diff --git a/internal/data/assets/plugin_616464667265657370616365811c9dc5_gen.json b/internal/data/assets/plugin_616464667265657370616365811c9dc5_gen.json new file mode 100644 index 00000000..9794b573 --- /dev/null +++ b/internal/data/assets/plugin_616464667265657370616365811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/40eaeb28-c721-4977-951d-582b7dc2bd12/addfreespace","title":"addfreespace <= 0.1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Page\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:07:04","sources":[{"name":"Wordfence","remoteId":"40eaeb28-c721-4977-951d-582b7dc2bd12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/40eaeb28-c721-4977-951d-582b7dc2bd12?source=api-prod","cve":"CVE-2026-6701","affectedVersions":"<=0.1.3","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_61646d696e2d736974652d656e68616e63656d656e7473811c9dc5_gen.json b/internal/data/assets/plugin_61646d696e2d736974652d656e68616e63656d656e7473811c9dc5_gen.json index 61fdcb58..ef41b735 100644 --- a/internal/data/assets/plugin_61646d696e2d736974652d656e68616e63656d656e7473811c9dc5_gen.json +++ b/internal/data/assets/plugin_61646d696e2d736974652d656e68616e63656d656e7473811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/05e8ec0d-74ad-483a-914d-f40c0cfc9b24/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 7.6.9 - Password Protection Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"05e8ec0d-74ad-483a-914d-f40c0cfc9b24"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/05e8ec0d-74ad-483a-914d-f40c0cfc9b24?source=api-prod","cve":"CVE-2024-13688","affectedVersions":"<=7.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/0abad47f-a806-4cdd-a11f-015b997b5e86/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 5.7.1 - Password Protection Mode Security Feature Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"0abad47f-a806-4cdd-a11f-015b997b5e86"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0abad47f-a806-4cdd-a11f-015b997b5e86?source=api-prod","cve":"CVE-2023-46630","affectedVersions":"<=5.7.1","severity":"high"},{"advisoryId":"WPSECADV/WF/1a4321d5-b472-4571-8dc1-96419b59c6c7/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 7.6.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1a4321d5-b472-4571-8dc1-96419b59c6c7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1a4321d5-b472-4571-8dc1-96419b59c6c7?source=api-prod","cve":"CVE-2025-24649","affectedVersions":"<=7.6.2","severity":"low"},{"advisoryId":"WPSECADV/WF/2903d15c-4f4d-497c-b6ed-4ae32c047a8a/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 7.6.9 - IP Spoofing to Limit Login Attempt Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"2903d15c-4f4d-497c-b6ed-4ae32c047a8a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2903d15c-4f4d-497c-b6ed-4ae32c047a8a?source=api-prod","cve":"CVE-2024-13685","affectedVersions":"<=7.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/4d7f2cea-f132-4881-9632-ee07a7b9d6b8/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 8.0.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d7f2cea-f132-4881-9632-ee07a7b9d6b8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d7f2cea-f132-4881-9632-ee07a7b9d6b8?source=api-prod","cve":"CVE-2025-64255","affectedVersions":"<=8.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/5d4ad020-0b40-456b-8f8c-597c7c4ef698/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) Pro <= 7.6.2.1 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"5d4ad020-0b40-456b-8f8c-597c7c4ef698"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5d4ad020-0b40-456b-8f8c-597c7c4ef698?source=api-prod","cve":"CVE-2024-43333","affectedVersions":"<=7.6.2.1","severity":"high"},{"advisoryId":"WPSECADV/WF/96e12fa5-eba4-4f69-ae3a-7e460bfa9e5d/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 7.5.1 - Authenticated Stored Cross-Site Scripting via SVG\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-11 16:57:04","sources":[{"name":"Wordfence","remoteId":"96e12fa5-eba4-4f69-ae3a-7e460bfa9e5d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/96e12fa5-eba4-4f69-ae3a-7e460bfa9e5d?source=api-prod","cve":"CVE-2024-10790","affectedVersions":"<=7.5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/c380b630-7378-43a9-8b8d-85d27b904ad4/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 8.4.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"c380b630-7378-43a9-8b8d-85d27b904ad4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c380b630-7378-43a9-8b8d-85d27b904ad4?source=api-prod","cve":"CVE-2026-32423","affectedVersions":"<=8.4.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/fec9a7a6-c515-4b43-8efc-9b3c86f0fd4b/admin-site-enhancements","title":"Admin and Site Enhancements <= 7.9.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"fec9a7a6-c515-4b43-8efc-9b3c86f0fd4b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fec9a7a6-c515-4b43-8efc-9b3c86f0fd4b?source=api-prod","cve":"CVE-2025-9487","affectedVersions":"<=7.9.7","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/05e8ec0d-74ad-483a-914d-f40c0cfc9b24/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 7.6.9 - Password Protection Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"05e8ec0d-74ad-483a-914d-f40c0cfc9b24"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/05e8ec0d-74ad-483a-914d-f40c0cfc9b24?source=api-prod","cve":"CVE-2024-13688","affectedVersions":"<=7.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/0abad47f-a806-4cdd-a11f-015b997b5e86/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 5.7.1 - Password Protection Mode Security Feature Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"0abad47f-a806-4cdd-a11f-015b997b5e86"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0abad47f-a806-4cdd-a11f-015b997b5e86?source=api-prod","cve":"CVE-2023-46630","affectedVersions":"<=5.7.1","severity":"high"},{"advisoryId":"WPSECADV/WF/1a4321d5-b472-4571-8dc1-96419b59c6c7/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 7.6.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1a4321d5-b472-4571-8dc1-96419b59c6c7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1a4321d5-b472-4571-8dc1-96419b59c6c7?source=api-prod","cve":"CVE-2025-24649","affectedVersions":"<=7.6.2","severity":"low"},{"advisoryId":"WPSECADV/WF/2903d15c-4f4d-497c-b6ed-4ae32c047a8a/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 7.6.9 - IP Spoofing to Limit Login Attempt Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"2903d15c-4f4d-497c-b6ed-4ae32c047a8a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2903d15c-4f4d-497c-b6ed-4ae32c047a8a?source=api-prod","cve":"CVE-2024-13685","affectedVersions":"<=7.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/4d7f2cea-f132-4881-9632-ee07a7b9d6b8/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 8.0.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d7f2cea-f132-4881-9632-ee07a7b9d6b8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d7f2cea-f132-4881-9632-ee07a7b9d6b8?source=api-prod","cve":"CVE-2025-64255","affectedVersions":"<=8.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/5d4ad020-0b40-456b-8f8c-597c7c4ef698/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) Pro <= 7.6.2.1 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"5d4ad020-0b40-456b-8f8c-597c7c4ef698"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5d4ad020-0b40-456b-8f8c-597c7c4ef698?source=api-prod","cve":"CVE-2024-43333","affectedVersions":"<=7.6.2.1","severity":"high"},{"advisoryId":"WPSECADV/WF/96e12fa5-eba4-4f69-ae3a-7e460bfa9e5d/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 7.5.1 - Authenticated Stored Cross-Site Scripting via SVG\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-11 16:57:04","sources":[{"name":"Wordfence","remoteId":"96e12fa5-eba4-4f69-ae3a-7e460bfa9e5d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/96e12fa5-eba4-4f69-ae3a-7e460bfa9e5d?source=api-prod","cve":"CVE-2024-10790","affectedVersions":"<=7.5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/c380b630-7378-43a9-8b8d-85d27b904ad4/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 8.4.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"c380b630-7378-43a9-8b8d-85d27b904ad4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c380b630-7378-43a9-8b8d-85d27b904ad4?source=api-prod","cve":"CVE-2026-32423","affectedVersions":"<=8.4.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e2ca42f3-776f-4ba4-a409-863799338c85/admin-site-enhancements","title":"Admin and Site Enhancements (ASE) <= 7.6.2.1 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"e2ca42f3-776f-4ba4-a409-863799338c85"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e2ca42f3-776f-4ba4-a409-863799338c85?source=api-prod","cve":"CVE-2025-24648","affectedVersions":"<=7.6.2.1","severity":"high"},{"advisoryId":"WPSECADV/WF/fec9a7a6-c515-4b43-8efc-9b3c86f0fd4b/admin-site-enhancements","title":"Admin and Site Enhancements <= 7.9.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"fec9a7a6-c515-4b43-8efc-9b3c86f0fd4b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fec9a7a6-c515-4b43-8efc-9b3c86f0fd4b?source=api-prod","cve":"CVE-2025-9487","affectedVersions":"<=7.9.7","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_616476616e6365642d666f726d2d696e746567726174696f6e811c9dc5_gen.json b/internal/data/assets/plugin_616476616e6365642d666f726d2d696e746567726174696f6e811c9dc5_gen.json index ae3688db..d717f01a 100644 --- a/internal/data/assets/plugin_616476616e6365642d666f726d2d696e746567726174696f6e811c9dc5_gen.json +++ b/internal/data/assets/plugin_616476616e6365642d666f726d2d696e746567726174696f6e811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/03354f47-ebf7-4242-89d0-1b937d418c6f/advanced-form-integration","title":"AFI – The Easiest Integration Plugin <= 1.89.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"03354f47-ebf7-4242-89d0-1b937d418c6f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/03354f47-ebf7-4242-89d0-1b937d418c6f?source=api-prod","cve":"CVE-2024-43340","affectedVersions":"<=1.89.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/1b5a6633-4ce3-4249-a5b0-d8f960aae903/advanced-form-integration","title":"AFI – The Easiest Integration Plugin <= 1.99.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"1b5a6633-4ce3-4249-a5b0-d8f960aae903"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b5a6633-4ce3-4249-a5b0-d8f960aae903?source=api-prod","cve":"CVE-2024-13123","affectedVersions":"<=1.99.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/1e9458e4-570e-4871-84ac-380107037b1c/advanced-form-integration","title":"Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration <= 1.62.0 - Authenticated (Admin+) Cross Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"1e9458e4-570e-4871-84ac-380107037b1c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1e9458e4-570e-4871-84ac-380107037b1c?source=api-prod","cve":"CVE-2022-47173","affectedVersions":"<=1.62.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42/advanced-form-integration","title":"Freemius SDK <= 2.4.2 - Missing Authorization Checks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"39fb0499-9ab4-4a2f-b0db-ece86bcf4d42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=api-prod","cve":"CVE-2022-4974","affectedVersions":"<1.49.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/45d5a677-9b8b-4258-9cfb-101b0f0e6f6f/advanced-form-integration","title":"Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"45d5a677-9b8b-4258-9cfb-101b0f0e6f6f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/45d5a677-9b8b-4258-9cfb-101b0f0e6f6f?source=api-prod","cve":"CVE-2024-2387","affectedVersions":"<=1.82.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/4c64ec9f-c9ca-49c1-9126-b31defb826dd/advanced-form-integration","title":"Advanced Form Integration <= 1.95.0 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"4c64ec9f-c9ca-49c1-9126-b31defb826dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4c64ec9f-c9ca-49c1-9126-b31defb826dd?source=api-prod","cve":"CVE-2024-56293","affectedVersions":"<=1.95.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/5253fe2b-040b-417c-b257-0cb59ee5aa6e/advanced-form-integration","title":"Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"5253fe2b-040b-417c-b257-0cb59ee5aa6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5253fe2b-040b-417c-b257-0cb59ee5aa6e?source=api-prod","cve":"CVE-2023-33999","affectedVersions":"<=1.69.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/63a373a5-4284-4de5-93cd-63274b4e739f/advanced-form-integration","title":"AFI – The Easiest Integration Plugin <= 1.99.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"63a373a5-4284-4de5-93cd-63274b4e739f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63a373a5-4284-4de5-93cd-63274b4e739f?source=api-prod","cve":"CVE-2024-13122","affectedVersions":"<=1.99.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/936de04d-9b80-430b-a8b7-9755b68e2a02/advanced-form-integration","title":"AFI – The Easiest Integration Plugin <= 1.92.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-12 18:26:36","sources":[{"name":"Wordfence","remoteId":"936de04d-9b80-430b-a8b7-9755b68e2a02"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/936de04d-9b80-430b-a8b7-9755b68e2a02?source=api-prod","cve":"CVE-2024-10877","affectedVersions":"<=1.92.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c5782b71-3234-4e53-9b26-225472f604c5/advanced-form-integration","title":"Advanced Form Integration <= 1.75.0 - Authenticated(Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"c5782b71-3234-4e53-9b26-225472f604c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c5782b71-3234-4e53-9b26-225472f604c5?source=api-prod","cve":"CVE-2023-50853","affectedVersions":"<1.76.0","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/03354f47-ebf7-4242-89d0-1b937d418c6f/advanced-form-integration","title":"AFI – The Easiest Integration Plugin <= 1.89.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"03354f47-ebf7-4242-89d0-1b937d418c6f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/03354f47-ebf7-4242-89d0-1b937d418c6f?source=api-prod","cve":"CVE-2024-43340","affectedVersions":"<=1.89.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/1b5a6633-4ce3-4249-a5b0-d8f960aae903/advanced-form-integration","title":"AFI – The Easiest Integration Plugin <= 1.99.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"1b5a6633-4ce3-4249-a5b0-d8f960aae903"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b5a6633-4ce3-4249-a5b0-d8f960aae903?source=api-prod","cve":"CVE-2024-13123","affectedVersions":"<=1.99.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/1e9458e4-570e-4871-84ac-380107037b1c/advanced-form-integration","title":"Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration <= 1.62.0 - Authenticated (Admin+) Cross Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"1e9458e4-570e-4871-84ac-380107037b1c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1e9458e4-570e-4871-84ac-380107037b1c?source=api-prod","cve":"CVE-2022-47173","affectedVersions":"<=1.62.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/2009a0d7-ce42-46b5-986d-33e3d06a513d/advanced-form-integration","title":"AFI – The Easiest Integration Plugin <= 1.126.12 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"2009a0d7-ce42-46b5-986d-33e3d06a513d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2009a0d7-ce42-46b5-986d-33e3d06a513d?source=api-prod","cve":"CVE-2026-42659","affectedVersions":"<=1.126.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42/advanced-form-integration","title":"Freemius SDK <= 2.4.2 - Missing Authorization Checks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"39fb0499-9ab4-4a2f-b0db-ece86bcf4d42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=api-prod","cve":"CVE-2022-4974","affectedVersions":"<1.49.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/45d5a677-9b8b-4258-9cfb-101b0f0e6f6f/advanced-form-integration","title":"Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"45d5a677-9b8b-4258-9cfb-101b0f0e6f6f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/45d5a677-9b8b-4258-9cfb-101b0f0e6f6f?source=api-prod","cve":"CVE-2024-2387","affectedVersions":"<=1.82.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/4c64ec9f-c9ca-49c1-9126-b31defb826dd/advanced-form-integration","title":"Advanced Form Integration <= 1.95.0 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"4c64ec9f-c9ca-49c1-9126-b31defb826dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4c64ec9f-c9ca-49c1-9126-b31defb826dd?source=api-prod","cve":"CVE-2024-56293","affectedVersions":"<=1.95.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/5253fe2b-040b-417c-b257-0cb59ee5aa6e/advanced-form-integration","title":"Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"5253fe2b-040b-417c-b257-0cb59ee5aa6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5253fe2b-040b-417c-b257-0cb59ee5aa6e?source=api-prod","cve":"CVE-2023-33999","affectedVersions":"<=1.69.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/63a373a5-4284-4de5-93cd-63274b4e739f/advanced-form-integration","title":"AFI – The Easiest Integration Plugin <= 1.99.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"63a373a5-4284-4de5-93cd-63274b4e739f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63a373a5-4284-4de5-93cd-63274b4e739f?source=api-prod","cve":"CVE-2024-13122","affectedVersions":"<=1.99.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/936de04d-9b80-430b-a8b7-9755b68e2a02/advanced-form-integration","title":"AFI – The Easiest Integration Plugin <= 1.92.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-12 18:26:36","sources":[{"name":"Wordfence","remoteId":"936de04d-9b80-430b-a8b7-9755b68e2a02"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/936de04d-9b80-430b-a8b7-9755b68e2a02?source=api-prod","cve":"CVE-2024-10877","affectedVersions":"<=1.92.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c5782b71-3234-4e53-9b26-225472f604c5/advanced-form-integration","title":"Advanced Form Integration <= 1.75.0 - Authenticated(Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"c5782b71-3234-4e53-9b26-225472f604c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c5782b71-3234-4e53-9b26-225472f604c5?source=api-prod","cve":"CVE-2023-50853","affectedVersions":"<1.76.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6167656e63792d746f6f6c6b6974811c9dc5_gen.json b/internal/data/assets/plugin_6167656e63792d746f6f6c6b6974811c9dc5_gen.json index 3d8ee4fa..e73e2722 100644 --- a/internal/data/assets/plugin_6167656e63792d746f6f6c6b6974811c9dc5_gen.json +++ b/internal/data/assets/plugin_6167656e63792d746f6f6c6b6974811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/9f5cdb47-205a-4c03-a8a9-f39d1b4fc769/agency-toolkit","title":"Agency Toolkit <= 1.0.23 - Missing Authorization to Unauthenticated Arbitrary Options Update\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"9f5cdb47-205a-4c03-a8a9-f39d1b4fc769"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9f5cdb47-205a-4c03-a8a9-f39d1b4fc769?source=api-prod","affectedVersions":"<=1.0.23","severity":"critical"},{"advisoryId":"WPSECADV/WF/f1ad41b4-c97b-4b3d-a82d-b39570ffe82f/agency-toolkit","title":"Agency Toolkit <= 1.0.24 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"f1ad41b4-c97b-4b3d-a82d-b39570ffe82f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f1ad41b4-c97b-4b3d-a82d-b39570ffe82f?source=api-prod","cve":"CVE-2025-31863","affectedVersions":"<=1.0.24","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/54b079b5-35e4-4d65-97ce-6d0d2053886d/agency-toolkit","title":"Agency Toolkit <= 1.0.23 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"54b079b5-35e4-4d65-97ce-6d0d2053886d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/54b079b5-35e4-4d65-97ce-6d0d2053886d?source=api-prod","cve":"CVE-2024-56066","affectedVersions":"<=1.0.23","severity":"critical"},{"advisoryId":"WPSECADV/WF/9f5cdb47-205a-4c03-a8a9-f39d1b4fc769/agency-toolkit","title":"Agency Toolkit <= 1.0.23 - Missing Authorization to Unauthenticated Arbitrary Options Update\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"9f5cdb47-205a-4c03-a8a9-f39d1b4fc769"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9f5cdb47-205a-4c03-a8a9-f39d1b4fc769?source=api-prod","affectedVersions":"<=1.0.23","severity":"critical"},{"advisoryId":"WPSECADV/WF/f1ad41b4-c97b-4b3d-a82d-b39570ffe82f/agency-toolkit","title":"Agency Toolkit <= 1.0.24 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"f1ad41b4-c97b-4b3d-a82d-b39570ffe82f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f1ad41b4-c97b-4b3d-a82d-b39570ffe82f?source=api-prod","cve":"CVE-2025-31863","affectedVersions":"<=1.0.24","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_616c6d612d676174657761792d666f722d776f6f636f6d6d65726365811c9dc5_gen.json b/internal/data/assets/plugin_616c6d612d676174657761792d666f722d776f6f636f6d6d65726365811c9dc5_gen.json index 387eeac3..70b49c0f 100644 --- a/internal/data/assets/plugin_616c6d612d676174657761792d666f722d776f6f636f6d6d65726365811c9dc5_gen.json +++ b/internal/data/assets/plugin_616c6d612d676174657761792d666f722d776f6f636f6d6d65726365811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/044d7480-ccd7-4ce8-bb5d-367ba5d0217c/alma-gateway-for-woocommerce","title":"Alma – Pay in installments or later for WooCommerce <= 5.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"044d7480-ccd7-4ce8-bb5d-367ba5d0217c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/044d7480-ccd7-4ce8-bb5d-367ba5d0217c?source=api-prod","cve":"CVE-2023-50369","affectedVersions":"<=5.2.0","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/044d7480-ccd7-4ce8-bb5d-367ba5d0217c/alma-gateway-for-woocommerce","title":"Alma – Pay in installments or later for WooCommerce <= 5.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"044d7480-ccd7-4ce8-bb5d-367ba5d0217c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/044d7480-ccd7-4ce8-bb5d-367ba5d0217c?source=api-prod","cve":"CVE-2023-50369","affectedVersions":"<=5.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/4424b889-fade-4ddd-85e9-812752a2552d/alma-gateway-for-woocommerce","title":"Alma <= 5.16.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"4424b889-fade-4ddd-85e9-812752a2552d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4424b889-fade-4ddd-85e9-812752a2552d?source=api-prod","cve":"CVE-2026-24999","affectedVersions":"<=5.16.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_616d656c6961626f6f6b696e67811c9dc5_gen.json b/internal/data/assets/plugin_616d656c6961626f6f6b696e67811c9dc5_gen.json index a5869ea9..9d1ab1b0 100644 --- a/internal/data/assets/plugin_616d656c6961626f6f6b696e67811c9dc5_gen.json +++ b/internal/data/assets/plugin_616d656c6961626f6f6b696e67811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/04597908-7086-4158-ae2b-8aa634a217c6/ameliabooking","title":"Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"04597908-7086-4158-ae2b-8aa634a217c6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/04597908-7086-4158-ae2b-8aa634a217c6?source=api-prod","cve":"CVE-2024-6225","affectedVersions":"<=1.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/1bfc5467-6610-4516-8c50-d47d05e2677d/ameliabooking","title":"Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-31 10:30:53","sources":[{"name":"Wordfence","remoteId":"1bfc5467-6610-4516-8c50-d47d05e2677d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1bfc5467-6610-4516-8c50-d47d05e2677d?source=api-prod","cve":"CVE-2026-4668","affectedVersions":"<=2.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/25a80b0b-2636-45c1-92e5-bd62c8a4ab20/ameliabooking","title":"Appointment and Event Booking Calendar for WordPress – Amelia < 1.0.49 - Arbitrary Booking Update and Sensitive Data Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"25a80b0b-2636-45c1-92e5-bd62c8a4ab20"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/25a80b0b-2636-45c1-92e5-bd62c8a4ab20?source=api-prod","cve":"CVE-2022-0825","affectedVersions":"<1.0.49","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ac1e3ee-4dcc-4f45-ad07-17af750da3d1/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-04 21:24:51","sources":[{"name":"Wordfence","remoteId":"2ac1e3ee-4dcc-4f45-ad07-17af750da3d1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ac1e3ee-4dcc-4f45-ad07-17af750da3d1?source=api-prod","cve":"CVE-2024-6332","affectedVersions":"<=1.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/33398af8-7b7f-47e5-b95b-c9faa33d0c80/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.0.85 - Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"33398af8-7b7f-47e5-b95b-c9faa33d0c80"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/33398af8-7b7f-47e5-b95b-c9faa33d0c80?source=api-prod","cve":"CVE-2023-50860","affectedVersions":"<=1.0.85","severity":"medium"},{"advisoryId":"WPSECADV/WF/39005c38-f60d-44fa-9121-a77039dc34de/ameliabooking","title":"Amelia <= 1.0.98 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"39005c38-f60d-44fa-9121-a77039dc34de"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39005c38-f60d-44fa-9121-a77039dc34de?source=api-prod","cve":"CVE-2024-22298","affectedVersions":"<=1.0.98","severity":"medium"},{"advisoryId":"WPSECADV/WF/3a849ef2-ad0a-45ea-8827-9a7233b1ca30/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.0.98 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"3a849ef2-ad0a-45ea-8827-9a7233b1ca30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3a849ef2-ad0a-45ea-8827-9a7233b1ca30?source=api-prod","cve":"CVE-2024-1484","affectedVersions":"<=1.0.98","severity":"medium"},{"advisoryId":"WPSECADV/WF/3bc19aca-15df-40c8-a7c4-10ae7faf0308/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Authenticated (Employee+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"3bc19aca-15df-40c8-a7c4-10ae7faf0308"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3bc19aca-15df-40c8-a7c4-10ae7faf0308?source=api-prod","cve":"CVE-2026-24963","affectedVersions":"<=1.2.38","severity":"high"},{"advisoryId":"WPSECADV/WF/5cd8c464-1402-4301-ac66-4e6fc0328de2/ameliabooking","title":"Amelia <= 1.2.16 - Unauthenticated Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5cd8c464-1402-4301-ac66-4e6fc0328de2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5cd8c464-1402-4301-ac66-4e6fc0328de2?source=api-prod","cve":"CVE-2025-26965","affectedVersions":"<=1.2.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/5dc278a9-79bd-4494-a34c-a5e92cde7062/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 2.2 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5dc278a9-79bd-4494-a34c-a5e92cde7062"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5dc278a9-79bd-4494-a34c-a5e92cde7062?source=api-prod","cve":"CVE-2026-40789","affectedVersions":"<=2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/60c2e8eb-d01b-44f2-8e0d-009ff00887fd/ameliabooking","title":"Appointment and Event Booking Calendar for WordPress - Amelia < 1.0.47 - Arbitrary Booking Update and Sensitive Data Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"60c2e8eb-d01b-44f2-8e0d-009ff00887fd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/60c2e8eb-d01b-44f2-8e0d-009ff00887fd?source=api-prod","cve":"CVE-2022-0720","affectedVersions":"<1.0.47","severity":"medium"},{"advisoryId":"WPSECADV/WF/6806e07b-96bf-43ad-a3ac-2105e7449e3c/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"6806e07b-96bf-43ad-a3ac-2105e7449e3c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6806e07b-96bf-43ad-a3ac-2105e7449e3c?source=api-prod","cve":"CVE-2025-2578","affectedVersions":"<=1.2.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/694fe940-3d0a-4a71-99d3-bcf3a8010585/ameliabooking","title":"Amelia <= 1.0.46 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"694fe940-3d0a-4a71-99d3-bcf3a8010585"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/694fe940-3d0a-4a71-99d3-bcf3a8010585?source=api-prod","cve":"CVE-2022-0616","affectedVersions":"<=1.0.46","severity":"medium"},{"advisoryId":"WPSECADV/WF/73f12f22-c0a4-4010-9634-ce7308254028/ameliabooking","title":"Amelia <= 1.0.46 - Stored Cross Site Scripting via lastName\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"73f12f22-c0a4-4010-9634-ce7308254028"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/73f12f22-c0a4-4010-9634-ce7308254028?source=api-prod","cve":"CVE-2022-0834","affectedVersions":"<=1.0.46","severity":"high"},{"advisoryId":"WPSECADV/WF/771ed385-587c-400f-89c6-1a827c3e2c79/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 17:39:35","sources":[{"name":"Wordfence","remoteId":"771ed385-587c-400f-89c6-1a827c3e2c79"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/771ed385-587c-400f-89c6-1a827c3e2c79?source=api-prod","cve":"CVE-2025-14720","affectedVersions":"<=1.2.38","severity":"medium"},{"advisoryId":"WPSECADV/WF/7eb0f690-c977-43de-a713-9d02ee99ba2e/ameliabooking","title":"Amelia 1.2.18 - 1.2.36 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"7eb0f690-c977-43de-a713-9d02ee99ba2e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7eb0f690-c977-43de-a713-9d02ee99ba2e?source=api-prod","cve":"CVE-2023-49282","affectedVersions":">=1.2.18,<=1.2.36","severity":"medium"},{"advisoryId":"WPSECADV/WF/8a41f96d-216f-4e5a-a28d-665b052666fb/ameliabooking","title":"Amelia <= 1.0.75 - Unauthenticated Reflected Cross-Site Scripting via 'code'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"8a41f96d-216f-4e5a-a28d-665b052666fb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8a41f96d-216f-4e5a-a28d-665b052666fb?source=api-prod","cve":"CVE-2023-29427","affectedVersions":"<=1.0.75","severity":"medium"},{"advisoryId":"WPSECADV/WF/8d7cc468-eeba-497f-9e11-79d4bebdd7a2/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 2.1.2 - Unauthenticated Authorization Bypass via Remote Approval Endpoint\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-01 19:17:26","sources":[{"name":"Wordfence","remoteId":"8d7cc468-eeba-497f-9e11-79d4bebdd7a2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8d7cc468-eeba-497f-9e11-79d4bebdd7a2?source=api-prod","cve":"CVE-2026-6449","affectedVersions":"<=2.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9dbaafbb-ab7b-41d8-a8f7-178b9d42b4c5/ameliabooking","title":"Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-25 15:31:53","sources":[{"name":"Wordfence","remoteId":"9dbaafbb-ab7b-41d8-a8f7-178b9d42b4c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9dbaafbb-ab7b-41d8-a8f7-178b9d42b4c5?source=api-prod","cve":"CVE-2026-2931","affectedVersions":"<=9.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/a4204099-1065-4167-8b42-3da25945236c/ameliabooking","title":"Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-06 18:13:11","sources":[{"name":"Wordfence","remoteId":"a4204099-1065-4167-8b42-3da25945236c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4204099-1065-4167-8b42-3da25945236c?source=api-prod","cve":"CVE-2026-5465","affectedVersions":"<=2.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/a4a0bf16-1a13-4955-8198-fa195fb65905/ameliabooking","title":"Appointment and Event Booking Calendar for WordPress – Amelia <= 1.0.47 - Information Disclosure and SMS Spam\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"a4a0bf16-1a13-4955-8198-fa195fb65905"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4a0bf16-1a13-4955-8198-fa195fb65905?source=api-prod","cve":"CVE-2022-0837","affectedVersions":"<1.0.48","severity":"medium"},{"advisoryId":"WPSECADV/WF/a7764ea4-6c4b-47cf-a711-b92e56e03d3a/ameliabooking","title":"Amelia <= 2.1.1 - Authenticated (Custom role+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"a7764ea4-6c4b-47cf-a711-b92e56e03d3a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a7764ea4-6c4b-47cf-a711-b92e56e03d3a?source=api-prod","cve":"CVE-2026-39487","affectedVersions":"<=2.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/aafb5402-3553-4c89-86e0-4dd556d86074/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"aafb5402-3553-4c89-86e0-4dd556d86074"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aafb5402-3553-4c89-86e0-4dd556d86074?source=api-prod","cve":"CVE-2023-6808","affectedVersions":"<=1.0.93","severity":"medium"},{"advisoryId":"WPSECADV/WF/b9d288b8-a0de-493b-b677-3f9bf8211504/ameliabooking","title":"Amelia <= 1.2.38 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"b9d288b8-a0de-493b-b677-3f9bf8211504"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b9d288b8-a0de-493b-b677-3f9bf8211504?source=api-prod","cve":"CVE-2026-24967","affectedVersions":"<=1.2.38","severity":"medium"},{"advisoryId":"WPSECADV/WF/bba7fde9-0718-4681-9a1b-7c77bc0affbd/ameliabooking","title":"Amelia <= 1.0.46 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"bba7fde9-0718-4681-9a1b-7c77bc0affbd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bba7fde9-0718-4681-9a1b-7c77bc0affbd?source=api-prod","cve":"CVE-2022-0627","affectedVersions":"<=1.0.46","severity":"medium"},{"advisoryId":"WPSECADV/WF/bdd70819-57dd-4a60-9398-68d6b87da3ca/ameliabooking","title":"Appointment and Event Booking Calendar - Amelia < 1.0.47 - Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"bdd70819-57dd-4a60-9398-68d6b87da3ca"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bdd70819-57dd-4a60-9398-68d6b87da3ca?source=api-prod","cve":"CVE-2022-0687","affectedVersions":"<1.0.47","severity":"high"},{"advisoryId":"WPSECADV/WF/c9aa2a44-5a71-4a10-9876-3d54b8d268c5/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-07 14:41:09","sources":[{"name":"Wordfence","remoteId":"c9aa2a44-5a71-4a10-9876-3d54b8d268c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c9aa2a44-5a71-4a10-9876-3d54b8d268c5?source=api-prod","cve":"CVE-2024-6552","affectedVersions":"<=1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/cacf2e32-12cf-41a9-a57f-1135c165494c/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via search\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-15 15:54:28","sources":[{"name":"Wordfence","remoteId":"cacf2e32-12cf-41a9-a57f-1135c165494c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cacf2e32-12cf-41a9-a57f-1135c165494c?source=api-prod","cve":"CVE-2025-12482","affectedVersions":"<=1.2.35","severity":"high"},{"advisoryId":"WPSECADV/WF/ea984974-2835-4bad-b7ca-975ad21c80e5/ameliabooking","title":"Amelia <= 1.0.95 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"ea984974-2835-4bad-b7ca-975ad21c80e5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ea984974-2835-4bad-b7ca-975ad21c80e5?source=api-prod","cve":"CVE-2024-31425","affectedVersions":"<=1.0.95","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/04597908-7086-4158-ae2b-8aa634a217c6/ameliabooking","title":"Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"04597908-7086-4158-ae2b-8aa634a217c6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/04597908-7086-4158-ae2b-8aa634a217c6?source=api-prod","cve":"CVE-2024-6225","affectedVersions":"<=1.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/1bfc5467-6610-4516-8c50-d47d05e2677d/ameliabooking","title":"Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-31 10:30:53","sources":[{"name":"Wordfence","remoteId":"1bfc5467-6610-4516-8c50-d47d05e2677d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1bfc5467-6610-4516-8c50-d47d05e2677d?source=api-prod","cve":"CVE-2026-4668","affectedVersions":"<=2.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/25a80b0b-2636-45c1-92e5-bd62c8a4ab20/ameliabooking","title":"Appointment and Event Booking Calendar for WordPress – Amelia < 1.0.49 - Arbitrary Booking Update and Sensitive Data Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"25a80b0b-2636-45c1-92e5-bd62c8a4ab20"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/25a80b0b-2636-45c1-92e5-bd62c8a4ab20?source=api-prod","cve":"CVE-2022-0825","affectedVersions":"<1.0.49","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ac1e3ee-4dcc-4f45-ad07-17af750da3d1/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-04 21:24:51","sources":[{"name":"Wordfence","remoteId":"2ac1e3ee-4dcc-4f45-ad07-17af750da3d1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ac1e3ee-4dcc-4f45-ad07-17af750da3d1?source=api-prod","cve":"CVE-2024-6332","affectedVersions":"<=1.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/33398af8-7b7f-47e5-b95b-c9faa33d0c80/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.0.85 - Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"33398af8-7b7f-47e5-b95b-c9faa33d0c80"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/33398af8-7b7f-47e5-b95b-c9faa33d0c80?source=api-prod","cve":"CVE-2023-50860","affectedVersions":"<=1.0.85","severity":"medium"},{"advisoryId":"WPSECADV/WF/359aae96-8b6d-4365-b0c1-f0c7220383c9/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 2.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"359aae96-8b6d-4365-b0c1-f0c7220383c9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/359aae96-8b6d-4365-b0c1-f0c7220383c9?source=api-prod","cve":"CVE-2026-40795","affectedVersions":"<=2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/39005c38-f60d-44fa-9121-a77039dc34de/ameliabooking","title":"Amelia <= 1.0.98 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"39005c38-f60d-44fa-9121-a77039dc34de"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39005c38-f60d-44fa-9121-a77039dc34de?source=api-prod","cve":"CVE-2024-22298","affectedVersions":"<=1.0.98","severity":"medium"},{"advisoryId":"WPSECADV/WF/3a849ef2-ad0a-45ea-8827-9a7233b1ca30/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.0.98 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"3a849ef2-ad0a-45ea-8827-9a7233b1ca30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3a849ef2-ad0a-45ea-8827-9a7233b1ca30?source=api-prod","cve":"CVE-2024-1484","affectedVersions":"<=1.0.98","severity":"medium"},{"advisoryId":"WPSECADV/WF/3bc19aca-15df-40c8-a7c4-10ae7faf0308/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Authenticated (Employee+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"3bc19aca-15df-40c8-a7c4-10ae7faf0308"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3bc19aca-15df-40c8-a7c4-10ae7faf0308?source=api-prod","cve":"CVE-2026-24963","affectedVersions":"<=1.2.38","severity":"high"},{"advisoryId":"WPSECADV/WF/5cd8c464-1402-4301-ac66-4e6fc0328de2/ameliabooking","title":"Amelia <= 1.2.16 - Unauthenticated Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5cd8c464-1402-4301-ac66-4e6fc0328de2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5cd8c464-1402-4301-ac66-4e6fc0328de2?source=api-prod","cve":"CVE-2025-26965","affectedVersions":"<=1.2.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/5dc278a9-79bd-4494-a34c-a5e92cde7062/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 2.2 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5dc278a9-79bd-4494-a34c-a5e92cde7062"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5dc278a9-79bd-4494-a34c-a5e92cde7062?source=api-prod","cve":"CVE-2026-40789","affectedVersions":"<=2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/60c2e8eb-d01b-44f2-8e0d-009ff00887fd/ameliabooking","title":"Appointment and Event Booking Calendar for WordPress - Amelia < 1.0.47 - Arbitrary Booking Update and Sensitive Data Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"60c2e8eb-d01b-44f2-8e0d-009ff00887fd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/60c2e8eb-d01b-44f2-8e0d-009ff00887fd?source=api-prod","cve":"CVE-2022-0720","affectedVersions":"<1.0.47","severity":"medium"},{"advisoryId":"WPSECADV/WF/6806e07b-96bf-43ad-a3ac-2105e7449e3c/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"6806e07b-96bf-43ad-a3ac-2105e7449e3c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6806e07b-96bf-43ad-a3ac-2105e7449e3c?source=api-prod","cve":"CVE-2025-2578","affectedVersions":"<=1.2.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/694fe940-3d0a-4a71-99d3-bcf3a8010585/ameliabooking","title":"Amelia <= 1.0.46 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"694fe940-3d0a-4a71-99d3-bcf3a8010585"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/694fe940-3d0a-4a71-99d3-bcf3a8010585?source=api-prod","cve":"CVE-2022-0616","affectedVersions":"<=1.0.46","severity":"medium"},{"advisoryId":"WPSECADV/WF/73f12f22-c0a4-4010-9634-ce7308254028/ameliabooking","title":"Amelia <= 1.0.46 - Stored Cross Site Scripting via lastName\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"73f12f22-c0a4-4010-9634-ce7308254028"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/73f12f22-c0a4-4010-9634-ce7308254028?source=api-prod","cve":"CVE-2022-0834","affectedVersions":"<=1.0.46","severity":"high"},{"advisoryId":"WPSECADV/WF/771ed385-587c-400f-89c6-1a827c3e2c79/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 17:39:35","sources":[{"name":"Wordfence","remoteId":"771ed385-587c-400f-89c6-1a827c3e2c79"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/771ed385-587c-400f-89c6-1a827c3e2c79?source=api-prod","cve":"CVE-2025-14720","affectedVersions":"<=1.2.38","severity":"medium"},{"advisoryId":"WPSECADV/WF/7eb0f690-c977-43de-a713-9d02ee99ba2e/ameliabooking","title":"Amelia 1.2.18 - 1.2.36 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"7eb0f690-c977-43de-a713-9d02ee99ba2e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7eb0f690-c977-43de-a713-9d02ee99ba2e?source=api-prod","cve":"CVE-2023-49282","affectedVersions":">=1.2.18,<=1.2.36","severity":"medium"},{"advisoryId":"WPSECADV/WF/8a41f96d-216f-4e5a-a28d-665b052666fb/ameliabooking","title":"Amelia <= 1.0.75 - Unauthenticated Reflected Cross-Site Scripting via 'code'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"8a41f96d-216f-4e5a-a28d-665b052666fb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8a41f96d-216f-4e5a-a28d-665b052666fb?source=api-prod","cve":"CVE-2023-29427","affectedVersions":"<=1.0.75","severity":"medium"},{"advisoryId":"WPSECADV/WF/8d7cc468-eeba-497f-9e11-79d4bebdd7a2/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 2.1.2 - Unauthenticated Authorization Bypass via Remote Approval Endpoint\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-01 19:17:26","sources":[{"name":"Wordfence","remoteId":"8d7cc468-eeba-497f-9e11-79d4bebdd7a2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8d7cc468-eeba-497f-9e11-79d4bebdd7a2?source=api-prod","cve":"CVE-2026-6449","affectedVersions":"<=2.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9dbaafbb-ab7b-41d8-a8f7-178b9d42b4c5/ameliabooking","title":"Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-25 15:31:53","sources":[{"name":"Wordfence","remoteId":"9dbaafbb-ab7b-41d8-a8f7-178b9d42b4c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9dbaafbb-ab7b-41d8-a8f7-178b9d42b4c5?source=api-prod","cve":"CVE-2026-2931","affectedVersions":"<=9.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/a4204099-1065-4167-8b42-3da25945236c/ameliabooking","title":"Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-06 18:13:11","sources":[{"name":"Wordfence","remoteId":"a4204099-1065-4167-8b42-3da25945236c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4204099-1065-4167-8b42-3da25945236c?source=api-prod","cve":"CVE-2026-5465","affectedVersions":"<=2.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/a4a0bf16-1a13-4955-8198-fa195fb65905/ameliabooking","title":"Appointment and Event Booking Calendar for WordPress – Amelia <= 1.0.47 - Information Disclosure and SMS Spam\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"a4a0bf16-1a13-4955-8198-fa195fb65905"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4a0bf16-1a13-4955-8198-fa195fb65905?source=api-prod","cve":"CVE-2022-0837","affectedVersions":"<1.0.48","severity":"medium"},{"advisoryId":"WPSECADV/WF/a7764ea4-6c4b-47cf-a711-b92e56e03d3a/ameliabooking","title":"Amelia <= 2.1.1 - Authenticated (Custom role+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"a7764ea4-6c4b-47cf-a711-b92e56e03d3a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a7764ea4-6c4b-47cf-a711-b92e56e03d3a?source=api-prod","cve":"CVE-2026-39487","affectedVersions":"<=2.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/aafb5402-3553-4c89-86e0-4dd556d86074/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"aafb5402-3553-4c89-86e0-4dd556d86074"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aafb5402-3553-4c89-86e0-4dd556d86074?source=api-prod","cve":"CVE-2023-6808","affectedVersions":"<=1.0.93","severity":"medium"},{"advisoryId":"WPSECADV/WF/b9d288b8-a0de-493b-b677-3f9bf8211504/ameliabooking","title":"Amelia <= 1.2.38 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"b9d288b8-a0de-493b-b677-3f9bf8211504"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b9d288b8-a0de-493b-b677-3f9bf8211504?source=api-prod","cve":"CVE-2026-24967","affectedVersions":"<=1.2.38","severity":"medium"},{"advisoryId":"WPSECADV/WF/bba7fde9-0718-4681-9a1b-7c77bc0affbd/ameliabooking","title":"Amelia <= 1.0.46 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"bba7fde9-0718-4681-9a1b-7c77bc0affbd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bba7fde9-0718-4681-9a1b-7c77bc0affbd?source=api-prod","cve":"CVE-2022-0627","affectedVersions":"<=1.0.46","severity":"medium"},{"advisoryId":"WPSECADV/WF/bdd70819-57dd-4a60-9398-68d6b87da3ca/ameliabooking","title":"Appointment and Event Booking Calendar - Amelia < 1.0.47 - Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"bdd70819-57dd-4a60-9398-68d6b87da3ca"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bdd70819-57dd-4a60-9398-68d6b87da3ca?source=api-prod","cve":"CVE-2022-0687","affectedVersions":"<1.0.47","severity":"high"},{"advisoryId":"WPSECADV/WF/c9aa2a44-5a71-4a10-9876-3d54b8d268c5/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-07 14:41:09","sources":[{"name":"Wordfence","remoteId":"c9aa2a44-5a71-4a10-9876-3d54b8d268c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c9aa2a44-5a71-4a10-9876-3d54b8d268c5?source=api-prod","cve":"CVE-2024-6552","affectedVersions":"<=1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/cacf2e32-12cf-41a9-a57f-1135c165494c/ameliabooking","title":"Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via search\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-15 15:54:28","sources":[{"name":"Wordfence","remoteId":"cacf2e32-12cf-41a9-a57f-1135c165494c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cacf2e32-12cf-41a9-a57f-1135c165494c?source=api-prod","cve":"CVE-2025-12482","affectedVersions":"<=1.2.35","severity":"high"},{"advisoryId":"WPSECADV/WF/ea984974-2835-4bad-b7ca-975ad21c80e5/ameliabooking","title":"Amelia <= 1.0.95 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"ea984974-2835-4bad-b7ca-975ad21c80e5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ea984974-2835-4bad-b7ca-975ad21c80e5?source=api-prod","cve":"CVE-2024-31425","affectedVersions":"<=1.0.95","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_616e6f746865722d776f726470726573732d636c6173736966696564732d706c7567696e811c9dc5_gen.json b/internal/data/assets/plugin_616e6f746865722d776f726470726573732d636c6173736966696564732d706c7567696e811c9dc5_gen.json index f6e9726d..6018ab31 100644 --- a/internal/data/assets/plugin_616e6f746865722d776f726470726573732d636c6173736966696564732d706c7567696e811c9dc5_gen.json +++ b/internal/data/assets/plugin_616e6f746865722d776f726470726573732d636c6173736966696564732d706c7567696e811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0a8de5b1-fefc-40b0-8f4d-435e6bd2f452/another-wordpress-classifieds-plugin","title":"WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 3.0 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-11-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"0a8de5b1-fefc-40b0-8f4d-435e6bd2f452"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0a8de5b1-fefc-40b0-8f4d-435e6bd2f452?source=api-prod","cve":"CVE-2014-10013","affectedVersions":"<3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/2a5ea5b6-4c34-4d77-9a3a-af53b914a72a/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.4.3 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"2a5ea5b6-4c34-4d77-9a3a-af53b914a72a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2a5ea5b6-4c34-4d77-9a3a-af53b914a72a?source=api-prod","cve":"CVE-2025-57928","affectedVersions":"<=4.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/3de27b2e-2196-4b8e-816c-729462a172d0/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"3de27b2e-2196-4b8e-816c-729462a172d0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3de27b2e-2196-4b8e-816c-729462a172d0?source=api-prod","cve":"CVE-2022-3254","affectedVersions":"<=4.2.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/4d19c023-4aa1-40ec-a87b-dcde945e7a2c/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.4.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d19c023-4aa1-40ec-a87b-dcde945e7a2c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d19c023-4aa1-40ec-a87b-dcde945e7a2c?source=api-prod","cve":"CVE-2026-39533","affectedVersions":"<=4.4.4","severity":"high"},{"advisoryId":"WPSECADV/WF/782e954f-1fdf-49fa-97bc-60f8fb8c4ecd/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.3.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"782e954f-1fdf-49fa-97bc-60f8fb8c4ecd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/782e954f-1fdf-49fa-97bc-60f8fb8c4ecd?source=api-prod","cve":"CVE-2024-31350","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/a52ed75b-07ce-46dc-8321-d10074ce0f61/another-wordpress-classifieds-plugin","title":"WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds <= 3.3.1 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-12-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"a52ed75b-07ce-46dc-8321-d10074ce0f61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a52ed75b-07ce-46dc-8321-d10074ce0f61?source=api-prod","affectedVersions":"<=3.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/b06a1b66-9057-4f16-878c-4fa66489f0ff/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.3 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"b06a1b66-9057-4f16-878c-4fa66489f0ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b06a1b66-9057-4f16-878c-4fa66489f0ff?source=api-prod","cve":"CVE-2023-41801","affectedVersions":"<=4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/da3b7218-4655-4def-a3f9-9931d6943583/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.4.3 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"da3b7218-4655-4def-a3f9-9931d6943583"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/da3b7218-4655-4def-a3f9-9931d6943583?source=api-prod","cve":"CVE-2026-24593","affectedVersions":"<=4.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/e7613875-b44e-4b91-9a5b-41ea0854cd61/another-wordpress-classifieds-plugin","title":"WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 2.0 - Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2012-04-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7613875-b44e-4b91-9a5b-41ea0854cd61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7613875-b44e-4b91-9a5b-41ea0854cd61?source=api-prod","cve":"CVE-2012-4874","affectedVersions":"<2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/ec395e79-b82a-45c3-a704-a15a5efaf26d/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.3.1 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"ec395e79-b82a-45c3-a704-a15a5efaf26d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ec395e79-b82a-45c3-a704-a15a5efaf26d?source=api-prod","cve":"CVE-2024-32447","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/fd8a4296-8a6e-4455-8a69-87cace9199a9/another-wordpress-classifieds-plugin","title":"WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 3.0 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd8a4296-8a6e-4455-8a69-87cace9199a9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd8a4296-8a6e-4455-8a69-87cace9199a9?source=api-prod","cve":"CVE-2014-10012","affectedVersions":"<3.0","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0a8de5b1-fefc-40b0-8f4d-435e6bd2f452/another-wordpress-classifieds-plugin","title":"WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 3.0 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-11-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"0a8de5b1-fefc-40b0-8f4d-435e6bd2f452"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0a8de5b1-fefc-40b0-8f4d-435e6bd2f452?source=api-prod","cve":"CVE-2014-10013","affectedVersions":"<3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/2a5ea5b6-4c34-4d77-9a3a-af53b914a72a/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.4.3 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"2a5ea5b6-4c34-4d77-9a3a-af53b914a72a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2a5ea5b6-4c34-4d77-9a3a-af53b914a72a?source=api-prod","cve":"CVE-2025-57928","affectedVersions":"<=4.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/3de27b2e-2196-4b8e-816c-729462a172d0/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"3de27b2e-2196-4b8e-816c-729462a172d0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3de27b2e-2196-4b8e-816c-729462a172d0?source=api-prod","cve":"CVE-2022-3254","affectedVersions":"<=4.2.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/4d19c023-4aa1-40ec-a87b-dcde945e7a2c/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.4.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d19c023-4aa1-40ec-a87b-dcde945e7a2c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d19c023-4aa1-40ec-a87b-dcde945e7a2c?source=api-prod","cve":"CVE-2026-39533","affectedVersions":"<=4.4.4","severity":"high"},{"advisoryId":"WPSECADV/WF/782e954f-1fdf-49fa-97bc-60f8fb8c4ecd/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.3.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"782e954f-1fdf-49fa-97bc-60f8fb8c4ecd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/782e954f-1fdf-49fa-97bc-60f8fb8c4ecd?source=api-prod","cve":"CVE-2024-31350","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/7908d167-f831-4ed0-b754-2b390b5c3b2c/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.4.5 - Unauthenticated SQL Injection via 'regions'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:11:27","sources":[{"name":"Wordfence","remoteId":"7908d167-f831-4ed0-b754-2b390b5c3b2c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7908d167-f831-4ed0-b754-2b390b5c3b2c?source=api-prod","cve":"CVE-2026-5100","affectedVersions":"<=4.4.5","severity":"high"},{"advisoryId":"WPSECADV/WF/a52ed75b-07ce-46dc-8321-d10074ce0f61/another-wordpress-classifieds-plugin","title":"WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds <= 3.3.1 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-12-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"a52ed75b-07ce-46dc-8321-d10074ce0f61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a52ed75b-07ce-46dc-8321-d10074ce0f61?source=api-prod","affectedVersions":"<=3.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/b06a1b66-9057-4f16-878c-4fa66489f0ff/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.3 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"b06a1b66-9057-4f16-878c-4fa66489f0ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b06a1b66-9057-4f16-878c-4fa66489f0ff?source=api-prod","cve":"CVE-2023-41801","affectedVersions":"<=4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/da3b7218-4655-4def-a3f9-9931d6943583/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.4.3 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"da3b7218-4655-4def-a3f9-9931d6943583"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/da3b7218-4655-4def-a3f9-9931d6943583?source=api-prod","cve":"CVE-2026-24593","affectedVersions":"<=4.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/e7613875-b44e-4b91-9a5b-41ea0854cd61/another-wordpress-classifieds-plugin","title":"WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 2.0 - Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2012-04-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7613875-b44e-4b91-9a5b-41ea0854cd61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7613875-b44e-4b91-9a5b-41ea0854cd61?source=api-prod","cve":"CVE-2012-4874","affectedVersions":"<2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/ec395e79-b82a-45c3-a704-a15a5efaf26d/another-wordpress-classifieds-plugin","title":"AWP Classifieds <= 4.3.1 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"ec395e79-b82a-45c3-a704-a15a5efaf26d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ec395e79-b82a-45c3-a704-a15a5efaf26d?source=api-prod","cve":"CVE-2024-32447","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/fd8a4296-8a6e-4455-8a69-87cace9199a9/another-wordpress-classifieds-plugin","title":"WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds < 3.0 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd8a4296-8a6e-4455-8a69-87cace9199a9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd8a4296-8a6e-4455-8a69-87cace9199a9?source=api-prod","cve":"CVE-2014-10012","affectedVersions":"<3.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_61746172696d2d76697375616c2d636f6c6c61626f726174696f6e811c9dc5_gen.json b/internal/data/assets/plugin_61746172696d2d76697375616c2d636f6c6c61626f726174696f6e811c9dc5_gen.json index 03b74f35..60c32ab4 100644 --- a/internal/data/assets/plugin_61746172696d2d76697375616c2d636f6c6c61626f726174696f6e811c9dc5_gen.json +++ b/internal/data/assets/plugin_61746172696d2d76697375616c2d636f6c6c61626f726174696f6e811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/15f3a6e1-6126-4825-b2b1-e40dc5694f43/atarim-visual-collaboration","title":"Atarim - Client Interface <= 3.9.1 - Missing Authorization via AJAX actions\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"15f3a6e1-6126-4825-b2b1-e40dc5694f43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/15f3a6e1-6126-4825-b2b1-e40dc5694f43?source=api-prod","affectedVersions":"<3.9.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/29532f4d-e830-4c99-ad77-076eebbbe98d/atarim-visual-collaboration","title":"Visual Website Collaboration, Feedback & Project Management – Atarim <= 3.22.6 - Hardcoded Credentials\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"29532f4d-e830-4c99-ad77-076eebbbe98d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/29532f4d-e830-4c99-ad77-076eebbbe98d?source=api-prod","cve":"CVE-2024-2038","affectedVersions":"<=3.22.6","severity":"high"},{"advisoryId":"WPSECADV/WF/379a7767-bb88-446f-806b-7a8e5c0584a6/atarim-visual-collaboration","title":"Atarim <= 4.3.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"379a7767-bb88-446f-806b-7a8e5c0584a6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/379a7767-bb88-446f-806b-7a8e5c0584a6?source=api-prod","cve":"CVE-2026-32447","affectedVersions":"<=4.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/444fae52-ffcb-4502-a052-239693bfa326/atarim-visual-collaboration","title":"Atarim <= 4.2.1 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"444fae52-ffcb-4502-a052-239693bfa326"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/444fae52-ffcb-4502-a052-239693bfa326?source=api-prod","cve":"CVE-2025-60187","affectedVersions":"<=4.2.