CVE-2019-25217 SiteGround Optimizer <= 5.0.12 – Missing Authorization

The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0.12 due to incorrect ...

Continue Reading
CVE-2019-25217 SiteGround Optimizer <= 5.0.12 – Missing Authorization

The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0.12 due to incorrect ...

Continue Reading
CVE-2022-4972 Download Monitor <= 4.7.51 – Missing Authorization to Unauthenticated Data Export

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7. ...

Continue Reading
CVE-2023-7289 Paytium: Mollie payment forms & donations <= 4.3.7 – Missing Authorization in 'paytium_sw_save_api_keys'

The Paytium: Mollie payment forms &amp; donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys function in ve ...

Continue Reading
CVE-2023-7289 Paytium: Mollie payment forms & donations <= 4.3.7 – Missing Authorization in 'paytium_sw_save_api_keys'

The Paytium: Mollie payment forms &amp; donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys function in ve ...

Continue Reading
CVE-2022-4972 Download Monitor <= 4.7.51 – Missing Authorization to Unauthenticated Data Export

The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7. ...

Continue Reading
CVE-2019-25214 ShopWP <= 2.0.4 – Missing Authorization to Stored Cross-Site Scripting

The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to, and including, 2.0.4. This makes it possible for u ...

Continue Reading
CVE-2019-25214 ShopWP <= 2.0.4 – Missing Authorization to Stored Cross-Site Scripting

The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to, and including, 2.0.4. This makes it possible for u ...

Continue Reading

Back to Main

Subscribe for the latest news: