CVE-2024-23503 – WordPress Ninja Tables plugin <= 5.0.6 - Broken Access Control vulnerability
https://notcve.org/view.php?id=CVE-2024-23503
11 Jun 2024 — Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.6. Vulnerabilidad de autorización faltante en WPManageNinja LLC Ninja Tables. Este problema afecta a Ninja Tables: desde n/a hasta 5.0.6. • https://patchstack.com/database/vulnerability/ninja-tables/wordpress-ninja-tables-plugin-5-0-5-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •
CVE-2023-6953 – PDF Generator For Fluent Forms <= 1.1.7 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2023-6953
22 Jan 2024 — The PDF Generator For Fluent Forms – The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the header, PDF body and footer content parameters in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploitation level depends on who is granted the right to create forms by an admini... • https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3023486%40fluentforms-pdf%2Ftrunk&old=2929799%40fluentforms-pdf%2Ftrunk&sfp_email=&sfph_mail= • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-51547 – WordPress Fluent Support Plugin <= 1.7.6 is vulnerable to SQL Injection
https://notcve.org/view.php?id=CVE-2023-51547
27 Dec 2023 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPManageNinja LLC Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin.This issue affects Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin: from n/a through 1.7.6. Neutralización incorrecta de elementos especiales utilizados en una vulnerabilidad de comando SQL ('inyección SQL') en WPManageNinja LLC Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugi... • https://patchstack.com/database/vulnerability/fluent-support/wordpress-fluent-support-plugin-1-7-6-sql-injection-vulnerability?_s_id=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-3087 – FluentSMTP <= 2.2.4 - Unauthenticated Stored Cross-Site Scripting via Email Subject
https://notcve.org/view.php?id=CVE-2023-3087
06 Jul 2023 — The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://plugins.trac.wordpress.org/changeset/2935217/fluent-smtp/trunk/app/Models/Logger.php • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-1430 – FluentCRM - Marketing Automation For WordPress <= 2.8.01 - Insufficient Use of Hash as Authorization Control
https://notcve.org/view.php?id=CVE-2023-1430
01 Jun 2023 — The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.7.40 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists and manage subscriptions, granted they gain access to any targeted subscribers email address. The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthori... • https://github.com/karlemilnikka/CVE-2023-1430 • CWE-759: Use of a One-Way Hash without a Salt •
CVE-2022-47136 – WordPress Ninja Tables Plugin <= 4.3.4 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2022-47136
20 Apr 2023 — Cross-Site Request Forgery (CSRF) vulnerability in WPManageNinja LLC Ninja Tables – Best Data Table Plugin for WordPress plugin <= 4.3.4 versions. The Ninja Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.4. This is due to missing or incorrect nonce validation on the remindMeLater function. This makes it possible for unauthenticated attackers to dismiss an admin notice via a forged request granted they can trick a site administrator into performi... • https://patchstack.com/database/vulnerability/ninja-tables/wordpress-ninja-tables-best-data-table-plugin-for-wordpress-plugin-4-3-4-cross-site-request-forgery-csrf?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-47137 – WordPress Ninja Tables Plugin <= 4.3.4 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2022-47137
19 Apr 2023 — Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPManageNinja LLC Ninja Tables plugin <= 4.3.4 versions. The Ninja Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 4.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an ... • https://patchstack.com/database/vulnerability/ninja-tables/wordpress-ninja-tables-best-data-table-plugin-for-wordpress-plugin-4-3-4-cross-site-scripting-xss?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-0219 – FluentSMTP < 2.2.3 - Stored XSS via Email Logs
https://notcve.org/view.php?id=CVE-2023-0219
03 Mar 2023 — The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to send emails with unfiltered HTML. The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sending mail (thus adding the payload into the logs of sent emails) in versions up to 2.2.3 due to insufficient input sanitization and outpu... • https://wpscan.com/vulnerability/71662b72-311c-42db-86c5-a0276d25535c • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-4746 – FluentAuth < 1.0.2 - Bypass blocks by IP Spoofing
https://notcve.org/view.php?id=CVE-2022-4746
27 Dec 2022 — The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin. El complemento FluentAuth para WordPress anterior a 1.0.2 prioriza obtener la dirección IP de un visitante de ciertos encabezados HTTP sobre REMOTE_ADDR de PHP, lo que hace posible evitar los bloqueos basados en IP establecidos por el complemento. The FluentAuth plugin for WordPress is vulnerable to ... • https://wpscan.com/vulnerability/62e3babc-00c6-4a35-972f-8f03ba70ba32 • CWE-290: Authentication Bypass by Spoofing CWE-348: Use of Less Trusted Source •
CVE-2022-2559 – Fluent Support < 1.5.8 - Admin+ SQLi
https://notcve.org/view.php?id=CVE-2022-2559
02 Aug 2022 — The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection vulnerability exploitable by high privilege users El plugin Fluent Support de WordPress versiones anteriores a 1.5.8, no sanea, comprueba y escapa de varios parámetros antes de usarlos en una sentencia SQL, conllevando a una vulnerabilidad de inyección SQL explotable por usuarios con altos privilegios The Fluent Support plugin ... • https://wpscan.com/vulnerability/062599ce-c630-487e-bb43-c3b27a62b9ec • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •