CVE-2024-1564 – Schema Pro < 2.7.16 - Contributor+ Custom Field Access
https://notcve.org/view.php?id=CVE-2024-1564
The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode El complemento wp-schema-pro de WordPress anterior a 2.7.16 no valida el acceso a la publicación, lo que permite a un usuario colaborador acceder a campos personalizados en cualquier publicación, independientemente del tipo o estado de la publicación a través de un código corto. The Schema Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability check in all versions up to, and including 2.7.15. This makes it possible for authenticated attackers, with contributor-level access and above, to access arbitrary custom fields. • https://wpscan.com/vulnerability/ecb1e36f-9c6e-4754-8878-03c97194644d • CWE-863: Incorrect Authorization •
CVE-2024-2761 – Genesis Blocks < 3.1.3 - Contributor+ Stored XSS
https://notcve.org/view.php?id=CVE-2024-2761
The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks. El complemento Genesis Blocks de WordPress anterior a 3.1.3 no escapa adecuadamente a la entrada de datos proporcionada a algunos de sus bloques, lo que permite su uso con al menos privilegios de colaborador para realizar ataques XSS almacenados. The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the postTitleTag in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://wpscan.com/vulnerability/e092ccdc-7ea1-4937-97b7-4cdbff5e74e5 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-0337 – Travelpayouts <= 1.1.15 - Open Redirect
https://notcve.org/view.php?id=CVE-2024-0337
The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action. The Travelpayouts: All Travel Brands in One Place plugin for WordPress is vulnerable to Open Redirect in versions 0.0.0.0 to 1.1.16. This is due to insufficient validation on the redirect url supplied via the travelpayouts_redirect parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action. • https://wpscan.com/vulnerability/2f17a274-8676-4f4e-989f-436030527890 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2024-0856 – Booking Calendar < 1.3.83 - CSRF appointment scheduling
https://notcve.org/view.php?id=CVE-2024-0856
The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying. The Appointment Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.82. This is due to missing or incorrect nonce validation on the cpabc_appointments.php page. This makes it possible for unauthenticated attackers to perform actions like adding bookings without paying via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://wpscan.com/vulnerability/eb383600-0cff-4f24-8127-1fb118f0565a • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2023-7246 – System Dashboard < 2.8.10 - XSS via Header Injection
https://notcve.org/view.php?id=CVE-2023-7246
The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'X-Forwarded-For' header in all versions up to, and including, 2.8.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. • https://wpscan.com/vulnerability/7413d5ec-10a7-4cb8-ac1c-4ef554751518 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •