CVE-2025-3707 – Sunnet eHDR CTMS SQL Injection
The following table lists the changes that have been made to the CVE-2025-3707 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 02, 2025 Action […]
CVE-2025-3510 – TagDiv Composer WordPress Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-3510 Published : May 2, 2025, 4:15 a.m. | 1 hour, 21 minutes ago Description : The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and including, 5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it […]
CVE-2025-1327 – “Homey WordPress Theme Insecure Direct Object Reference Vulnerability”
CVE ID : CVE-2025-1327 Published : May 2, 2025, 4:15 a.m. | 1 hour, 21 minutes ago Description : The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.4 via the ‘homey_delete_user_account’ action due to missing validation on a user controlled key. This makes it possible for […]
CVE-2025-1326 – Homey WordPress Missing Capability Check Data Deletion Vulnerability
CVE ID : CVE-2025-1326 Published : May 2, 2025, 4:15 a.m. | 1 hour, 21 minutes ago Description : The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the homey_reservation_del() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with […]
CVE-2024-13420 – WordPress Envato Theme/Plugin Unauthorized Access Vulnerability
CVE ID : CVE-2024-13420 Published : May 2, 2025, 4:15 a.m. | 1 hour, 21 minutes ago Description : Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like ‘gsf_reset_section_options’, ‘gsf_reset_section_options’, ‘gsf_create_preset_options’ and more in various versions. This makes it possible for authenticated attackers, with […]
CVE-2024-13419 – WordPress Smart Framework Stored Cross-Site Scripting
CVE ID : CVE-2024-13419 Published : May 2, 2025, 4:15 a.m. | 1 hour, 21 minutes ago Description : Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for authenticated attackers, with […]
CVE-2024-13418 – WordPress Theme/Plugin Arbitrary File Upload Vulnerability
The following table lists the changes that have been made to the CVE-2024-13418 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 02, 2025 Action […]
CVE-2024-13344 – WooCommerce Advance Seat Reservation SQL Injection
CVE ID : CVE-2024-13344 Published : May 2, 2025, 4:15 a.m. | 1 hour, 21 minutes ago Description : The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘profileId’ parameter in all versions up to, and including, 3.3 due to insufficient escaping on the user supplied parameter and lack […]
CVE-2024-13322 – WordPress Ads Pro Plugin SQL Injection Vulnerability
CVE ID : CVE-2024-13322 Published : May 2, 2025, 4:15 a.m. | 1 hour, 21 minutes ago Description : The Ads Pro Plugin – Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the ‘a_id’ parameter in all versions up to, and including, 4.88 due to insufficient escaping on the user supplied parameter […]
CVE-2024-12023 – “Elementor CRM FULL Cliente SQL Injection Vulnerability”
CVE ID : CVE-2024-12023 Published : May 2, 2025, 4:15 a.m. | 1 hour, 21 minutes ago Description : The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the ‘formId’ parameter in all versions 3.1.5 to 3.1.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the […]