
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2023-27456 | Published 2024-12-13 | CVSS: 4.3 | ShadowTrackr CVSS: 1.3 | Summary: Missing Authorization vulnerability in HashThemes Total allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total: from n/a through 2.1.19. |
CVE: CVE-2023-27454 | Published 2024-12-09 | CVSS: 5.4 | ShadowTrackr CVSS: 1.3 | Summary: Missing Authorization vulnerability in Apollo13Themes Rife Elementor Extensions & Templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rife Elementor Extensions & Templates: from n/a through 1.1.10. |
CVE: CVE-2023-27459 | Published 2024-03-26 | CVSS: 7.4 | ShadowTrackr CVSS: 1.3 | Summary: Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1. |
CVE: CVE-2023-27457 | Published 2023-11-22 | CVSS: 4.3 | ShadowTrackr CVSS: 1.2 | Summary: Cross-Site Request Forgery (CSRF) vulnerability in Passionate Brains Add Expires Headers & Optimized Minify plugin <= 2.7 versions. |
CVE: CVE-2023-27458 | Published 2023-11-22 | CVSS: 4.3 | ShadowTrackr CVSS: 1.2 | Summary: Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream plugin <= 4.4.10 versions. |
CVE: CVE-2023-27453 | Published 2023-11-22 | CVSS: 5.4 | ShadowTrackr CVSS: 1.2 | Summary: Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.3.1 versions. |
CVE: CVE-2023-27451 | Published 2023-11-22 | CVSS: 7.2 | ShadowTrackr CVSS: 6.6 | Summary: Server-Side Request Forgery (SSRF) vulnerability in Darren Cooney Instant Images plugin <= 5.1.0.2 versions. |
CVE: CVE-2023-27452 | Published 2023-06-22 | CVSS: 5.9 | ShadowTrackr CVSS: 0.9 | Summary: Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.3 versions. |
CVE: CVE-2023-27450 | Published 2023-06-21 | CVSS: 7.1 | ShadowTrackr CVSS: 1.2 | Summary: Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.29.2 versions. |
CVE: CVE-2023-2745 | Published 2023-05-17 | CVSS: 5.4 | ShadowTrackr CVSS: 2.9 | Summary: WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack. |
CVE: CVE-2023-27455 | Published 2023-05-10 | CVSS: 7.1 | ShadowTrackr CVSS: 1.2 | Summary: Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maui Marketing Update Image Tag Alt Attribute plugin <= 2.4.5 versions. |