In Service Finder Bookings plugin for WordPress versions 5.0 and prior a critical severity vulnerability CVE-2024-13442 was detected. This vulnerability allows unauthenticated attackers to take over accounts due to improper identity validation, enabling them to log in as any user with a known email or change passwords, including for administrators, to gain unauthorized access. To address this issue, users should upgrade Service Finder Bookings plugin to versions 5.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13442.
Read more CMSIn BoomBox Theme Extensions plugin for WordPress versions 1.8.0 and prior a high severity vulnerability CVE-2024-12295 was detected. This vulnerability allows attackers with subscriber-level access to take over accounts by exploiting improper identity validation in the password reset function, enabling them to change any user’s password, including administrators, and gain unauthorized access. To address this issue, users should upgrade BoomBox Theme Extensions plugin to versions 1.8.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12295.
Read more CMSIn Site Reviews plugin for WordPress versions before 7.2.5 a high severity vulnerability CVE-2025-1232 was detected. This vulnerability allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) attacks due to improper sanitization and escaping of certain review fields. To address this issue, users should upgrade Site Reviews plugin to versions 7.2.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1232.
Read more CMSIn Download Manager WordPress plugin versions before 3.3.07 a medium severity vulnerability CVE-2024-13126 was detected. This vulnerability allows attackers to access unauthorized files due to the lack of directory listing prevention on web servers that don’t use htaccess. To address this issue, users should upgrade Download Manager WordPress plugin to version 3.3.07 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13126.
Read more CMSIn Poll Maker WordPress plugin versions before 5.5.4 a low severity vulnerability CVE-2024-13602 was detected. This vulnerability allows high-privilege users, such as admins, to perform Stored Cross-Site Scripting (XSS) attacks due to improper sanitization and escaping of certain settings, even when the unfiltered_html capability is disallowed (e.g., in a multisite setup). To address this issue, users should upgrade Poll Maker WordPress plugin to version 5.5.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13602.
Read more CMSIn GDPR Cookie Compliance plugin for WordPress versions before 4.15.9 a low severity vulnerability CVE-2025-1624 was detected. This vulnerability allows attackers to perform Stored Cross-Site Scripting (XSS) attacks due to the plugin not sanitizing and escaping some of its settings, which could allow high privilege users such as admins to exploit it, even when the unfiltered_html capability is disallowed (e.g., in multisite setups). To address this issue, users should upgrade GDPR Cookie Compliance plugin to versions 4.15.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1624.
Read more CMSIn Mattermost Desktop App versions 5.10.0 and prior a low severity vulnerability CVE-2025-1398 was detected. This vulnerability allows attackers with remote access to bypass Transparency, Consent, and Control (TCC) via code injection due to explicitly declared unnecessary macOS entitlements. To address this issue, users should upgrade Mattermost to versions 5.11.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1398.
Read more CommunicationIn MongoDB C Driver library versions prior to 1.27.5 and MongoDB Server versions 8.0 prior to 8.0.1 and 7.0 prior to 7.0.16 a high severity vulnerability CVE-2025-0755 was detected. This vulnerability allows attackers to trigger a buffer overflow when handling BSON documents exceeding the maximum allowable size (INT32_MAX), potentially causing a segmentation fault and application crash. To address this issue, users should upgrade to libbson versions 1.27.5, MongoDB Server versions 8.0.1 or 7.0.16. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0755.
Read more DatabaseIn Tripetto plugin for WordPress versions up to and including 8.0.9 a medium severity vulnerability CVE-2025-1530 was detected. This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) due to missing nonce validation. This makes it possible for unauthenticated attackers to delete arbitrary results by tricking a site administrator into performing an action such as clicking on a link. To address this issue, users should upgrade Tripetto plugin to versions 8.0.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1530.
Read more CMS