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/470fb8d4-3d60-4a8e-a89b-2d64203c1f0b/atarim-visual-collaboration","title":"Atarim <= 4.2.1 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"470fb8d4-3d60-4a8e-a89b-2d64203c1f0b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/470fb8d4-3d60-4a8e-a89b-2d64203c1f0b?source=api-prod","cve":"CVE-2025-62895","affectedVersions":"<=4.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/47b0a994-0460-44fb-bebd-d09efc69a8f3/atarim-visual-collaboration","title":"Atarim <= 4.3.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"47b0a994-0460-44fb-bebd-d09efc69a8f3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/47b0a994-0460-44fb-bebd-d09efc69a8f3?source=api-prod","cve":"CVE-2026-25019","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/4f5919eb-ac74-4926-9ede-e651bb4463b2/atarim-visual-collaboration","title":"Atarim <= 3.12 - Unauthenticated Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"4f5919eb-ac74-4926-9ede-e651bb4463b2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4f5919eb-ac74-4926-9ede-e651bb4463b2?source=api-prod","cve":"CVE-2023-47544","affectedVersions":"<=3.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/5853aa0c-09cf-4af8-b75a-4ec95dfe94c3/atarim-visual-collaboration","title":"Atarim <= 3.31 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"5853aa0c-09cf-4af8-b75a-4ec95dfe94c3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5853aa0c-09cf-4af8-b75a-4ec95dfe94c3?source=api-prod","cve":"CVE-2024-37434","affectedVersions":"<=3.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/5cbbe2c5-2a5d-4d87-a0b5-07c3583311ec/atarim-visual-collaboration","title":"Atarim <= 4.1.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5cbbe2c5-2a5d-4d87-a0b5-07c3583311ec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5cbbe2c5-2a5d-4d87-a0b5-07c3583311ec?source=api-prod","cve":"CVE-2025-26993","affectedVersions":"<=4.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/6a6c46a2-96de-49d1-ac3b-448ccb837d78/atarim-visual-collaboration","title":"Atarim <= 4.2.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"6a6c46a2-96de-49d1-ac3b-448ccb837d78"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6a6c46a2-96de-49d1-ac3b-448ccb837d78?source=api-prod","cve":"CVE-2025-67993","affectedVersions":"<=4.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/7d40c658-a156-470e-bf93-a1f2ccec9c61/atarim-visual-collaboration","title":"Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"7d40c658-a156-470e-bf93-a1f2ccec9c61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7d40c658-a156-470e-bf93-a1f2ccec9c61?source=api-prod","cve":"CVE-2024-12104","affectedVersions":"<=4.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/7f17e055-ad49-4115-89c5-dd76b6c531f7/atarim-visual-collaboration","title":"Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-09 13:41:33","sources":[{"name":"Wordfence","remoteId":"7f17e055-ad49-4115-89c5-dd76b6c531f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7f17e055-ad49-4115-89c5-dd76b6c531f7?source=api-prod","cve":"CVE-2024-7621","affectedVersions":"<=4.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/829a19fc-f262-4b67-b499-76580779eb9a/atarim-visual-collaboration","title":"Atarim <= 4.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"829a19fc-f262-4b67-b499-76580779eb9a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/829a19fc-f262-4b67-b499-76580779eb9a?source=api-prod","cve":"CVE-2024-38771","affectedVersions":"<=4.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/8edf693e-8a84-4f0c-a169-605522603fe9/atarim-visual-collaboration","title":"Atarim <= 4.2.1 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"8edf693e-8a84-4f0c-a169-605522603fe9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8edf693e-8a84-4f0c-a169-605522603fe9?source=api-prod","cve":"CVE-2025-60188","affectedVersions":"<=4.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/9bd63003-d1d6-480a-8df7-878bcc89f1ee/atarim-visual-collaboration","title":"Visual Website Collaboration, Feedback & Project Management – Atarim <= 3.30 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"9bd63003-d1d6-480a-8df7-878bcc89f1ee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9bd63003-d1d6-480a-8df7-878bcc89f1ee?source=api-prod","cve":"CVE-2024-2793","affectedVersions":"<=3.30","severity":"high"},{"advisoryId":"WPSECADV/WF/afbfef8e-cdea-4ca0-bd28-08cc30eeec6e/atarim-visual-collaboration","title":"Atarim <= 4.0.8 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"afbfef8e-cdea-4ca0-bd28-08cc30eeec6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/afbfef8e-cdea-4ca0-bd28-08cc30eeec6e?source=api-prod","cve":"CVE-2025-24570","affectedVersions":"<=4.0.8","severity":"high"},{"advisoryId":"WPSECADV/WF/bc26ce1b-2427-4320-8363-f635ea02aece/atarim-visual-collaboration","title":"Atarim <= 3.9.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"bc26ce1b-2427-4320-8363-f635ea02aece"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bc26ce1b-2427-4320-8363-f635ea02aece?source=api-prod","cve":"CVE-2023-37393","affectedVersions":"<=3.9.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/c3ede2bc-15a6-4194-a963-d176cb0fc612/atarim-visual-collaboration","title":"Atarim <= 4.0.1 - Missing Authorization via remove_feedbacktool_notice()\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"c3ede2bc-15a6-4194-a963-d176cb0fc612"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c3ede2bc-15a6-4194-a963-d176cb0fc612?source=api-prod","cve":"CVE-2024-43290","affectedVersions":"<=4.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/fb7112bb-c76a-4665-b891-8c388ce05d51/atarim-visual-collaboration","title":"Atarim <= 4.2.1 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"fb7112bb-c76a-4665-b891-8c388ce05d51"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fb7112bb-c76a-4665-b891-8c388ce05d51?source=api-prod","cve":"CVE-2025-60195","affectedVersions":"<=4.2.1","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/15f3a6e1-6126-4825-b2b1-e40dc5694f43/atarim-visual-collaboration","title":"Atarim - Client Interface <= 3.9.1 - Missing Authorization via AJAX actions\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"15f3a6e1-6126-4825-b2b1-e40dc5694f43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/15f3a6e1-6126-4825-b2b1-e40dc5694f43?source=api-prod","affectedVersions":"<3.9.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/29532f4d-e830-4c99-ad77-076eebbbe98d/atarim-visual-collaboration","title":"Visual Website Collaboration, Feedback & Project Management – Atarim <= 3.22.6 - Hardcoded Credentials\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"29532f4d-e830-4c99-ad77-076eebbbe98d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/29532f4d-e830-4c99-ad77-076eebbbe98d?source=api-prod","cve":"CVE-2024-2038","affectedVersions":"<=3.22.6","severity":"high"},{"advisoryId":"WPSECADV/WF/379a7767-bb88-446f-806b-7a8e5c0584a6/atarim-visual-collaboration","title":"Atarim <= 4.3.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"379a7767-bb88-446f-806b-7a8e5c0584a6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/379a7767-bb88-446f-806b-7a8e5c0584a6?source=api-prod","cve":"CVE-2026-32447","affectedVersions":"<=4.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/444fae52-ffcb-4502-a052-239693bfa326/atarim-visual-collaboration","title":"Atarim <= 4.2.1 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"444fae52-ffcb-4502-a052-239693bfa326"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/444fae52-ffcb-4502-a052-239693bfa326?source=api-prod","cve":"CVE-2025-60187","affectedVersions":"<=4.2.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/470fb8d4-3d60-4a8e-a89b-2d64203c1f0b/atarim-visual-collaboration","title":"Atarim <= 4.2.1 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"470fb8d4-3d60-4a8e-a89b-2d64203c1f0b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/470fb8d4-3d60-4a8e-a89b-2d64203c1f0b?source=api-prod","cve":"CVE-2025-62895","affectedVersions":"<=4.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/47b0a994-0460-44fb-bebd-d09efc69a8f3/atarim-visual-collaboration","title":"Atarim <= 4.3.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"47b0a994-0460-44fb-bebd-d09efc69a8f3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/47b0a994-0460-44fb-bebd-d09efc69a8f3?source=api-prod","cve":"CVE-2026-25019","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/4f5919eb-ac74-4926-9ede-e651bb4463b2/atarim-visual-collaboration","title":"Atarim <= 3.12 - Unauthenticated Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"4f5919eb-ac74-4926-9ede-e651bb4463b2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4f5919eb-ac74-4926-9ede-e651bb4463b2?source=api-prod","cve":"CVE-2023-47544","affectedVersions":"<=3.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/5853aa0c-09cf-4af8-b75a-4ec95dfe94c3/atarim-visual-collaboration","title":"Atarim <= 3.31 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"5853aa0c-09cf-4af8-b75a-4ec95dfe94c3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5853aa0c-09cf-4af8-b75a-4ec95dfe94c3?source=api-prod","cve":"CVE-2024-37434","affectedVersions":"<=3.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/5cbbe2c5-2a5d-4d87-a0b5-07c3583311ec/atarim-visual-collaboration","title":"Atarim <= 4.1.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5cbbe2c5-2a5d-4d87-a0b5-07c3583311ec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5cbbe2c5-2a5d-4d87-a0b5-07c3583311ec?source=api-prod","cve":"CVE-2025-26993","affectedVersions":"<=4.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/6a3db653-c39f-4097-9d31-6d009a82c4a4/atarim-visual-collaboration","title":"Atarim <= 4.0.9 - Missing Authorization to Unauthenticated Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"6a3db653-c39f-4097-9d31-6d009a82c4a4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6a3db653-c39f-4097-9d31-6d009a82c4a4?source=api-prod","cve":"CVE-2025-22657","affectedVersions":"<=4.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/6a6c46a2-96de-49d1-ac3b-448ccb837d78/atarim-visual-collaboration","title":"Atarim <= 4.2.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"6a6c46a2-96de-49d1-ac3b-448ccb837d78"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6a6c46a2-96de-49d1-ac3b-448ccb837d78?source=api-prod","cve":"CVE-2025-67993","affectedVersions":"<=4.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/7d40c658-a156-470e-bf93-a1f2ccec9c61/atarim-visual-collaboration","title":"Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"7d40c658-a156-470e-bf93-a1f2ccec9c61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7d40c658-a156-470e-bf93-a1f2ccec9c61?source=api-prod","cve":"CVE-2024-12104","affectedVersions":"<=4.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/7f17e055-ad49-4115-89c5-dd76b6c531f7/atarim-visual-collaboration","title":"Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-09 13:41:33","sources":[{"name":"Wordfence","remoteId":"7f17e055-ad49-4115-89c5-dd76b6c531f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7f17e055-ad49-4115-89c5-dd76b6c531f7?source=api-prod","cve":"CVE-2024-7621","affectedVersions":"<=4.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/829a19fc-f262-4b67-b499-76580779eb9a/atarim-visual-collaboration","title":"Atarim <= 4.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"829a19fc-f262-4b67-b499-76580779eb9a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/829a19fc-f262-4b67-b499-76580779eb9a?source=api-prod","cve":"CVE-2024-38771","affectedVersions":"<=4.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/8edf693e-8a84-4f0c-a169-605522603fe9/atarim-visual-collaboration","title":"Atarim <= 4.2.1 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"8edf693e-8a84-4f0c-a169-605522603fe9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8edf693e-8a84-4f0c-a169-605522603fe9?source=api-prod","cve":"CVE-2025-60188","affectedVersions":"<=4.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/9bd63003-d1d6-480a-8df7-878bcc89f1ee/atarim-visual-collaboration","title":"Visual Website Collaboration, Feedback & Project Management – Atarim <= 3.30 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"9bd63003-d1d6-480a-8df7-878bcc89f1ee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9bd63003-d1d6-480a-8df7-878bcc89f1ee?source=api-prod","cve":"CVE-2024-2793","affectedVersions":"<=3.30","severity":"high"},{"advisoryId":"WPSECADV/WF/afbfef8e-cdea-4ca0-bd28-08cc30eeec6e/atarim-visual-collaboration","title":"Atarim <= 4.0.8 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"afbfef8e-cdea-4ca0-bd28-08cc30eeec6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/afbfef8e-cdea-4ca0-bd28-08cc30eeec6e?source=api-prod","cve":"CVE-2025-24570","affectedVersions":"<=4.0.8","severity":"high"},{"advisoryId":"WPSECADV/WF/bc26ce1b-2427-4320-8363-f635ea02aece/atarim-visual-collaboration","title":"Atarim <= 3.9.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"bc26ce1b-2427-4320-8363-f635ea02aece"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bc26ce1b-2427-4320-8363-f635ea02aece?source=api-prod","cve":"CVE-2023-37393","affectedVersions":"<=3.9.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/c3ede2bc-15a6-4194-a963-d176cb0fc612/atarim-visual-collaboration","title":"Atarim <= 4.0.1 - Missing Authorization via remove_feedbacktool_notice()\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"c3ede2bc-15a6-4194-a963-d176cb0fc612"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c3ede2bc-15a6-4194-a963-d176cb0fc612?source=api-prod","cve":"CVE-2024-43290","affectedVersions":"<=4.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/fb7112bb-c76a-4665-b891-8c388ce05d51/atarim-visual-collaboration","title":"Atarim <= 4.2.1 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"fb7112bb-c76a-4665-b891-8c388ce05d51"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fb7112bb-c76a-4665-b891-8c388ce05d51?source=api-prod","cve":"CVE-2025-60195","affectedVersions":"<=4.2.1","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6175746f6d61746f727770811c9dc5_gen.json b/internal/data/assets/plugin_6175746f6d61746f727770811c9dc5_gen.json index cef3ef06..e5dd84d6 100644 --- a/internal/data/assets/plugin_6175746f6d61746f727770811c9dc5_gen.json +++ b/internal/data/assets/plugin_6175746f6d61746f727770811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0747c996-982c-42a9-942e-2fa7056127f8/automatorwp","title":"AutomatorWP <= 5.2.4 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"0747c996-982c-42a9-942e-2fa7056127f8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0747c996-982c-42a9-942e-2fa7056127f8?source=api-prod","cve":"CVE-2025-68561","affectedVersions":"<=5.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/3e1a84c6-e28b-42fe-a16a-aeb227cfe956/automatorwp","title":"AutomatorWP <= 5.2.5 - Authenticated (Administrator+) SQL Injection via field_conditions\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-13 17:44:57","sources":[{"name":"Wordfence","remoteId":"3e1a84c6-e28b-42fe-a16a-aeb227cfe956"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3e1a84c6-e28b-42fe-a16a-aeb227cfe956?source=api-prod","cve":"CVE-2025-5487","affectedVersions":"<=5.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/5ebdf903-828e-4a22-953a-17d85984b576/automatorwp","title":"AutomatorWP <= 2.5.8 - Cross Site Request Forgery via bulk_delete\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"5ebdf903-828e-4a22-953a-17d85984b576"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ebdf903-828e-4a22-953a-17d85984b576?source=api-prod","affectedVersions":"<=2.5.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/62ed278c-f914-4edd-aba1-4aaa099a869f/automatorwp","title":"AutomatorWP <= 5.3.7 - Authenticated (Subscriber+) Missing Authorization to Multiple Functions\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-08 17:53:24","sources":[{"name":"Wordfence","remoteId":"62ed278c-f914-4edd-aba1-4aaa099a869f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62ed278c-f914-4edd-aba1-4aaa099a869f?source=api-prod","cve":"CVE-2025-9542","affectedVersions":"<=5.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/9534b2dc-fe56-4f97-bb6e-79d55508ed38/automatorwp","title":"AutomatorWP <= 5.2.1.3 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"9534b2dc-fe56-4f97-bb6e-79d55508ed38"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9534b2dc-fe56-4f97-bb6e-79d55508ed38?source=api-prod","cve":"CVE-2025-48280","affectedVersions":"<=5.2.1.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/9b95fe0e-4677-4667-9a84-96801b547088/automatorwp","title":"AutomatorWP <= 1.7.5 - Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-09-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"9b95fe0e-4677-4667-9a84-96801b547088"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9b95fe0e-4677-4667-9a84-96801b547088?source=api-prod","cve":"CVE-2021-24717","affectedVersions":"<1.7.6","severity":"high"},{"advisoryId":"WPSECADV/WF/9efa04ca-68c8-4221-a3d9-cf75010d2266/automatorwp","title":"AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.3.6 - Missing Authorization To Authenticated (Subscriber+) Remote Code Execution via Automation Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-08 17:53:28","sources":[{"name":"Wordfence","remoteId":"9efa04ca-68c8-4221-a3d9-cf75010d2266"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9efa04ca-68c8-4221-a3d9-cf75010d2266?source=api-prod","cve":"CVE-2025-9539","affectedVersions":"<=5.3.6","severity":"high"},{"advisoryId":"WPSECADV/WF/c189a778-0338-408c-bcca-a0ac76d8eb44/automatorwp","title":"AutomatorWP <= 2.5.0 - Cross Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"c189a778-0338-408c-bcca-a0ac76d8eb44"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c189a778-0338-408c-bcca-a0ac76d8eb44?source=api-prod","cve":"CVE-2023-23992","affectedVersions":"<=2.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8abcc7b-6c68-4fc8-81af-e88624e417dd/automatorwp","title":"AutomatorWP <= 5.0.9 - Reflected Cross-Site Scripting via a-0-o-search_field_value\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"c8abcc7b-6c68-4fc8-81af-e88624e417dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8abcc7b-6c68-4fc8-81af-e88624e417dd?source=api-prod","cve":"CVE-2024-12626","affectedVersions":"<=5.0.9","severity":"critical"},{"advisoryId":"WPSECADV/WF/ef8c41c6-3065-4650-81e9-bdba0e38f2bd/automatorwp","title":"AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"ef8c41c6-3065-4650-81e9-bdba0e38f2bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ef8c41c6-3065-4650-81e9-bdba0e38f2bd?source=api-prod","cve":"CVE-2026-40785","affectedVersions":"<=5.6.7","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0747c996-982c-42a9-942e-2fa7056127f8/automatorwp","title":"AutomatorWP <= 5.2.4 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"0747c996-982c-42a9-942e-2fa7056127f8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0747c996-982c-42a9-942e-2fa7056127f8?source=api-prod","cve":"CVE-2025-68561","affectedVersions":"<=5.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/3e1a84c6-e28b-42fe-a16a-aeb227cfe956/automatorwp","title":"AutomatorWP <= 5.2.5 - Authenticated (Administrator+) SQL Injection via field_conditions\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-13 17:44:57","sources":[{"name":"Wordfence","remoteId":"3e1a84c6-e28b-42fe-a16a-aeb227cfe956"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3e1a84c6-e28b-42fe-a16a-aeb227cfe956?source=api-prod","cve":"CVE-2025-5487","affectedVersions":"<=5.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/5ebdf903-828e-4a22-953a-17d85984b576/automatorwp","title":"AutomatorWP <= 2.5.8 - Cross Site Request Forgery via bulk_delete\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"5ebdf903-828e-4a22-953a-17d85984b576"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ebdf903-828e-4a22-953a-17d85984b576?source=api-prod","affectedVersions":"<=2.5.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/62ed278c-f914-4edd-aba1-4aaa099a869f/automatorwp","title":"AutomatorWP <= 5.3.7 - Authenticated (Subscriber+) Missing Authorization to Multiple Functions\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-08 17:53:24","sources":[{"name":"Wordfence","remoteId":"62ed278c-f914-4edd-aba1-4aaa099a869f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62ed278c-f914-4edd-aba1-4aaa099a869f?source=api-prod","cve":"CVE-2025-9542","affectedVersions":"<=5.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/9534b2dc-fe56-4f97-bb6e-79d55508ed38/automatorwp","title":"AutomatorWP <= 5.2.1.3 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"9534b2dc-fe56-4f97-bb6e-79d55508ed38"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9534b2dc-fe56-4f97-bb6e-79d55508ed38?source=api-prod","cve":"CVE-2025-48280","affectedVersions":"<=5.2.1.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/9b95fe0e-4677-4667-9a84-96801b547088/automatorwp","title":"AutomatorWP <= 1.7.5 - Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-09-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"9b95fe0e-4677-4667-9a84-96801b547088"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9b95fe0e-4677-4667-9a84-96801b547088?source=api-prod","cve":"CVE-2021-24717","affectedVersions":"<1.7.6","severity":"high"},{"advisoryId":"WPSECADV/WF/9efa04ca-68c8-4221-a3d9-cf75010d2266/automatorwp","title":"AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.3.6 - Missing Authorization To Authenticated (Subscriber+) Remote Code Execution via Automation Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-08 17:53:28","sources":[{"name":"Wordfence","remoteId":"9efa04ca-68c8-4221-a3d9-cf75010d2266"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9efa04ca-68c8-4221-a3d9-cf75010d2266?source=api-prod","cve":"CVE-2025-9539","affectedVersions":"<=5.3.6","severity":"high"},{"advisoryId":"WPSECADV/WF/b06201bd-4f8e-41e5-89e1-b1f47757799b/automatorwp","title":"AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"b06201bd-4f8e-41e5-89e1-b1f47757799b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b06201bd-4f8e-41e5-89e1-b1f47757799b?source=api-prod","cve":"CVE-2026-42650","affectedVersions":"<=5.6.7","severity":"high"},{"advisoryId":"WPSECADV/WF/c189a778-0338-408c-bcca-a0ac76d8eb44/automatorwp","title":"AutomatorWP <= 2.5.0 - Cross Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"c189a778-0338-408c-bcca-a0ac76d8eb44"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c189a778-0338-408c-bcca-a0ac76d8eb44?source=api-prod","cve":"CVE-2023-23992","affectedVersions":"<=2.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8abcc7b-6c68-4fc8-81af-e88624e417dd/automatorwp","title":"AutomatorWP <= 5.0.9 - Reflected Cross-Site Scripting via a-0-o-search_field_value\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"c8abcc7b-6c68-4fc8-81af-e88624e417dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8abcc7b-6c68-4fc8-81af-e88624e417dd?source=api-prod","cve":"CVE-2024-12626","affectedVersions":"<=5.0.9","severity":"critical"},{"advisoryId":"WPSECADV/WF/ef8c41c6-3065-4650-81e9-bdba0e38f2bd/automatorwp","title":"AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.6.7 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"ef8c41c6-3065-4650-81e9-bdba0e38f2bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ef8c41c6-3065-4650-81e9-bdba0e38f2bd?source=api-prod","cve":"CVE-2026-40785","affectedVersions":"<=5.6.7","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6175746f73686172652d666f722d74776974746572811c9dc5_gen.json b/internal/data/assets/plugin_6175746f73686172652d666f722d74776974746572811c9dc5_gen.json index dc5b9396..8c5a219b 100644 --- a/internal/data/assets/plugin_6175746f73686172652d666f722d74776974746572811c9dc5_gen.json +++ b/internal/data/assets/plugin_6175746f73686172652d666f722d74776974746572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/4c747e6f-31fc-41b0-ba62-f009b5483696/autoshare-for-twitter","title":"simple-git < 3.15.0 - Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"4c747e6f-31fc-41b0-ba62-f009b5483696"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4c747e6f-31fc-41b0-ba62-f009b5483696?source=api-prod","cve":"CVE-2022-25912","affectedVersions":"<=1.2.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/d535c069-cfa3-4c41-9a01-b4c4e7c75764/autoshare-for-twitter","title":"Terser < 4.8.1 and 5.0.0-5.14.1 - Regular Expression Denial of Service\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-07-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"d535c069-cfa3-4c41-9a01-b4c4e7c75764"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d535c069-cfa3-4c41-9a01-b4c4e7c75764?source=api-prod","cve":"CVE-2022-25858","affectedVersions":"<=1.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e3147a94-056a-4454-8815-44c0b9d1de81/autoshare-for-twitter","title":"decode-uri-component <= 0.2.1 - Denial of Service\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"e3147a94-056a-4454-8815-44c0b9d1de81"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e3147a94-056a-4454-8815-44c0b9d1de81?source=api-prod","cve":"CVE-2022-38900","affectedVersions":"<=1.2.1","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/4c747e6f-31fc-41b0-ba62-f009b5483696/autoshare-for-twitter","title":"simple-git < 3.15.0 - Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"4c747e6f-31fc-41b0-ba62-f009b5483696"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4c747e6f-31fc-41b0-ba62-f009b5483696?source=api-prod","cve":"CVE-2022-25912","affectedVersions":"<=1.2.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/ac05441d-137e-433a-86bd-a702ec664db0/autoshare-for-twitter","title":"Autoshare for Twitter <= 2.3.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"ac05441d-137e-433a-86bd-a702ec664db0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ac05441d-137e-433a-86bd-a702ec664db0?source=api-prod","cve":"CVE-2026-25311","affectedVersions":"<=2.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/d535c069-cfa3-4c41-9a01-b4c4e7c75764/autoshare-for-twitter","title":"Terser < 4.8.1 and 5.0.0-5.14.1 - Regular Expression Denial of Service\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-07-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"d535c069-cfa3-4c41-9a01-b4c4e7c75764"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d535c069-cfa3-4c41-9a01-b4c4e7c75764?source=api-prod","cve":"CVE-2022-25858","affectedVersions":"<=1.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e3147a94-056a-4454-8815-44c0b9d1de81/autoshare-for-twitter","title":"decode-uri-component <= 0.2.1 - Denial of Service\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"e3147a94-056a-4454-8815-44c0b9d1de81"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e3147a94-056a-4454-8815-44c0b9d1de81?source=api-prod","cve":"CVE-2022-38900","affectedVersions":"<=1.2.1","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6179732d636861746770742d617373697374616e74811c9dc5_gen.json b/internal/data/assets/plugin_6179732d636861746770742d617373697374616e74811c9dc5_gen.json index 3f772028..e13a117f 100644 --- a/internal/data/assets/plugin_6179732d636861746770742d617373697374616e74811c9dc5_gen.json +++ b/internal/data/assets/plugin_6179732d636861746770742d617373697374616e74811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/293ad145-dc93-4d7a-83ba-78f8c730ed6d/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Unauthenticated Server-Side Request Forgery via 'pinecone_url' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-26 21:00:16","sources":[{"name":"Wordfence","remoteId":"293ad145-dc93-4d7a-83ba-78f8c730ed6d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/293ad145-dc93-4d7a-83ba-78f8c730ed6d?source=api-prod","cve":"CVE-2025-13378","affectedVersions":"<=2.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/53b3d441-4938-435f-85c3-707477f0293d/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.5 - Missing Authorization to Unauthenticated API Key Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 11:22:35","sources":[{"name":"Wordfence","remoteId":"53b3d441-4938-435f-85c3-707477f0293d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/53b3d441-4938-435f-85c3-707477f0293d?source=api-prod","cve":"CVE-2026-1336","affectedVersions":"<=2.7.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/af871d3d-2dc0-49c3-a697-2635e4aa8f70/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.6.6 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"af871d3d-2dc0-49c3-a697-2635e4aa8f70"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af871d3d-2dc0-49c3-a697-2635e4aa8f70?source=api-prod","cve":"CVE-2025-62039","affectedVersions":"<=2.6.6","severity":"high"},{"advisoryId":"WPSECADV/WF/be3411ec-0e34-4b0b-a04c-98ac94396989/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Missing Authorization to Unauthenticated Media File Uploads\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"be3411ec-0e34-4b0b-a04c-98ac94396989"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be3411ec-0e34-4b0b-a04c-98ac94396989?source=api-prod","cve":"CVE-2025-13381","affectedVersions":"<=2.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/d970e2fa-ba2f-4c0f-8ff4-10041b9c276e/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.0.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"d970e2fa-ba2f-4c0f-8ff4-10041b9c276e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d970e2fa-ba2f-4c0f-8ff4-10041b9c276e?source=api-prod","cve":"CVE-2024-7714","affectedVersions":"<=2.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/eb38024c-880d-4d22-b81a-412d46183e1b/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.0.9 - Unauthenticated OpenAI Key Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"eb38024c-880d-4d22-b81a-412d46183e1b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eb38024c-880d-4d22-b81a-412d46183e1b?source=api-prod","cve":"CVE-2024-7713","affectedVersions":"<=2.0.9","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/293ad145-dc93-4d7a-83ba-78f8c730ed6d/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Unauthenticated Server-Side Request Forgery via 'pinecone_url' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-26 21:00:16","sources":[{"name":"Wordfence","remoteId":"293ad145-dc93-4d7a-83ba-78f8c730ed6d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/293ad145-dc93-4d7a-83ba-78f8c730ed6d?source=api-prod","cve":"CVE-2025-13378","affectedVersions":"<=2.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/53b3d441-4938-435f-85c3-707477f0293d/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.5 - Missing Authorization to Unauthenticated API Key Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 11:22:35","sources":[{"name":"Wordfence","remoteId":"53b3d441-4938-435f-85c3-707477f0293d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/53b3d441-4938-435f-85c3-707477f0293d?source=api-prod","cve":"CVE-2026-1336","affectedVersions":"<=2.7.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/af871d3d-2dc0-49c3-a697-2635e4aa8f70/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.6.6 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"af871d3d-2dc0-49c3-a697-2635e4aa8f70"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af871d3d-2dc0-49c3-a697-2635e4aa8f70?source=api-prod","cve":"CVE-2025-62039","affectedVersions":"<=2.6.6","severity":"high"},{"advisoryId":"WPSECADV/WF/be3411ec-0e34-4b0b-a04c-98ac94396989/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Missing Authorization to Unauthenticated Media File Uploads\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"be3411ec-0e34-4b0b-a04c-98ac94396989"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be3411ec-0e34-4b0b-a04c-98ac94396989?source=api-prod","cve":"CVE-2025-13381","affectedVersions":"<=2.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca7e89fc-4d85-4512-9e27-e212d57e0e35/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca7e89fc-4d85-4512-9e27-e212d57e0e35"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca7e89fc-4d85-4512-9e27-e212d57e0e35?source=api-prod","cve":"CVE-2026-25338","affectedVersions":"<=2.7.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/d970e2fa-ba2f-4c0f-8ff4-10041b9c276e/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.0.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"d970e2fa-ba2f-4c0f-8ff4-10041b9c276e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d970e2fa-ba2f-4c0f-8ff4-10041b9c276e?source=api-prod","cve":"CVE-2024-7714","affectedVersions":"<=2.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/eb38024c-880d-4d22-b81a-412d46183e1b/ays-chatgpt-assistant","title":"AI ChatBot with ChatGPT and Content Generator by AYS <= 2.0.9 - Unauthenticated OpenAI Key Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"eb38024c-880d-4d22-b81a-412d46183e1b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eb38024c-880d-4d22-b81a-412d46183e1b?source=api-prod","cve":"CVE-2024-7713","affectedVersions":"<=2.0.9","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6265747465722d627573696e6573732d72657669657773811c9dc5_gen.json b/internal/data/assets/plugin_6265747465722d627573696e6573732d72657669657773811c9dc5_gen.json index e26824e8..d195525e 100644 --- a/internal/data/assets/plugin_6265747465722d627573696e6573732d72657669657773811c9dc5_gen.json +++ b/internal/data/assets/plugin_6265747465722d627573696e6573732d72657669657773811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/4d7b8c5f-3e3d-4ccc-8598-fcb4503c25ea/better-business-reviews","title":"Better Business Reviews <= 0.1.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d7b8c5f-3e3d-4ccc-8598-fcb4503c25ea"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d7b8c5f-3e3d-4ccc-8598-fcb4503c25ea?source=api-prod","cve":"CVE-2025-69354","affectedVersions":"<=0.1.1","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/4d7b8c5f-3e3d-4ccc-8598-fcb4503c25ea/better-business-reviews","title":"Better Business Reviews <= 0.1.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d7b8c5f-3e3d-4ccc-8598-fcb4503c25ea"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d7b8c5f-3e3d-4ccc-8598-fcb4503c25ea?source=api-prod","cve":"CVE-2025-69354","affectedVersions":"<=0.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/b4df93a3-4366-4759-87d5-d4a648ea3b8b/better-business-reviews","title":"Better Business Reviews <= 0.1.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"b4df93a3-4366-4759-87d5-d4a648ea3b8b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b4df93a3-4366-4759-87d5-d4a648ea3b8b?source=api-prod","cve":"CVE-2026-23804","affectedVersions":"<=0.1.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_626c6f672d73657474696e6773811c9dc5_gen.json b/internal/data/assets/plugin_626c6f672d73657474696e6773811c9dc5_gen.json new file mode 100644 index 00000000..e64a77b5 --- /dev/null +++ b/internal/data/assets/plugin_626c6f672d73657474696e6773811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/d28e5374-dd34-4745-a20b-059e9846d96d/blog-settings","title":"Blog Settings <= 1.0 - Reflected Cross-Site Scripting via 'page' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:07:42","sources":[{"name":"Wordfence","remoteId":"d28e5374-dd34-4745-a20b-059e9846d96d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d28e5374-dd34-4745-a20b-059e9846d96d?source=api-prod","cve":"CVE-2026-6704","affectedVersions":"<=1.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_627564647970726573732d6d65646961811c9dc5_gen.json b/internal/data/assets/plugin_627564647970726573732d6d65646961811c9dc5_gen.json index 76054ee5..f4d8f838 100644 --- a/internal/data/assets/plugin_627564647970726573732d6d65646961811c9dc5_gen.json +++ b/internal/data/assets/plugin_627564647970726573732d6d65646961811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0cb5df54-a6a7-4c2e-8df0-5d050218622e/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization via export_settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"0cb5df54-a6a7-4c2e-8df0-5d050218622e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0cb5df54-a6a7-4c2e-8df0-5d050218622e?source=api-prod","cve":"CVE-2023-41951","affectedVersions":"<=4.6.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/1814ad55-0807-4def-b584-6dbbc5d6eb72/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 3.9.5 - Local File Inclusion\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-11-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1814ad55-0807-4def-b584-6dbbc5d6eb72"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1814ad55-0807-4def-b584-6dbbc5d6eb72?source=api-prod","affectedVersions":"<=3.9.5","severity":"critical"},{"advisoryId":"WPSECADV/WF/32b6938a-0566-46c8-8761-0403b3a0e3e9/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"32b6938a-0566-46c8-8761-0403b3a0e3e9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/32b6938a-0566-46c8-8761-0403b3a0e3e9?source=api-prod","cve":"CVE-2024-3293","affectedVersions":"<=4.6.18","severity":"high"},{"advisoryId":"WPSECADV/WF/5dfc145e-d2d4-4137-a5c6-dec2ebb41876/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization to Settings Update\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"5dfc145e-d2d4-4137-a5c6-dec2ebb41876"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5dfc145e-d2d4-4137-a5c6-dec2ebb41876?source=api-prod","affectedVersions":"<4.6.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/68533b4c-1bdf-4104-a263-757b018af129/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-12 15:34:22","sources":[{"name":"Wordfence","remoteId":"68533b4c-1bdf-4104-a263-757b018af129"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/68533b4c-1bdf-4104-a263-757b018af129?source=api-prod","cve":"CVE-2025-9218","affectedVersions":">=4.7.0,<=4.7.3","severity":"low"},{"advisoryId":"WPSECADV/WF/7a2420ca-e079-429b-b1f1-47bf1d0a9f71/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Subscriber+) SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"7a2420ca-e079-429b-b1f1-47bf1d0a9f71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7a2420ca-e079-429b-b1f1-47bf1d0a9f71?source=api-prod","affectedVersions":"<=4.6.18","severity":"high"},{"advisoryId":"WPSECADV/WF/7b19b0b2-d6cb-4d92-9925-c77d517ddfb7/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 3.10.1 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-01-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"7b19b0b2-d6cb-4d92-9925-c77d517ddfb7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7b19b0b2-d6cb-4d92-9925-c77d517ddfb7?source=api-prod","affectedVersions":"<3.10.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9ba74e58-0647-4283-9fa3-428976c54474/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress < 3.7.40 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-04-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"9ba74e58-0647-4283-9fa3-428976c54474"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9ba74e58-0647-4283-9fa3-428976c54474?source=api-prod","affectedVersions":"<3.7.40","severity":"critical"},{"advisoryId":"WPSECADV/WF/be837a77-9b25-43af-aaba-94a8aa59e7e3/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization to Sensitive Information Exposure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"be837a77-9b25-43af-aaba-94a8aa59e7e3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be837a77-9b25-43af-aaba-94a8aa59e7e3?source=api-prod","affectedVersions":"<4.6.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/be97e1ca-6c9c-4641-ba7c-bbb14a58d99e/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.2 - Arbitary File Upload\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-12-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"be97e1ca-6c9c-4641-ba7c-bbb14a58d99e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be97e1ca-6c9c-4641-ba7c-bbb14a58d99e?source=api-prod","affectedVersions":"<4.2.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/cacd9237-a330-4927-ac53-ee86b9ac8289/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"cacd9237-a330-4927-ac53-ee86b9ac8289"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cacd9237-a330-4927-ac53-ee86b9ac8289?source=api-prod","cve":"CVE-2026-40773","affectedVersions":"<=4.7.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/d619d300-8bba-45a1-bd0a-d82e9066a43d/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress WordPress <= 4.6.15 - Authenticated (Admin+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"d619d300-8bba-45a1-bd0a-d82e9066a43d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d619d300-8bba-45a1-bd0a-d82e9066a43d?source=api-prod","cve":"CVE-2023-5939","affectedVersions":"<=4.6.15","severity":"high"},{"advisoryId":"WPSECADV/WF/eb022e51-32fd-403e-a9b3-34114e957020/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.6.15 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"eb022e51-32fd-403e-a9b3-34114e957020"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eb022e51-32fd-403e-a9b3-34114e957020?source=api-prod","cve":"CVE-2023-5931","affectedVersions":"<=4.6.15","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0cb5df54-a6a7-4c2e-8df0-5d050218622e/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization via export_settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"0cb5df54-a6a7-4c2e-8df0-5d050218622e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0cb5df54-a6a7-4c2e-8df0-5d050218622e?source=api-prod","cve":"CVE-2023-41951","affectedVersions":"<=4.6.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/1814ad55-0807-4def-b584-6dbbc5d6eb72/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 3.9.5 - Local File Inclusion\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-11-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1814ad55-0807-4def-b584-6dbbc5d6eb72"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1814ad55-0807-4def-b584-6dbbc5d6eb72?source=api-prod","affectedVersions":"<=3.9.5","severity":"critical"},{"advisoryId":"WPSECADV/WF/32b6938a-0566-46c8-8761-0403b3a0e3e9/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"32b6938a-0566-46c8-8761-0403b3a0e3e9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/32b6938a-0566-46c8-8761-0403b3a0e3e9?source=api-prod","cve":"CVE-2024-3293","affectedVersions":"<=4.6.18","severity":"high"},{"advisoryId":"WPSECADV/WF/5dfc145e-d2d4-4137-a5c6-dec2ebb41876/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization to Settings Update\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"5dfc145e-d2d4-4137-a5c6-dec2ebb41876"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5dfc145e-d2d4-4137-a5c6-dec2ebb41876?source=api-prod","affectedVersions":"<4.6.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/68533b4c-1bdf-4104-a263-757b018af129/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-12 15:34:22","sources":[{"name":"Wordfence","remoteId":"68533b4c-1bdf-4104-a263-757b018af129"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/68533b4c-1bdf-4104-a263-757b018af129?source=api-prod","cve":"CVE-2025-9218","affectedVersions":">=4.7.0,<=4.7.3","severity":"low"},{"advisoryId":"WPSECADV/WF/7a2420ca-e079-429b-b1f1-47bf1d0a9f71/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Subscriber+) SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"7a2420ca-e079-429b-b1f1-47bf1d0a9f71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7a2420ca-e079-429b-b1f1-47bf1d0a9f71?source=api-prod","affectedVersions":"<=4.6.18","severity":"high"},{"advisoryId":"WPSECADV/WF/7b19b0b2-d6cb-4d92-9925-c77d517ddfb7/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 3.10.1 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-01-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"7b19b0b2-d6cb-4d92-9925-c77d517ddfb7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7b19b0b2-d6cb-4d92-9925-c77d517ddfb7?source=api-prod","affectedVersions":"<3.10.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9ba74e58-0647-4283-9fa3-428976c54474/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress < 3.7.40 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-04-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"9ba74e58-0647-4283-9fa3-428976c54474"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9ba74e58-0647-4283-9fa3-428976c54474?source=api-prod","affectedVersions":"<3.7.40","severity":"critical"},{"advisoryId":"WPSECADV/WF/be837a77-9b25-43af-aaba-94a8aa59e7e3/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization to Sensitive Information Exposure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"be837a77-9b25-43af-aaba-94a8aa59e7e3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be837a77-9b25-43af-aaba-94a8aa59e7e3?source=api-prod","affectedVersions":"<4.6.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/be97e1ca-6c9c-4641-ba7c-bbb14a58d99e/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.2 - Arbitary File Upload\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-12-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"be97e1ca-6c9c-4641-ba7c-bbb14a58d99e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be97e1ca-6c9c-4641-ba7c-bbb14a58d99e?source=api-prod","affectedVersions":"<4.2.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/cacd9237-a330-4927-ac53-ee86b9ac8289/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"cacd9237-a330-4927-ac53-ee86b9ac8289"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cacd9237-a330-4927-ac53-ee86b9ac8289?source=api-prod","cve":"CVE-2026-40773","affectedVersions":"<=4.7.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/d619d300-8bba-45a1-bd0a-d82e9066a43d/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress WordPress <= 4.6.15 - Authenticated (Admin+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"d619d300-8bba-45a1-bd0a-d82e9066a43d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d619d300-8bba-45a1-bd0a-d82e9066a43d?source=api-prod","cve":"CVE-2023-5939","affectedVersions":"<=4.6.15","severity":"high"},{"advisoryId":"WPSECADV/WF/eb022e51-32fd-403e-a9b3-34114e957020/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.6.15 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"eb022e51-32fd-403e-a9b3-34114e957020"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eb022e51-32fd-403e-a9b3-34114e957020?source=api-prod","cve":"CVE-2023-5931","affectedVersions":"<=4.6.15","severity":"high"},{"advisoryId":"WPSECADV/WF/fc972c88-ec32-454f-a1f6-4fe04fda98cc/buddypress-media","title":"rtMedia for WordPress, BuddyPress and bbPress <= 4.7.8 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"fc972c88-ec32-454f-a1f6-4fe04fda98cc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fc972c88-ec32-454f-a1f6-4fe04fda98cc?source=api-prod","cve":"CVE-2026-25325","affectedVersions":"<=4.7.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_63617274666c6f7773811c9dc5_gen.json b/internal/data/assets/plugin_63617274666c6f7773811c9dc5_gen.json index 6e47c21c..87c1fbc4 100644 --- a/internal/data/assets/plugin_63617274666c6f7773811c9dc5_gen.json +++ b/internal/data/assets/plugin_63617274666c6f7773811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/083d368c-ba38-433a-b499-c00d205bd331/cartflows","title":"Funnel Builder by CartFlows <= 1.6.12 - Authenticated Stored Cross-Site scripting via FB Pixel ID and Google Analytics ID\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-05-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"083d368c-ba38-433a-b499-c00d205bd331"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/083d368c-ba38-433a-b499-c00d205bd331?source=api-prod","cve":"CVE-2021-24330","affectedVersions":"<1.6.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/0d98c849-4178-4cee-846b-2c136bc56daf/cartflows","title":"WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce <= 1.5.15 - Cross-Site Request Forgery Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d98c849-4178-4cee-846b-2c136bc56daf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d98c849-4178-4cee-846b-2c136bc56daf?source=api-prod","cve":"CVE-2020-36736","affectedVersions":"<1.5.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/5f75e37d-a94e-4103-b706-5fead24f1f73/cartflows","title":"Funnel Builder by CartFlows <= 2.0.1 - Authenticated (Editor+) Stored Cross-Site Scripting via settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"5f75e37d-a94e-4103-b706-5fead24f1f73"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5f75e37d-a94e-4103-b706-5fead24f1f73?source=api-prod","cve":"CVE-2024-29813","affectedVersions":"<=2.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6d84682-6966-47fd-a04c-7f4c5b914fc6/cartflows","title":"CartFlows <= 2.2.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"b6d84682-6966-47fd-a04c-7f4c5b914fc6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6d84682-6966-47fd-a04c-7f4c5b914fc6?source=api-prod","cve":"CVE-2026-39477","affectedVersions":"<=2.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/b9002f6e-4345-4908-9cb8-9841a2458eb7/cartflows","title":"CartFlows <= 1.11.11 - Insecure Direct Object Reference to Arbitrary Post Deletion\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"b9002f6e-4345-4908-9cb8-9841a2458eb7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b9002f6e-4345-4908-9cb8-9841a2458eb7?source=api-prod","affectedVersions":"<1.11.12","severity":"low"},{"advisoryId":"WPSECADV/WF/e9a89613-cfd9-4a96-b8eb-4b17376be433/cartflows","title":"WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"e9a89613-cfd9-4a96-b8eb-4b17376be433"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e9a89613-cfd9-4a96-b8eb-4b17376be433?source=api-prod","cve":"CVE-2024-4632","affectedVersions":"<=2.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/f0b95670-0767-4325-88d0-4ae6d7302558/cartflows","title":"Funnel Builder <= 1.3.0 - Arbitrary Plugin Activation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-11-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"f0b95670-0767-4325-88d0-4ae6d7302558"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f0b95670-0767-4325-88d0-4ae6d7302558?source=api-prod","cve":"CVE-2019-25151","affectedVersions":"<=1.3.0","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/083d368c-ba38-433a-b499-c00d205bd331/cartflows","title":"Funnel Builder by CartFlows <= 1.6.12 - Authenticated Stored Cross-Site scripting via FB Pixel ID and Google Analytics ID\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-05-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"083d368c-ba38-433a-b499-c00d205bd331"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/083d368c-ba38-433a-b499-c00d205bd331?source=api-prod","cve":"CVE-2021-24330","affectedVersions":"<1.6.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/0d98c849-4178-4cee-846b-2c136bc56daf/cartflows","title":"WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce <= 1.5.15 - Cross-Site Request Forgery Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d98c849-4178-4cee-846b-2c136bc56daf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d98c849-4178-4cee-846b-2c136bc56daf?source=api-prod","cve":"CVE-2020-36736","affectedVersions":"<1.5.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/5f75e37d-a94e-4103-b706-5fead24f1f73/cartflows","title":"Funnel Builder by CartFlows <= 2.0.1 - Authenticated (Editor+) Stored Cross-Site Scripting via settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"5f75e37d-a94e-4103-b706-5fead24f1f73"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5f75e37d-a94e-4103-b706-5fead24f1f73?source=api-prod","cve":"CVE-2024-29813","affectedVersions":"<=2.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/96a2e7cc-23ae-404a-9889-e7bf9f744ec5/cartflows","title":"CartFlows – Checkout & Funnel Builder for WooCommerce <= 2.1.19 - Authenticated (Administrator+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"96a2e7cc-23ae-404a-9889-e7bf9f744ec5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/96a2e7cc-23ae-404a-9889-e7bf9f744ec5?source=api-prod","cve":"CVE-2026-25316","affectedVersions":"<=2.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6d84682-6966-47fd-a04c-7f4c5b914fc6/cartflows","title":"CartFlows <= 2.2.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"b6d84682-6966-47fd-a04c-7f4c5b914fc6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6d84682-6966-47fd-a04c-7f4c5b914fc6?source=api-prod","cve":"CVE-2026-39477","affectedVersions":"<=2.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/b9002f6e-4345-4908-9cb8-9841a2458eb7/cartflows","title":"CartFlows <= 1.11.11 - Insecure Direct Object Reference to Arbitrary Post Deletion\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"b9002f6e-4345-4908-9cb8-9841a2458eb7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b9002f6e-4345-4908-9cb8-9841a2458eb7?source=api-prod","affectedVersions":"<1.11.12","severity":"low"},{"advisoryId":"WPSECADV/WF/e9a89613-cfd9-4a96-b8eb-4b17376be433/cartflows","title":"WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"e9a89613-cfd9-4a96-b8eb-4b17376be433"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e9a89613-cfd9-4a96-b8eb-4b17376be433?source=api-prod","cve":"CVE-2024-4632","affectedVersions":"<=2.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/f0b95670-0767-4325-88d0-4ae6d7302558/cartflows","title":"Funnel Builder <= 1.3.0 - Arbitrary Plugin Activation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-11-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"f0b95670-0767-4325-88d0-4ae6d7302558"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f0b95670-0767-4325-88d0-4ae6d7302558?source=api-prod","cve":"CVE-2019-25151","affectedVersions":"<=1.3.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6368617274732d6e696e6a612d6772617068732d616e642d636861727473811c9dc5_gen.json b/internal/data/assets/plugin_6368617274732d6e696e6a612d6772617068732d616e642d636861727473811c9dc5_gen.json new file mode 100644 index 00000000..4964fb98 --- /dev/null +++ b/internal/data/assets/plugin_6368617274732d6e696e6a612d6772617068732d616e642d636861727473811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/491c7680-d270-41ed-a756-9397a0bd86bc/charts-ninja-graphs-and-charts","title":"Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'chartid' Shortcode Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:07:54","sources":[{"name":"Wordfence","remoteId":"491c7680-d270-41ed-a756-9397a0bd86bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/491c7680-d270-41ed-a756-9397a0bd86bc?source=api-prod","cve":"CVE-2026-4730","affectedVersions":"<=2.1.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_636c61737369666965642d6c697374696e67811c9dc5_gen.json b/internal/data/assets/plugin_636c61737369666965642d6c697374696e67811c9dc5_gen.json index 81a7413b..9e329db5 100644 --- a/internal/data/assets/plugin_636c61737369666965642d6c697374696e67811c9dc5_gen.json +++ b/internal/data/assets/plugin_636c61737369666965642d6c697374696e67811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/13d9a59f-1a1a-4936-a5ab-8a5e0c50303b/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 3.1.15.1 - Authenticated (Subscriber+) Limited Arbitrary Option Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"13d9a59f-1a1a-4936-a5ab-8a5e0c50303b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/13d9a59f-1a1a-4936-a5ab-8a5e0c50303b?source=api-prod","cve":"CVE-2024-11194","affectedVersions":"<=3.1.15.1","severity":"high"},{"advisoryId":"WPSECADV/WF/2352dce7-5302-4892-9ae2-bf814f029af4/classified-listing","title":"Classified Listing <= 2.4.5 - Cross-Site Request Forgery via rtcl_ajax_thumbnail_delete\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"2352dce7-5302-4892-9ae2-bf814f029af4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2352dce7-5302-4892-9ae2-bf814f029af4?source=api-prod","cve":"CVE-2023-37387","affectedVersions":"<=2.4.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/41fcf001-84da-4baf-9f43-5911ad33af35/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 4.0.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"41fcf001-84da-4baf-9f43-5911ad33af35"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/41fcf001-84da-4baf-9f43-5911ad33af35?source=api-prod","cve":"CVE-2025-24745","affectedVersions":"<=4.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/494d2e69-0759-419a-a603-e8870c157e49/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 3.1.7 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-12 18:35:01","sources":[{"name":"Wordfence","remoteId":"494d2e69-0759-419a-a603-e8870c157e49"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/494d2e69-0759-419a-a603-e8870c157e49?source=api-prod","cve":"CVE-2024-7888","affectedVersions":"<=3.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/4cfee2e2-3486-4be8-954f-6d7f9b6d54ec/classified-listing","title":"Classima < 2.1.11 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"4cfee2e2-3486-4be8-954f-6d7f9b6d54ec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4cfee2e2-3486-4be8-954f-6d7f9b6d54ec?source=api-prod","cve":"CVE-2022-2654","affectedVersions":"<2.2.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/517531ec-4160-4287-8499-6266e08223dc/classified-listing","title":"Classified Listing <= 4.2.0 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"517531ec-4160-4287-8499-6266e08223dc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/517531ec-4160-4287-8499-6266e08223dc?source=api-prod","cve":"CVE-2025-52715","affectedVersions":"<=4.2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/5439651e-5557-4b13-813a-4fc0ad876104/classified-listing","title":"Classified Listing <= 3.0.4 - Cross-Site Request Forgery to Account Takeover via rtcl_update_user_account\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"5439651e-5557-4b13-813a-4fc0ad876104"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5439651e-5557-4b13-813a-4fc0ad876104?source=api-prod","cve":"CVE-2024-1315","affectedVersions":"<=3.0.4","severity":"high"},{"advisoryId":"WPSECADV/WF/60782340-8913-4114-8544-109337795f45/classified-listing","title":"Classified Listing <= 5.0.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"60782340-8913-4114-8544-109337795f45"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/60782340-8913-4114-8544-109337795f45?source=api-prod","cve":"CVE-2025-58601","affectedVersions":"<=5.0.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/811f147e-5829-4f7e-91d8-9dba780950d5/classified-listing","title":"Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.2.0 - Missing Authorization to Authenticated (Subscriber+) Listing Types Tampering\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-10 22:39:09","sources":[{"name":"Wordfence","remoteId":"811f147e-5829-4f7e-91d8-9dba780950d5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/811f147e-5829-4f7e-91d8-9dba780950d5?source=api-prod","cve":"CVE-2025-12953","affectedVersions":"<=5.