NA - CVE-2025-23119 - An Improper Neutralization of Escape Sequences...
An Improper Neutralization of Escape Sequences vulnerability could allow an Authentication Bypass with a Remote Code Execution (RCE) by a malicious actor with access to UniFi Protect Cameras...
Medium - CVE-2024-13358 - The BuddyPress WooCommerce My Account...
The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the...
Medium - CVE-2025-1780 - The BuddyPress WooCommerce My Account...
The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the...
Medium - CVE-2024-13518 - The Simple:Press Forum plugin for WordPress is...
The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.11. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-13559 - The TemplatesNext ToolKit plugin for WordPress...
The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wishlist_table' shortcode in all versions up to, and including,...
High - CVE-2024-13568 - The Fluent Support – Helpdesk & Customer...
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the...
Medium - CVE-2024-13746 - The Booking Calendar and Notification plugin...
The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on the wpcb_all_bookings(),...
Medium - CVE-2024-13750 - The Multilevel Referral Affiliate Plugin for...
The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.27 due to...
Medium - CVE-2024-9212 - The SKU Generator for WooCommerce plugin for...
The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to,...
Medium - CVE-2024-9217 - The Currency Switcher for WooCommerce plugin...
The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up...