
CVE-2023-47530 – WordPress Redirect 404 Error Page to Homepage or Custom Page with Logs Plugin <= 1.8.7 is vulnerable to SQL Injection
https://notcve.org/view.php?id=CVE-2023-47530
07 Nov 2023 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPVibes Redirect 404 Error Page to Homepage or Custom Page with Logs allows SQL Injection.This issue affects Redirect 404 Error Page to Homepage or Custom Page with Logs: from n/a through 1.8.7. La neutralización incorrecta de elementos especiales utilizados en una vulnerabilidad de comando SQL ('inyección SQL') en WPVibes Redirect 404 Error Page to Homepage or Custom Page with Logs permite la inyección de ... • https://patchstack.com/database/vulnerability/redirect-404-error-page-to-homepage-or-custom-page/wordpress-redirect-404-error-page-to-homepage-or-custom-page-with-logs-plugin-1-8-7-sql-injection-vulnerability?_s_id=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-3088 – WP Mail Log <= 1.1.1 - Unauthenticated Stored Cross-Site Scripting via Email
https://notcve.org/view.php?id=CVE-2023-3088
05 Jul 2023 — The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://plugins.trac.wordpress.org/changeset/2931706/wp-mail-log • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-0443 – AnyWhere Elementor < 1.2.8 - Freemius API Key Disclosure
https://notcve.org/view.php?id=CVE-2023-0443
02 May 2023 — The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked. The AnyWhere Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.7 via the wpv_ae. This allowed anyone able to view the plugin repo to view a Freemius API Secret Key allowing them to purchase Freemius... • https://wpscan.com/vulnerability/471f3226-8f90-43d1-b826-f11ef4bbd602 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2022-45807 – WordPress WP Mail Log Plugin <= 1.0.1 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2022-45807
02 Dec 2022 — Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions. The WP Mail Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the wpv_mail_review function. This makes it possible for unauthenticated attackers to review the plugin, via forged request granted they can trick a site administrator into performing an action such as clicking on a link. Cross-Site Request Forgery (C... • https://patchstack.com/database/vulnerability/wp-mail-log/wordpress-wp-mail-log-plugin-1-0-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2022-3764 – Form Vibes < 1.4.5 - Admin+ SQLi
https://notcve.org/view.php?id=CVE-2022-3764
08 Nov 2022 — The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability. El complemento no filtra el parámetro "delete_entries" de las solicitudes de los usuarios, lo que genera una vulnerabilidad de inyección SQL. The Form Vibes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.5 due to insufficient escaping on the user supplied parameter IDs and lack of sufficient preparation on the existing SQL query. This makes it po... • https://wpscan.com/vulnerability/9d49df6b-e2f1-4662-90d2-84c29c3b1cb0 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2022-4974 – Freemius SDK <= 2.4.2 - Missing Authorization Checks
https://notcve.org/view.php?id=CVE-2022-4974
04 Mar 2022 — The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable. • https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=cve • CWE-862: Missing Authorization •