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/8e926708-3c7f-4d7b-a64b-209f696984f9/classified-listing","title":"Classified Listing <= 3.1.16 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e926708-3c7f-4d7b-a64b-209f696984f9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e926708-3c7f-4d7b-a64b-209f696984f9?source=api-prod","cve":"CVE-2024-52386","affectedVersions":"<=3.1.16","severity":"high"},{"advisoryId":"WPSECADV/WF/abebfbc4-37ed-44d5-a35d-d6ad87346f3a/classified-listing","title":"Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.4 - Authenticated (Subscriber+) Sensitive Data Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"abebfbc4-37ed-44d5-a35d-d6ad87346f3a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/abebfbc4-37ed-44d5-a35d-d6ad87346f3a?source=api-prod","cve":"CVE-2026-23546","affectedVersions":"<=5.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/baf2af6b-277e-4613-b066-1f2acda56602/classified-listing","title":"Classified Listing <= 5.0.0 - Authenticated (Contributor+) Content Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"baf2af6b-277e-4613-b066-1f2acda56602"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/baf2af6b-277e-4613-b066-1f2acda56602?source=api-prod","cve":"CVE-2025-54698","affectedVersions":"<=5.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/d9b10db9-0c7c-4f13-9d98-6d407446cfb8/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 5.0.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Listing Description\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-17 09:59:24","sources":[{"name":"Wordfence","remoteId":"d9b10db9-0c7c-4f13-9d98-6d407446cfb8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d9b10db9-0c7c-4f13-9d98-6d407446cfb8?source=api-prod","cve":"CVE-2025-7711","affectedVersions":"<=5.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/e701b771-59f2-4783-b0a1-bea4d6c3d245/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 4.0.4 - Unauthenticated Settings Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"e701b771-59f2-4783-b0a1-bea4d6c3d245"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e701b771-59f2-4783-b0a1-bea4d6c3d245?source=api-prod","cve":"CVE-2025-1063","affectedVersions":"<=4.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/e7113b1c-78dc-4648-b14a-52ff6668fd1d/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 3.0.10.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7113b1c-78dc-4648-b14a-52ff6668fd1d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7113b1c-78dc-4648-b14a-52ff6668fd1d?source=api-prod","cve":"CVE-2024-3893","affectedVersions":"<=3.0.10.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/f5da4cdd-15c7-41a6-be2f-e31bd407ae05/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 3.0.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"f5da4cdd-15c7-41a6-be2f-e31bd407ae05"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5da4cdd-15c7-41a6-be2f-e31bd407ae05?source=api-prod","cve":"CVE-2024-1352","affectedVersions":"<=3.0.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/13d9a59f-1a1a-4936-a5ab-8a5e0c50303b/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 3.1.15.1 - Authenticated (Subscriber+) Limited Arbitrary Option Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"13d9a59f-1a1a-4936-a5ab-8a5e0c50303b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/13d9a59f-1a1a-4936-a5ab-8a5e0c50303b?source=api-prod","cve":"CVE-2024-11194","affectedVersions":"<=3.1.15.1","severity":"high"},{"advisoryId":"WPSECADV/WF/2352dce7-5302-4892-9ae2-bf814f029af4/classified-listing","title":"Classified Listing <= 2.4.5 - Cross-Site Request Forgery via rtcl_ajax_thumbnail_delete\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"2352dce7-5302-4892-9ae2-bf814f029af4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2352dce7-5302-4892-9ae2-bf814f029af4?source=api-prod","cve":"CVE-2023-37387","affectedVersions":"<=2.4.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/41fcf001-84da-4baf-9f43-5911ad33af35/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 4.0.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"41fcf001-84da-4baf-9f43-5911ad33af35"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/41fcf001-84da-4baf-9f43-5911ad33af35?source=api-prod","cve":"CVE-2025-24745","affectedVersions":"<=4.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/494d2e69-0759-419a-a603-e8870c157e49/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 3.1.7 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-12 18:35:01","sources":[{"name":"Wordfence","remoteId":"494d2e69-0759-419a-a603-e8870c157e49"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/494d2e69-0759-419a-a603-e8870c157e49?source=api-prod","cve":"CVE-2024-7888","affectedVersions":"<=3.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/4cfee2e2-3486-4be8-954f-6d7f9b6d54ec/classified-listing","title":"Classima < 2.1.11 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"4cfee2e2-3486-4be8-954f-6d7f9b6d54ec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4cfee2e2-3486-4be8-954f-6d7f9b6d54ec?source=api-prod","cve":"CVE-2022-2654","affectedVersions":"<2.2.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/517531ec-4160-4287-8499-6266e08223dc/classified-listing","title":"Classified Listing <= 4.2.0 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"517531ec-4160-4287-8499-6266e08223dc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/517531ec-4160-4287-8499-6266e08223dc?source=api-prod","cve":"CVE-2025-52715","affectedVersions":"<=4.2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/5439651e-5557-4b13-813a-4fc0ad876104/classified-listing","title":"Classified Listing <= 3.0.4 - Cross-Site Request Forgery to Account Takeover via rtcl_update_user_account\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"5439651e-5557-4b13-813a-4fc0ad876104"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5439651e-5557-4b13-813a-4fc0ad876104?source=api-prod","cve":"CVE-2024-1315","affectedVersions":"<=3.0.4","severity":"high"},{"advisoryId":"WPSECADV/WF/60782340-8913-4114-8544-109337795f45/classified-listing","title":"Classified Listing <= 5.0.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"60782340-8913-4114-8544-109337795f45"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/60782340-8913-4114-8544-109337795f45?source=api-prod","cve":"CVE-2025-58601","affectedVersions":"<=5.0.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/70dda3b3-8515-49b2-8e45-21ceb9aeb419/classified-listing","title":"Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"70dda3b3-8515-49b2-8e45-21ceb9aeb419"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/70dda3b3-8515-49b2-8e45-21ceb9aeb419?source=api-prod","cve":"CVE-2026-42651","affectedVersions":"<=5.3.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/811f147e-5829-4f7e-91d8-9dba780950d5/classified-listing","title":"Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.2.0 - Missing Authorization to Authenticated (Subscriber+) Listing Types Tampering\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-10 22:39:09","sources":[{"name":"Wordfence","remoteId":"811f147e-5829-4f7e-91d8-9dba780950d5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/811f147e-5829-4f7e-91d8-9dba780950d5?source=api-prod","cve":"CVE-2025-12953","affectedVersions":"<=5.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/8e926708-3c7f-4d7b-a64b-209f696984f9/classified-listing","title":"Classified Listing <= 3.1.16 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e926708-3c7f-4d7b-a64b-209f696984f9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e926708-3c7f-4d7b-a64b-209f696984f9?source=api-prod","cve":"CVE-2024-52386","affectedVersions":"<=3.1.16","severity":"high"},{"advisoryId":"WPSECADV/WF/abebfbc4-37ed-44d5-a35d-d6ad87346f3a/classified-listing","title":"Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.4 - Authenticated (Subscriber+) Sensitive Data Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"abebfbc4-37ed-44d5-a35d-d6ad87346f3a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/abebfbc4-37ed-44d5-a35d-d6ad87346f3a?source=api-prod","cve":"CVE-2026-23546","affectedVersions":"<=5.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/baf2af6b-277e-4613-b066-1f2acda56602/classified-listing","title":"Classified Listing <= 5.0.0 - Authenticated (Contributor+) Content Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"baf2af6b-277e-4613-b066-1f2acda56602"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/baf2af6b-277e-4613-b066-1f2acda56602?source=api-prod","cve":"CVE-2025-54698","affectedVersions":"<=5.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/cbb25a81-a92b-4773-9194-9aa355750817/classified-listing","title":"Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"cbb25a81-a92b-4773-9194-9aa355750817"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cbb25a81-a92b-4773-9194-9aa355750817?source=api-prod","cve":"CVE-2026-42640","affectedVersions":"<=5.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/d9b10db9-0c7c-4f13-9d98-6d407446cfb8/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 5.0.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Listing Description\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-17 09:59:24","sources":[{"name":"Wordfence","remoteId":"d9b10db9-0c7c-4f13-9d98-6d407446cfb8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d9b10db9-0c7c-4f13-9d98-6d407446cfb8?source=api-prod","cve":"CVE-2025-7711","affectedVersions":"<=5.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/e701b771-59f2-4783-b0a1-bea4d6c3d245/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 4.0.4 - Unauthenticated Settings Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"e701b771-59f2-4783-b0a1-bea4d6c3d245"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e701b771-59f2-4783-b0a1-bea4d6c3d245?source=api-prod","cve":"CVE-2025-1063","affectedVersions":"<=4.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/e7113b1c-78dc-4648-b14a-52ff6668fd1d/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 3.0.10.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7113b1c-78dc-4648-b14a-52ff6668fd1d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7113b1c-78dc-4648-b14a-52ff6668fd1d?source=api-prod","cve":"CVE-2024-3893","affectedVersions":"<=3.0.10.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/f0e6b405-0843-4469-ae60-7023dea0786f/classified-listing","title":"Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.8 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"f0e6b405-0843-4469-ae60-7023dea0786f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f0e6b405-0843-4469-ae60-7023dea0786f?source=api-prod","cve":"CVE-2026-42658","affectedVersions":"<=5.3.8","severity":"high"},{"advisoryId":"WPSECADV/WF/f5da4cdd-15c7-41a6-be2f-e31bd407ae05/classified-listing","title":"Classified Listing – Classified ads & Business Directory Plugin <= 3.0.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"f5da4cdd-15c7-41a6-be2f-e31bd407ae05"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5da4cdd-15c7-41a6-be2f-e31bd407ae05?source=api-prod","cve":"CVE-2024-1352","affectedVersions":"<=3.0.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_636c69656e742d706f7274616c811c9dc5_gen.json b/internal/data/assets/plugin_636c69656e742d706f7274616c811c9dc5_gen.json index 12d1820f..dc4ff0c8 100644 --- a/internal/data/assets/plugin_636c69656e742d706f7274616c811c9dc5_gen.json +++ b/internal/data/assets/plugin_636c69656e742d706f7274616c811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/b89185c1-f7f9-47fb-ae8b-ba4c9f4e1d3e/client-portal","title":"Client Portal – Private user pages and login <= 1.1.8 - Cross-Site Request Forgery via cp_create_private_pages_for_all_users function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"b89185c1-f7f9-47fb-ae8b-ba4c9f4e1d3e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b89185c1-f7f9-47fb-ae8b-ba4c9f4e1d3e?source=api-prod","cve":"CVE-2023-25968","affectedVersions":"<=1.1.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/c3319993-6f2c-425d-8cb2-ab26f7a52139/client-portal","title":"Client Portal <= 1.1.8 - Cross-Site Request Forgery via cp_create_private_pages_for_all_users\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"c3319993-6f2c-425d-8cb2-ab26f7a52139"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c3319993-6f2c-425d-8cb2-ab26f7a52139?source=api-prod","affectedVersions":"<=1.1.8","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/a8360ce3-6885-418c-9950-4a5f888c703b/client-portal","title":"Client Portal – Private user pages and login <= 1.2.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"a8360ce3-6885-418c-9950-4a5f888c703b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a8360ce3-6885-418c-9950-4a5f888c703b?source=api-prod","cve":"CVE-2026-25003","affectedVersions":"<=1.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/b89185c1-f7f9-47fb-ae8b-ba4c9f4e1d3e/client-portal","title":"Client Portal – Private user pages and login <= 1.1.8 - Cross-Site Request Forgery via cp_create_private_pages_for_all_users function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"b89185c1-f7f9-47fb-ae8b-ba4c9f4e1d3e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b89185c1-f7f9-47fb-ae8b-ba4c9f4e1d3e?source=api-prod","cve":"CVE-2023-25968","affectedVersions":"<=1.1.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/c3319993-6f2c-425d-8cb2-ab26f7a52139/client-portal","title":"Client Portal <= 1.1.8 - Cross-Site Request Forgery via cp_create_private_pages_for_all_users\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"c3319993-6f2c-425d-8cb2-ab26f7a52139"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c3319993-6f2c-425d-8cb2-ab26f7a52139?source=api-prod","affectedVersions":"<=1.1.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_636d736d6173746572732d636f6e74656e742d636f6d706f736572811c9dc5_gen.json b/internal/data/assets/plugin_636d736d6173746572732d636f6e74656e742d636f6d706f736572811c9dc5_gen.json index 9bda403d..00d70380 100644 --- a/internal/data/assets/plugin_636d736d6173746572732d636f6e74656e742d636f6d706f736572811c9dc5_gen.json +++ b/internal/data/assets/plugin_636d736d6173746572732d636f6e74656e742d636f6d706f736572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/00d8e7db-b1a4-4785-ba57-1dce0fd11dec/cmsmasters-content-composer","title":"CMSMasters Content Composer <= 1.4.5 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"00d8e7db-b1a4-4785-ba57-1dce0fd11dec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00d8e7db-b1a4-4785-ba57-1dce0fd11dec?source=api-prod","cve":"CVE-2026-25326","affectedVersions":"<=1.4.5","severity":"high"},{"advisoryId":"WPSECADV/WF/42c1d2ea-dea6-4cde-8db3-37709da9eb71/cmsmasters-content-composer","title":"CMSMasters Content Composer <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"42c1d2ea-dea6-4cde-8db3-37709da9eb71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/42c1d2ea-dea6-4cde-8db3-37709da9eb71?source=api-prod","cve":"CVE-2024-7963","affectedVersions":"<=1.8.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/48ba51f0-5ae6-4aa0-a7fc-40264ada7998/cmsmasters-content-composer","title":"CMSMasters Content Composer < 2.5.7 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"48ba51f0-5ae6-4aa0-a7fc-40264ada7998"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/48ba51f0-5ae6-4aa0-a7fc-40264ada7998?source=api-prod","cve":"CVE-2025-4414","affectedVersions":"<2.5.7","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/00d8e7db-b1a4-4785-ba57-1dce0fd11dec/cmsmasters-content-composer","title":"CMSMasters Content Composer <= 1.4.5 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"00d8e7db-b1a4-4785-ba57-1dce0fd11dec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00d8e7db-b1a4-4785-ba57-1dce0fd11dec?source=api-prod","cve":"CVE-2026-25326","affectedVersions":"<=1.4.5","severity":"high"},{"advisoryId":"WPSECADV/WF/42c1d2ea-dea6-4cde-8db3-37709da9eb71/cmsmasters-content-composer","title":"CMSMasters Content Composer <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"42c1d2ea-dea6-4cde-8db3-37709da9eb71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/42c1d2ea-dea6-4cde-8db3-37709da9eb71?source=api-prod","cve":"CVE-2024-7963","affectedVersions":"<=1.8.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/48ba51f0-5ae6-4aa0-a7fc-40264ada7998/cmsmasters-content-composer","title":"CMSMasters Content Composer < 2.5.7 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"48ba51f0-5ae6-4aa0-a7fc-40264ada7998"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/48ba51f0-5ae6-4aa0-a7fc-40264ada7998?source=api-prod","cve":"CVE-2025-4414","affectedVersions":"<2.5.7","severity":"high"},{"advisoryId":"WPSECADV/WF/900339ef-7481-4c55-ab1d-df2617987520/cmsmasters-content-composer","title":"CMSMasters Content Composer <= 2.5.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"900339ef-7481-4c55-ab1d-df2617987520"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/900339ef-7481-4c55-ab1d-df2617987520?source=api-prod","cve":"CVE-2026-23547","affectedVersions":"<=2.5.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_636f6e746573742d67616c6c657279811c9dc5_gen.json b/internal/data/assets/plugin_636f6e746573742d67616c6c657279811c9dc5_gen.json index d8362507..40b6f6ea 100644 --- a/internal/data/assets/plugin_636f6e746573742d67616c6c657279811c9dc5_gen.json +++ b/internal/data/assets/plugin_636f6e746573742d67616c6c657279811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/07f16cf7-94ad-4203-9d71-8e6e349d8c89/contest-gallery","title":"Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.2.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"07f16cf7-94ad-4203-9d71-8e6e349d8c89"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/07f16cf7-94ad-4203-9d71-8e6e349d8c89?source=api-prod","cve":"CVE-2026-25035","affectedVersions":"<=28.1.2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/0df7f413-2631-46d9-8c0b-d66f05a02c01/contest-gallery","title":"Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"0df7f413-2631-46d9-8c0b-d66f05a02c01"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0df7f413-2631-46d9-8c0b-d66f05a02c01?source=api-prod","cve":"CVE-2024-11103","affectedVersions":"<=24.0.7","severity":"critical"},{"advisoryId":"WPSECADV/WF/0f835e7c-f921-449d-9ffc-dd0fd141119d/contest-gallery","title":"Contest Gallery <= 26.0.6 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"0f835e7c-f921-449d-9ffc-dd0fd141119d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f835e7c-f921-449d-9ffc-dd0fd141119d?source=api-prod","cve":"CVE-2025-48291","affectedVersions":"<=26.0.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/10e05707-02cb-42de-8399-4556d76b01b3/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Unauthenticated SQL Injection via cg_Fields\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"10e05707-02cb-42de-8399-4556d76b01b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/10e05707-02cb-42de-8399-4556d76b01b3?source=api-prod","cve":"CVE-2022-4158","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/16bbabe5-e8cf-43fa-ae7d-326045464192/contest-gallery","title":"Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"16bbabe5-e8cf-43fa-ae7d-326045464192"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/16bbabe5-e8cf-43fa-ae7d-326045464192?source=api-prod","cve":"CVE-2026-24964","affectedVersions":"<=28.1.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/18003103-3a14-4cbc-8bed-87a8ab050308/contest-gallery","title":"Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-31 16:20:34","sources":[{"name":"Wordfence","remoteId":"18003103-3a14-4cbc-8bed-87a8ab050308"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/18003103-3a14-4cbc-8bed-87a8ab050308?source=api-prod","cve":"CVE-2025-7725","affectedVersions":"<=26.1.0","severity":"high"},{"advisoryId":"WPSECADV/WF/1a0fa7f6-cc1a-45fe-881d-694c81b841c7/contest-gallery","title":"Contest Gallery <= 19.1.5 - Unauthenticated SQL Injection via user_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"1a0fa7f6-cc1a-45fe-881d-694c81b841c7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1a0fa7f6-cc1a-45fe-881d-694c81b841c7?source=api-prod","cve":"CVE-2022-4156","affectedVersions":"<=19.