Aggregator
.NET内网实战:通过winlogon、CMSTP提升本地账户权限
1 year ago
CVE-2025-24570 | Atarim Plugin up to 4.0.8 on WordPress cross site scripting
1 year ago
A vulnerability, which was classified as problematic, has been found in Atarim Plugin up to 4.0.8 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-24570. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-24572 | Epsiloncool WP Fast Total Search Plugin up to 1.78.258 on WordPress cross-site request forgery
1 year ago
A vulnerability, which was classified as problematic, was found in Epsiloncool WP Fast Total Search Plugin up to 1.78.258 on WordPress. Affected is an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-24572. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24573 | PageLayer Plugin up to 1.9.4 on WordPress cross site scripting
1 year ago
A vulnerability has been found in PageLayer Plugin up to 1.9.4 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-24573. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24575 | HelloAsso Plugin up to 1.1.11 on WordPress cross site scripting
1 year ago
A vulnerability was found in HelloAsso Plugin up to 1.1.11 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-24575. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24578 | ElementInvader Addons for Elementor Plugin up to 1.3.0 on WordPress cross site scripting
1 year ago
A vulnerability was found in ElementInvader Addons for Elementor Plugin up to 1.3.0 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-24578. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24579 | Kyle Phillips Nested Pages Plugin up to 3.2.9 on WordPress cross site scripting
1 year ago
A vulnerability was found in Kyle Phillips Nested Pages Plugin up to 3.2.9 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-24579. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-24568 | Brainstorm Force Starter Templates Plugin up to 4.4.9 on WordPress cross-site request forgery
1 year ago
A vulnerability was found in Brainstorm Force Starter Templates Plugin up to 4.4.9 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2025-24568. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-24555 | SubscriptionDNA Subscription DNA Plugin up to 2.1 on WordPress SubscriptionDNA.com cross-site request forgery
1 year ago
A vulnerability classified as problematic has been found in SubscriptionDNA Subscription DNA Plugin up to 2.1 on WordPress. Affected is an unknown function of the file SubscriptionDNA.com of the component Subscription Handler. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-24555. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24561 | ReviewsTap Plugin up to 1.1.2 on WordPress cross-site request forgery
1 year ago
A vulnerability classified as problematic was found in ReviewsTap Plugin up to 1.1.2 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-24561. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24562 | Optimal Access KBucket Plugin up to 4.1.6 on WordPress cross-site request forgery
1 year ago
A vulnerability, which was classified as problematic, has been found in Optimal Access KBucket Plugin up to 4.1.6 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-24562. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24610 | Christian Leuenberg & L.net Web Solutions Restrict Anonymous Access Plugin up to 1.2 on WordPress cross site scripting
1 year ago
A vulnerability classified as problematic was found in Christian Leuenberg & L.net Web Solutions Restrict Anonymous Access Plugin up to 1.2 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-24610. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-24585 | N.O.U.S. Open Useful and Simple Event Post Plugin up to 5.9.7 on WordPress cross site scripting
1 year ago
A vulnerability has been found in N.O.U.S. Open Useful and Simple Event Post Plugin up to 5.9.7 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-24585. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24595 | bPlugins All Embed Plugin up to 1.1.3 on WordPress cross site scripting
1 year ago
A vulnerability was found in bPlugins All Embed Plugin up to 1.1.3 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-24595. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24625 | Marco Almeida Taxonomy up to 5.1 on WordPress authorization
1 year ago
A vulnerability classified as problematic was found in Marco Almeida Taxonomy and Term and Role based Discounts for WooCommerce Plugin up to 5.1 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2025-24625. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24666 | ThemeIsle AI Chatbot Plugin up to 1.2.2 on WordPress cross site scripting
1 year ago
A vulnerability, which was classified as problematic, was found in ThemeIsle AI Chatbot Plugin up to 1.2.2 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-24666. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24678 | Listamester Plugin up to 2.3.4 on WordPress cross site scripting
1 year ago
A vulnerability was found in Listamester Plugin up to 2.3.4 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2025-24678. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24673 | AyeCode Ketchup Shortcodes Plugin up to 0.1.2 on WordPress cross site scripting
1 year ago
A vulnerability classified as problematic was found in AyeCode Ketchup Shortcodes Plugin up to 0.1.2 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting.
This vulnerability is known as CVE-2025-24673. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24644 | WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin cross site scripting
1 year ago
A vulnerability, which was classified as problematic, has been found in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin up to 4.7.1 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-24644. The attack may be launched remotely. There is no exploit available.
vuldb.com