Total
4661 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-12365 | 1 Boldgrid | 1 W3 Total Cache | 2025-01-16 | N/A | 8.5 HIGH |
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain the plugin's nonce value and perform unauthorized actions, resulting in information disclosure, service plan limits consumption as well as making web requests to arbitrary locations originating from the web application that can be used to query information from internal services, including instance metadata on cloud-based applications. | |||||
CVE-2024-12006 | 1 Boldgrid | 1 W3 Total Cache | 2025-01-16 | N/A | 5.3 MEDIUM |
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin extensions. | |||||
CVE-2025-23963 | 2025-01-16 | N/A | 5.4 MEDIUM | ||
Missing Authorization vulnerability in Sven Hofmann & Michael Schoenrock Mark Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mark Posts: from n/a through 2.2.3. | |||||
CVE-2025-23962 | 2025-01-16 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in Goldstar Goldstar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Goldstar: from n/a through 2.1.1. | |||||
CVE-2025-23961 | 2025-01-16 | N/A | 5.4 MEDIUM | ||
Missing Authorization vulnerability in WP Tasker WordPress Graphs & Charts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Graphs & Charts: from n/a through 2.0.8. | |||||
CVE-2025-23957 | 2025-01-16 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in Sur.ly Sur.ly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sur.ly: from n/a through 3.0.3. | |||||
CVE-2025-23955 | 2025-01-16 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in xola.com Xola allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xola: from n/a through 1.6. | |||||
CVE-2025-23954 | 2025-01-16 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in AWcode & KingfisherFox Salvador – AI Image Generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salvador – AI Image Generator: from n/a through 1.0.11. | |||||
CVE-2025-23930 | 2025-01-16 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in iTechArt-Group PayPal Marketing Solutions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Marketing Solutions: from n/a through 1.2. | |||||
CVE-2025-23929 | 2025-01-16 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in wishfulthemes Email Capture & Lead Generation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Email Capture & Lead Generation: from n/a through 1.0.2. | |||||
CVE-2025-23917 | 2025-01-16 | N/A | 5.4 MEDIUM | ||
Missing Authorization vulnerability in Chandrika Guntur, Morgan Kay Chamber Dashboard Business Directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.8. | |||||
CVE-2025-23916 | 2025-01-16 | N/A | 5.4 MEDIUM | ||
Missing Authorization vulnerability in Nuanced Media WP Meetup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Meetup: from n/a through 2.3.0. | |||||
CVE-2025-23862 | 2025-01-16 | N/A | 5.3 MEDIUM | ||
Missing Authorization vulnerability in SzMake Contact Form 7 Anti Spambot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form 7 Anti Spambot: from n/a through 1.0.1. | |||||
CVE-2025-23785 | 2025-01-16 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in August Infotech AI Responsive Gallery Album allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Responsive Gallery Album: from n/a through 1.4. | |||||
CVE-2025-23778 | 2025-01-16 | N/A | 5.4 MEDIUM | ||
Missing Authorization vulnerability in Pravin Durugkar User Sync ActiveCampaign allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Sync ActiveCampaign: from n/a through 1.3.2. | |||||
CVE-2025-23776 | 2025-01-16 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in Thorn Technologies LLC Cache Sniper for Nginx allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cache Sniper for Nginx: from n/a through 1.0.4.2. | |||||
CVE-2025-23764 | 2025-01-16 | N/A | 5.3 MEDIUM | ||
Missing Authorization vulnerability in Ujjaval Jani Copy Move Posts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Copy Move Posts: from n/a through 1.6. | |||||
CVE-2025-23761 | 2025-01-16 | N/A | 5.4 MEDIUM | ||
Missing Authorization vulnerability in Alex Volkov Woo Tuner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woo Tuner: from n/a through 0.1.2. | |||||
CVE-2025-23514 | 2025-01-16 | N/A | 5.3 MEDIUM | ||
Missing Authorization vulnerability in Sanjaysolutions Loginplus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Loginplus: from n/a through 1.2. | |||||
CVE-2025-23423 | 2025-01-16 | N/A | 4.3 MEDIUM | ||
Missing Authorization vulnerability in Smackcoders SendGrid for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SendGrid for WordPress: from n/a through 1.4. |