2rm4-44r9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv7f-2rm4-44r9", + "modified": "2024-04-11T15:30:48Z", + "published": "2024-04-11T15:30:47Z", + "aliases": [ + "CVE-2024-31931" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Save as Image plugin by Pdfcrowd allows Stored XSS.This issue affects Save as Image plugin by Pdfcrowd: from n/a through 3.2.1 .\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31931" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/save-as-image-by-pdfcrowd/wordpress-save-as-image-plugin-by-pdfcrowd-plugin-3-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cwg6-2p35-rmg5/GHSA-cwg6-2p35-rmg5.json b/advisories/unreviewed/2024/04/GHSA-cwg6-2p35-rmg5/GHSA-cwg6-2p35-rmg5.json new file mode 100644 index 00000000000..3534307314f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cwg6-2p35-rmg5/GHSA-cwg6-2p35-rmg5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwg6-2p35-rmg5", + "modified": "2024-04-11T15:30:47Z", + "published": "2024-04-11T15:30:47Z", + "aliases": [ + "CVE-2024-31930" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Stored XSS.This issue affects Save as PDF plugin by Pdfcrowd: from n/a through 3.2.1 .\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31930" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/save-as-pdf-by-pdfcrowd/wordpress-save-as-pdf-by-pdfcrowd-plugin-3-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fv77-v4vq-cvm5/GHSA-fv77-v4vq-cvm5.json b/advisories/unreviewed/2024/04/GHSA-fv77-v4vq-cvm5/GHSA-fv77-v4vq-cvm5.json new file mode 100644 index 00000000000..6a606e36e35 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fv77-v4vq-cvm5/GHSA-fv77-v4vq-cvm5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv77-v4vq-cvm5", + "modified": "2024-04-11T15:30:46Z", + "published": "2024-04-11T15:30:46Z", + "aliases": [ + "CVE-2024-31387" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup LikeBox Team Popup Like box allows Stored XSS.This issue affects Popup Like box: from n/a through 3.7.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31387" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ays-facebook-popup-likebox/wordpress-popup-likebox-plugin-3-7-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g539-33wv-mrqf/GHSA-g539-33wv-mrqf.json b/advisories/unreviewed/2024/04/GHSA-g539-33wv-mrqf/GHSA-g539-33wv-mrqf.json new file mode 100644 index 00000000000..c6a7d103cb9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g539-33wv-mrqf/GHSA-g539-33wv-mrqf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g539-33wv-mrqf", + "modified": "2024-04-11T15:30:48Z", + "published": "2024-04-11T15:30:48Z", + "aliases": [ + "CVE-2024-31936" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a before 1.2.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31936" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/userswp/wordpress-userswp-front-end-login-form-user-registration-user-profile-members-directory-plugin-for-wordpress-plugin-1-2-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h322-r32h-qf8x/GHSA-h322-r32h-qf8x.json b/advisories/unreviewed/2024/04/GHSA-h322-r32h-qf8x/GHSA-h322-r32h-qf8x.json new file mode 100644 index 00000000000..14a0533924f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h322-r32h-qf8x/GHSA-h322-r32h-qf8x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h322-r32h-qf8x", + "modified": "2024-04-11T15:30:47Z", + "published": "2024-04-11T15:30:47Z", + "aliases": [ + "CVE-2024-31929" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Polevaultweb Intagrate Lite allows Stored XSS.This issue affects Intagrate Lite: from n/a through 1.3.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31929" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/instagrate-to-wordpress/wordpress-intagrate-lite-plugin-1-3-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jrp9-fp9p-gf9q/GHSA-jrp9-fp9p-gf9q.json b/advisories/unreviewed/2024/04/GHSA-jrp9-fp9p-gf9q/GHSA-jrp9-fp9p-gf9q.json new file mode 100644 index 00000000000..71e5e328304 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jrp9-fp9p-gf9q/GHSA-jrp9-fp9p-gf9q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrp9-fp9p-gf9q", + "modified": "2024-04-11T15:30:48Z", + "published": "2024-04-11T15:30:48Z", + "aliases": [ + "CVE-2024-32083" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Varun Kumar Easy Logo allows Stored XSS.This issue affects Easy Logo: from n/a through 1.9.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32083" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easylogo/wordpress-easy-logo-plugin-1-9-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mh57-xhqm-mxp9/GHSA-mh57-xhqm-mxp9.json b/advisories/unreviewed/2024/04/GHSA-mh57-xhqm-mxp9/GHSA-mh57-xhqm-mxp9.json new file mode 100644 index 00000000000..461652483da --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mh57-xhqm-mxp9/GHSA-mh57-xhqm-mxp9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh57-xhqm-mxp9", + "modified": "2024-04-11T15:30:48Z", + "published": "2024-04-11T15:30:48Z", + "aliases": [ + "CVE-2024-32106" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One].This issue affects WP Compress – Image Optimizer [All-In-One]: from n/a through 6.10.35.