All CVEs — page 230 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This flaw allows any authenticated user with Contributor-level access or higher to retrieve email addresses of all registered users, including administrators, due to lack of proper user restriction checks in GeoDirectory WordPress plugin versions before 2.8.168.
The flaw allows unauthenticated users to delete arbitrary files, leading to potential full site takeover.
The flaw allows unauthenticated users to bypass registration restrictions set by administrators, enabling account creation even when open registration is disabled.
The flaw allows an authenticated vendor to manipulate other vendors' stores on the marketplace due to inadequate verification of store ownership.
The flaw allows unauthenticated users to view password-protected content without entering a password, compromising data confidentiality.
The flaw allows unauthenticated users to access protected content via the WordPress REST API, bypassing category-based restrictions.
The flaw allows unauthenticated users to access non-public post content via an unsecured REST endpoint in Passster WordPress plugin versions before 4.3.6.
The flaw allows unauthenticated attackers to upload a malicious SVG file containing JavaScript, leading to Stored Cross-Site Scripting (XSS). This matters because it can enable arbitrary code execution in users' browsers when they view the affected site.
The flaw allows unauthenticated users to access private image comments through a vulnerable AJAX action in Sunshine Photo Cart WordPress plugin versions prior to 3.6.12, compromising privacy and security.
The flaw allows direct authentication cookie issuance post-password check, bypassing security measures and enabling unthrottled password guessing.
The flaw allows an attacker to rebind a user's second factor to their own account if they know the user’s password, enabling unauthorized access.
The WP 2FA plugin before version 4.1.0 fails to validate the second authentication factor, allowing attackers with knowledge of a user's password to bypass two-factor authentication and gain full access to the account.
The flaw is a time-based blind SQL injection vulnerability in the Ajax Load More WordPress plugin before 8.0.1, allowing unauthenticated attackers to extract sensitive data from the database. This matters because it can lead to data breaches and loss of confidentiality.
The flaw allows any authenticated user to overwrite pricing configurations and disclose private coupon codes due to missing capability checks in REST API routes.
The flaw allows unauthenticated users to brute-force OTP codes, potentially taking over any account, including administrator accounts.
The flaw allows any authenticated user to upload arbitrary PHP files, leading to remote code execution due to improper file validation.
The flaw allows password reset link poisoning, enabling attackers to take over user accounts, including administrator accounts, by leveraging the unvalidated rc_redirect POST parameter.