Vulnerabilities

 Customer Reviews for WooCommerce Vulnerability – Improper Authorization via submit_review – CVE-2024-1044 | WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 6, 2024

Plugin Name: Customer Reviews for WooCommerce Key Information: Software Type: Plugin Software Slug: customer-reviews-woocommerce Software Status: Active Software Author: ivole Software Downloads: 3,898,158 Active Installs: 60,000 Last Updated: February 13, 2024 Patched Versions: 5.39.0 Affected Versions: <= 5.38.12 Vulnerability Details: Name: Customer Reviews for WooCommerce <= 5.38.12 Title: Improper Authorization via submit_review Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE:…

PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-1055 | WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 6, 2024

Plugin Name: PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) Key Information: Software Type: Plugin Software Slug: powerpack-lite-for-elementor Software Status: Active Software Author: ideaboxcreations Software Downloads: 2,129,545 Active Installs: 100,000 Last Updated: February 13, 2024 Patched Versions: 2.7.15 Affected Versions: <= 2.7.14 Vulnerability Details: Name: PowerPack Addons for Elementor <= 2.7.14 Title: Authenticated (Contributor+)…

Shield Security Vulnerability– Smart Bot Blocking & Intrusion Prevention Security – Unauthenticated Local File Inclusion – CVE-2023-6989 |WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 5, 2024

Plugin Name: Shield Security – Smart Bot Blocking & Intrusion Prevention Security Key Information: Software Type: Plugin Software Slug: wp-simple-firewall Software Status: Active Software Author: paultgoodchild Software Downloads: 11,714,137 Active Installs: 50,000 Last Updated: February 8, 2024 Patched Versions: 18.5.10 Affected Versions: <= 18.5.9 Vulnerability Details: Name: Shield Security – Smart Bot Blocking & Intrusion…

WP 404 Auto Redirect to Similar Post Vulnerability- Reflected Cross-Site Scripting via request – CVE-2024-0509 |WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 5, 2024

Plugin Name: WP 404 Auto Redirect to Similar Post Key Information: Software Type: Plugin Software Slug: wp-404-auto-redirect-to-similar-post Software Status: Active Software Author: hwk-fr Software Downloads: 266,878 Active Installs: 40,000 Last Updated: February 8, 2024 Patched Versions: 1.0.4 Affected Versions: <= 1.0.3 Vulnerability Details: Name: WP 404 Auto Redirect to Similar Post <= 1.0.3 Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N…

Elementor Addon Elements Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-0834 |WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 5, 2024

Plugin Name: Elementor Addon Elements Key Information: Software Type: Plugin Software Slug: addon-elements-for-elementor-page-builder Software Status: Active Software Author: webtechstreet Software Downloads: 2,364,972 Active Installs: 100,000 Last Updated: February 8, 2024 Patched Versions: 1.12.12 Affected Versions: 1.12.11 – 1.12.11 Vulnerability Details: Name: Elementor Addon Elements <= 1.12.11 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE:…

Meta Box Vulnerability– WordPress Custom Fields Framework – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-6526 |WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 5, 2024

Plugin Name: Meta Box – WordPress Custom Fields Framework Key Information: Software Type: Plugin Software Slug: meta-box Software Status: Active Software Author: rilwis Software Downloads: 16,593,050 Active Installs: 700,000 Last Updated: February 8, 2024 Patched Versions: 5.9.3 Affected Versions: <= 5.9.2 Vulnerability Details: Name: Meta Box – WordPress Custom Fields Framework <= 5.9.2 Title: Authenticated…

Minimal Coming Soon Vulnerability– Coming Soon Page – Unauthenticated Maintenance Mode Bypass – CVE-2024-1075 |WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 5, 2024

Plugin Name: Minimal Coming Soon – Coming Soon Page Key Information: Software Type: Plugin Software Slug: minimal-coming-soon-maintenance-mode Software Status: Active Software Author: webfactory Software Downloads: 1,881,425 Active Installs: 100,000 Last Updated: February 8, 2024 Patched Versions: 2.38 Affected Versions: <= 2.37 Vulnerability Details: Name: Minimal Coming Soon – Coming Soon Page <= 2.37 Title: Unauthenticated…

Shariff Wrapper Vulnerability – Authenticated (Admin+) Stored Cross-Site Scripting – CVE-2024-1106 |WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 5, 2024

Plugin Name: Shariff Wrapper Key Information: Software Type: Plugin Software Slug: shariff Software Status: Active Software Author: 3uu Software Downloads: 848,443 Active Installs: 50,000 Last Updated: February 8, 2024 Patched Versions: 4.6.10 Affected Versions: <= 4.6.9 Vulnerability Details: Name: Shariff Wrapper <= 4.6.9 Title: Authenticated (Admin+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-1106 CVSS Score:…

BEAR Vulnerability– Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net – Missing Authorization via Several Functions – CVE-2024-24835 | WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 2, 2024

Plugin Name: BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Key Information: Software Type: Plugin Software Slug: woo-bulk-editor Software Status: Active Software Author: realmag777 Software Downloads: 545,399 Active Installs: 30,000 Last Updated: February 8, 2024 Patched Versions: 1.1.4.1 Affected Versions: <= 1.1.4 Vulnerability Details: Name: BEAR <= 1.1.4 Title: Missing Authorization…

Easy Digital Downloads Vulnerability– Sell Digital Files (eCommerce Store & Payments Made Easy) – Authenticated (Shop Manager+) Stored Cross-Site Scripting – CVE-2024-0659 | WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 2, 2024

Plugin Name: Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) Key Information: Software Type: Plugin Software Slug: easy-digital-downloads Software Status: Active Software Author: smub Software Downloads: 4,802,741 Active Installs: 50,000 Last Updated: February 8, 2024 Patched Versions: 3.2.7 Affected Versions: <= 3.2.6 Vulnerability Details: Name: Easy Digital Downloads <= 3.2.6…