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32106" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-compress-image-optimizer/wordpress-wp-compress-plugin-6-10-35-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p788-3h6g-7p3f/GHSA-p788-3h6g-7p3f.json b/advisories/unreviewed/2024/04/GHSA-p788-3h6g-7p3f/GHSA-p788-3h6g-7p3f.json new file mode 100644 index 00000000000..cf44908b33b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p788-3h6g-7p3f/GHSA-p788-3h6g-7p3f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p788-3h6g-7p3f", + "modified": "2024-04-11T15:30:47Z", + "published": "2024-04-11T15:30:47Z", + "aliases": [ + "CVE-2024-31937" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visitor Analytics TWIPLA (Visitor Analytics IO) allows Stored XSS.This issue affects TWIPLA (Visitor Analytics IO): from n/a through 1.2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31937" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/visitor-analytics-io/wordpress-twipla-visitor-analytics-io-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q846-3fgc-qhjr/GHSA-q846-3fgc-qhjr.json b/advisories/unreviewed/2024/04/GHSA-q846-3fgc-qhjr/GHSA-q846-3fgc-qhjr.json new file mode 100644 index 00000000000..f6dfa2bf2ad --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q846-3fgc-qhjr/GHSA-q846-3fgc-qhjr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q846-3fgc-qhjr", + "modified": "2024-04-11T15:30:47Z", + "published": "2024-04-11T15:30:47Z", + "aliases": [ + "CVE-2024-31926" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BracketSpace Advanced Cron Manager – debug & control allows Stored XSS.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31926" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-cron-manager/wordpress-advanced-cron-manager-debug-control-plugin-2-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r5vj-hjx4-mp69/GHSA-r5vj-hjx4-mp69.json b/advisories/unreviewed/2024/04/GHSA-r5vj-hjx4-mp69/GHSA-r5vj-hjx4-mp69.json new file mode 100644 index 00000000000..c1e87266252 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r5vj-hjx4-mp69/GHSA-r5vj-hjx4-mp69.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5vj-hjx4-mp69", + "modified": "2024-04-11T15:30:47Z", + "published": "2024-04-11T15:30:47Z", + "aliases": [ + "CVE-2024-31927" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aminur Islam WP Login and Logout Redirect allows Stored XSS.This issue affects WP Login and Logout Redirect: from n/a through 1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31927" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-login-and-logout-redirect/wordpress-wp-login-and-logout-redirect-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v8pw-v275-vxvw/GHSA-v8pw-v275-vxvw.json b/advisories/unreviewed/2024/04/GHSA-v8pw-v275-vxvw/GHSA-v8pw-v275-vxvw.json new file mode 100644 index 00000000000..4a9a68c2c11 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v8pw-v275-vxvw/GHSA-v8pw-v275-vxvw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8pw-v275-vxvw", + "modified": "2024-04-11T15:30:46Z", + "published": "2024-04-11T15:30:46Z", + "aliases": [ + "CVE-2024-31361" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.Net allows Stored XSS.This issue affects bunny.Net: from n/a through 2.0.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31361" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bunnycdn/wordpress-bunny-net-plugin-2-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vj6v-pg66-4f9j/GHSA-vj6v-pg66-4f9j.json b/advisories/unreviewed/2024/04/GHSA-vj6v-pg66-4f9j/GHSA-vj6v-pg66-4f9j.json new file mode 100644 index 00000000000..80ca2d6c80a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vj6v-pg66-4f9j/GHSA-vj6v-pg66-4f9j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj6v-pg66-4f9j", + "modified": "2024-04-11T15:30:48Z", + "published": "2024-04-11T15:30:48Z", + "aliases": [ + "CVE-2024-32107" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32107" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/finale-woocommerce-sales-countdown-timer-discount/wordpress-finale-lite-sales-countdown-timer-discount-for-woocommerce-plugin-2-18-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x6x2-3r7p-w8cx/GHSA-x6x2-3r7p-w8cx.json b/advisories/unreviewed/2024/04/GHSA-x6x2-3r7p-w8cx/GHSA-x6x2-3r7p-w8cx.json new file mode 100644 index 00000000000..9c3517ed665 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x6x2-3r7p-w8cx/GHSA-x6x2-3r7p-w8cx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6x2-3r7p-w8cx", + "modified": "2024-04-11T15:30:48Z", + "published": "2024-04-11T15:30:48Z", + "aliases": [ + "CVE-2024-32109" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Julien Berthelot / MPEmbed.Com WP Matterport Shortcode.This issue affects WP Matterport Shortcode: from n/a through 2.1.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32109" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortcode-gallery-for-matterport-showcase/wordpress-wp-matterport-shortcode-plugin-2-1-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-11T13:15:56Z" + } +} \ No newline at end of file