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/1b5cf360-0163-4a7c-8979-ec89ec80ad62/contest-gallery","title":"Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-27 16:40:04","sources":[{"name":"Wordfence","remoteId":"1b5cf360-0163-4a7c-8979-ec89ec80ad62"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b5cf360-0163-4a7c-8979-ec89ec80ad62?source=api-prod","cve":"CVE-2025-1513","affectedVersions":"<=26.0.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/1dba61bb-2d26-483e-835f-c3841f07efe6/contest-gallery","title":"Contest Gallery <= 23.1.2 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1dba61bb-2d26-483e-835f-c3841f07efe6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1dba61bb-2d26-483e-835f-c3841f07efe6?source=api-prod","cve":"CVE-2024-39631","affectedVersions":"<=23.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/1f9d8bbe-205f-44b6-a0c6-89b9135e6363/contest-gallery","title":"Contest Gallery – Files Upload and Contest Plugin for WordPress <= 17.0.4 - Admin+ SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-06-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"1f9d8bbe-205f-44b6-a0c6-89b9135e6363"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1f9d8bbe-205f-44b6-a0c6-89b9135e6363?source=api-prod","affectedVersions":"<=17.0.4","severity":"high"},{"advisoryId":"WPSECADV/WF/1fb84512-82c3-4def-a11b-ba0b7d64c41f/contest-gallery","title":"Contest Gallery <= 25.1.0 - Authenticated (Author+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"1fb84512-82c3-4def-a11b-ba0b7d64c41f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1fb84512-82c3-4def-a11b-ba0b7d64c41f?source=api-prod","cve":"CVE-2025-22693","affectedVersions":"<=25.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/213fde1b-13dc-442a-8f48-4b1074155a6f/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_option_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"213fde1b-13dc-442a-8f48-4b1074155a6f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/213fde1b-13dc-442a-8f48-4b1074155a6f?source=api-prod","cve":"CVE-2022-4157","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/250788a8-55d1-416b-bf1c-2170e8483ccc/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via wp_user_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"250788a8-55d1-416b-bf1c-2170e8483ccc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/250788a8-55d1-416b-bf1c-2170e8483ccc?source=api-prod","cve":"CVE-2022-4155","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/2aa5b7e8-3030-47d3-9440-3b1b5c94b5ec/contest-gallery","title":"Contest Gallery <= 24.0.3 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"2aa5b7e8-3030-47d3-9440-3b1b5c94b5ec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2aa5b7e8-3030-47d3-9440-3b1b5c94b5ec?source=api-prod","cve":"CVE-2024-56237","affectedVersions":"<=24.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2d3150b3-fba1-4e89-8f4e-b6c605227395/contest-gallery","title":"Photos and Files Contest Gallery <= 21.3.2 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"2d3150b3-fba1-4e89-8f4e-b6c605227395"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2d3150b3-fba1-4e89-8f4e-b6c605227395?source=api-prod","cve":"CVE-2024-30238","affectedVersions":"<=21.3.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/31196bdf-2ddd-49ea-840d-8fd78611629e/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via option_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"31196bdf-2ddd-49ea-840d-8fd78611629e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/31196bdf-2ddd-49ea-840d-8fd78611629e?source=api-prod","cve":"CVE-2022-4151","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/3184c304-52d3-4baa-b3c2-90957e1d8e79/contest-gallery","title":"Contest Gallery – Photo Contest Plugin for WordPress <= 13.1.0.5 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-04-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"3184c304-52d3-4baa-b3c2-90957e1d8e79"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3184c304-52d3-4baa-b3c2-90957e1d8e79?source=api-prod","cve":"CVE-2021-24915","affectedVersions":"<=13.1.0.5","severity":"critical"},{"advisoryId":"WPSECADV/WF/3b1b1a55-7872-456f-a754-023aad354359/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_multiple_files_for_post\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"3b1b1a55-7872-456f-a754-023aad354359"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3b1b1a55-7872-456f-a754-023aad354359?source=api-prod","cve":"CVE-2022-4164","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/3e3c9f08-9e73-4791-b6ca-2c8b9dc3fb81/contest-gallery","title":"Contest Gallery < 21.2.8.1 - Unauthenticated Stored Cross-Site Scripting via headers\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"3e3c9f08-9e73-4791-b6ca-2c8b9dc3fb81"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3e3c9f08-9e73-4791-b6ca-2c8b9dc3fb81?source=api-prod","cve":"CVE-2023-5307","affectedVersions":"<21.2.8.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/3e9672b1-6d00-45bc-91ef-0c5583b5306e/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_copy_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"3e9672b1-6d00-45bc-91ef-0c5583b5306e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3e9672b1-6d00-45bc-91ef-0c5583b5306e?source=api-prod","cve":"CVE-2022-4160","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/407d8ebe-f3fc-433a-856f-de2ad4e58b9e/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_copy_start\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"407d8ebe-f3fc-433a-856f-de2ad4e58b9e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/407d8ebe-f3fc-433a-856f-de2ad4e58b9e?source=api-prod","cve":"CVE-2022-4161","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/5d080f5b-6646-47ef-8ae7-8b94270f9f59/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_activate and cg_deactivate\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"5d080f5b-6646-47ef-8ae7-8b94270f9f59"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5d080f5b-6646-47ef-8ae7-8b94270f9f59?source=api-prod","cve":"CVE-2022-4163","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/691eb4c1-18ba-433b-8725-70f2ecf89b0a/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via option_id GET\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"691eb4c1-18ba-433b-8725-70f2ecf89b0a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/691eb4c1-18ba-433b-8725-70f2ecf89b0a?source=api-prod","cve":"CVE-2022-4152","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/6f854ffc-244b-45c3-94ce-198e85c11869/contest-gallery","title":"Contest Gallery <= 28.0.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f854ffc-244b-45c3-94ce-198e85c11869"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f854ffc-244b-45c3-94ce-198e85c11869?source=api-prod","cve":"CVE-2025-62950","affectedVersions":"<=28.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/6f946251-c7be-4ef6-885f-8b378c0c234c/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_order\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f946251-c7be-4ef6-885f-8b378c0c234c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f946251-c7be-4ef6-885f-8b378c0c234c?source=api-prod","cve":"CVE-2022-4165","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/75c6697c-bc1d-456f-baee-ee9c57e40d21/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_row\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"75c6697c-bc1d-456f-baee-ee9c57e40d21"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/75c6697c-bc1d-456f-baee-ee9c57e40d21?source=api-prod","cve":"CVE-2022-4162","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/768d0d53-8724-4598-ae73-305225b52633/contest-gallery","title":"Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"768d0d53-8724-4598-ae73-305225b52633"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/768d0d53-8724-4598-ae73-305225b52633?source=api-prod","cve":"CVE-2026-40771","affectedVersions":"<=28.1.6","severity":"high"},{"advisoryId":"WPSECADV/WF/7759b209-4211-4ee5-ae7a-42645f5d5e96/contest-gallery","title":"Contest Gallery < 13.1.0.7 - Authenticated Email Address Disclosure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"7759b209-4211-4ee5-ae7a-42645f5d5e96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7759b209-4211-4ee5-ae7a-42645f5d5e96?source=api-prod","affectedVersions":"<13.1.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/78f745f9-c44e-4458-9381-f639c842a31e/contest-gallery","title":"Contest Gallery <= 13.1.0.9 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-12-20 12:39:00","sources":[{"name":"Wordfence","remoteId":"78f745f9-c44e-4458-9381-f639c842a31e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/78f745f9-c44e-4458-9381-f639c842a31e?source=api-prod","cve":"CVE-2022-27853","affectedVersions":"<=13.1.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/79fb4f24-8a59-4e57-b583-c87ee2493cdb/contest-gallery","title":"Photos and Files Contest Gallery <= 21.3.4 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"79fb4f24-8a59-4e57-b583-c87ee2493cdb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/79fb4f24-8a59-4e57-b583-c87ee2493cdb?source=api-prod","cve":"CVE-2024-30236","affectedVersions":"<=21.3.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/7db0a94e-2633-4f62-adb6-9acb3f884cb8/contest-gallery","title":"Contest Gallery <= 28.1.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"7db0a94e-2633-4f62-adb6-9acb3f884cb8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7db0a94e-2633-4f62-adb6-9acb3f884cb8?source=api-prod","cve":"CVE-2026-24965","affectedVersions":"<=28.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/7dbd3b23-cebc-4212-bcae-c6f23031c040/contest-gallery","title":"Contest Gallery <= 21.1.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"7dbd3b23-cebc-4212-bcae-c6f23031c040"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7dbd3b23-cebc-4212-bcae-c6f23031c040?source=api-prod","cve":"CVE-2023-28784","affectedVersions":"<=21.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/7ef37e72-f98f-4df6-8adb-514690350a82/contest-gallery","title":"Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress <= 21.3.0 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"7ef37e72-f98f-4df6-8adb-514690350a82"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7ef37e72-f98f-4df6-8adb-514690350a82?source=api-prod","cve":"CVE-2024-1487","affectedVersions":"<=21.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/8b0c54f2-3942-48bd-b821-b66a57fd1506/contest-gallery","title":"Contest Gallery <= 21.3.5 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"8b0c54f2-3942-48bd-b821-b66a57fd1506"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8b0c54f2-3942-48bd-b821-b66a57fd1506?source=api-prod","cve":"CVE-2024-30428","affectedVersions":"<=21.3.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/8ed63de5-ef65-4e90-afc1-b7a075e99316/contest-gallery","title":"Contest Gallery <= 21.3.4 - Authenticated (Author+) Arbitrary File Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ed63de5-ef65-4e90-afc1-b7a075e99316"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ed63de5-ef65-4e90-afc1-b7a075e99316?source=api-prod","cve":"CVE-2024-32778","affectedVersions":"<=21.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/91d52a64-8dc1-4923-be0b-06800382151e/contest-gallery","title":"Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 04:44:39","sources":[{"name":"Wordfence","remoteId":"91d52a64-8dc1-4923-be0b-06800382151e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91d52a64-8dc1-4923-be0b-06800382151e?source=api-prod","cve":"CVE-2026-3180","affectedVersions":"<=28.1.4","severity":"high"},{"advisoryId":"WPSECADV/WF/9a0dc62c-786d-40f3-b9c9-bd199a176192/contest-gallery","title":"Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-10 19:47:00","sources":[{"name":"Wordfence","remoteId":"9a0dc62c-786d-40f3-b9c9-bd199a176192"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9a0dc62c-786d-40f3-b9c9-bd199a176192?source=api-prod","cve":"CVE-2025-11254","affectedVersions":"<=27.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/a1b043a1-7bee-4ef0-86d9-19cf202cfc71/contest-gallery","title":"Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 22:33:58","sources":[{"name":"Wordfence","remoteId":"a1b043a1-7bee-4ef0-86d9-19cf202cfc71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a1b043a1-7bee-4ef0-86d9-19cf202cfc71?source=api-prod","cve":"CVE-2025-3862","affectedVersions":"<=26.0.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/b24625d7-2a38-451b-ab79-a1d9c5b8822a/contest-gallery","title":"Contest Gallery <= 19.1.5 - Authenticated (Author+) SQL Injection via cg_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"b24625d7-2a38-451b-ab79-a1d9c5b8822a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b24625d7-2a38-451b-ab79-a1d9c5b8822a?source=api-prod","cve":"CVE-2022-4159","affectedVersions":"<=19.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/cf24ee30-7d9f-47c3-bc2a-1c3c92971ba8/contest-gallery","title":"Contest Gallery <= 19.1.5 - Authenticated (Author+) SQL Injection via upload[]\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"cf24ee30-7d9f-47c3-bc2a-1c3c92971ba8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cf24ee30-7d9f-47c3-bc2a-1c3c92971ba8?source=api-prod","cve":"CVE-2022-4153","affectedVersions":"<=19.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/de379f74-660a-4e59-b1c4-4b88dff8a843/contest-gallery","title":"Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-03 14:48:39","sources":[{"name":"Wordfence","remoteId":"de379f74-660a-4e59-b1c4-4b88dff8a843"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/de379f74-660a-4e59-b1c4-4b88dff8a843?source=api-prod","cve":"CVE-2025-10383","affectedVersions":"<=27.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e000c4ad-43ec-4ad0-89f9-74e9e6d8b917/contest-gallery","title":"Contest Gallery <= 28.0.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-14 18:27:20","sources":[{"name":"Wordfence","remoteId":"e000c4ad-43ec-4ad0-89f9-74e9e6d8b917"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e000c4ad-43ec-4ad0-89f9-74e9e6d8b917?source=api-prod","cve":"CVE-2025-12849","affectedVersions":"<=28.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e4ed8c6e-5f80-4360-9478-fff49b1fee94/contest-gallery","title":"Contest Gallery <= 21.2.8.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"e4ed8c6e-5f80-4360-9478-fff49b1fee94"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e4ed8c6e-5f80-4360-9478-fff49b1fee94?source=api-prod","cve":"CVE-2024-24887","affectedVersions":"<=21.2.8.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/e54caaf5-f37b-4842-ab3d-8e37cbed58da/contest-gallery","title":"Contest Gallery <= 26.0.8 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-10 18:41:31","sources":[{"name":"Wordfence","remoteId":"e54caaf5-f37b-4842-ab3d-8e37cbed58da"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e54caaf5-f37b-4842-ab3d-8e37cbed58da?source=api-prod","cve":"CVE-2025-6716","affectedVersions":"<=26.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/e7fcda2b-d679-44af-9592-4a96a0115a08/contest-gallery","title":"Contest Gallery (Pro) <= 19.1.5 - SQL Injection via option_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7fcda2b-d679-44af-9592-4a96a0115a08"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7fcda2b-d679-44af-9592-4a96a0115a08?source=api-prod","cve":"CVE-2022-4150","affectedVersions":"<=19.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/f185709e-0d13-48d3-9c15-03466b72dac2/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via addCountS\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"f185709e-0d13-48d3-9c15-03466b72dac2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f185709e-0d13-48d3-9c15-03466b72dac2?source=api-prod","cve":"CVE-2022-4166","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/f1b9725b-dee5-44ca-bb33-c6812fb76adc/contest-gallery","title":"Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 11:19:11","sources":[{"name":"Wordfence","remoteId":"f1b9725b-dee5-44ca-bb33-c6812fb76adc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f1b9725b-dee5-44ca-bb33-c6812fb76adc?source=api-prod","cve":"CVE-2026-4021","affectedVersions":"<=28.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/f2b5213d-fdc5-4c98-9a05-15d83bd7308f/contest-gallery","title":"Contest Gallery <= 21.2.8.4 - Cross-Site Request Forgery\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"f2b5213d-fdc5-4c98-9a05-15d83bd7308f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2b5213d-fdc5-4c98-9a05-15d83bd7308f?source=api-prod","affectedVersions":"<=21.2.8.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/f36af71c-78af-402c-9d3a-3752368e7584/contest-gallery","title":"Contest Gallery <= 13.1.0.9 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"f36af71c-78af-402c-9d3a-3752368e7584"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f36af71c-78af-402c-9d3a-3752368e7584?source=api-prod","cve":"CVE-2022-45848","affectedVersions":"<=13.1.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/f5e400f8-35b4-4be4-bb00-c59e14ddd57f/contest-gallery","title":"Contest Gallery <= 23.1.2 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"f5e400f8-35b4-4be4-bb00-c59e14ddd57f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5e400f8-35b4-4be4-bb00-c59e14ddd57f?source=api-prod","cve":"CVE-2024-43283","affectedVersions":"<=23.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f9b90e03-cdaa-4bd3-9afd-5d5c91a17962/contest-gallery","title":"Contest Gallery <= 17.0.4 - Authenticated (Author+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"f9b90e03-cdaa-4bd3-9afd-5d5c91a17962"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f9b90e03-cdaa-4bd3-9afd-5d5c91a17962?source=api-prod","cve":"CVE-2022-36394","affectedVersions":"<=17.0.4","severity":"high"},{"advisoryId":"WPSECADV/WF/fb4b6d33-82cd-4c41-ba54-dbc7fe5f6ac6/contest-gallery","title":"Contest Gallery – Photo Contest Plugin for WordPress <= 10.4.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-06-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"fb4b6d33-82cd-4c41-ba54-dbc7fe5f6ac6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fb4b6d33-82cd-4c41-ba54-dbc7fe5f6ac6?source=api-prod","cve":"CVE-2019-5974","affectedVersions":"<=10.4.4","severity":"high"},{"advisoryId":"WPSECADV/WF/fd3b4c44-d47a-45de-bcb2-0820e475b331/contest-gallery","title":"Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-04 21:11:26","sources":[{"name":"Wordfence","remoteId":"fd3b4c44-d47a-45de-bcb2-0820e475b331"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd3b4c44-d47a-45de-bcb2-0820e475b331?source=api-prod","cve":"CVE-2024-10687","affectedVersions":"<=24.0.3","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/07f16cf7-94ad-4203-9d71-8e6e349d8c89/contest-gallery","title":"Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.2.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"07f16cf7-94ad-4203-9d71-8e6e349d8c89"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/07f16cf7-94ad-4203-9d71-8e6e349d8c89?source=api-prod","cve":"CVE-2026-25035","affectedVersions":"<=28.1.2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/0df7f413-2631-46d9-8c0b-d66f05a02c01/contest-gallery","title":"Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"0df7f413-2631-46d9-8c0b-d66f05a02c01"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0df7f413-2631-46d9-8c0b-d66f05a02c01?source=api-prod","cve":"CVE-2024-11103","affectedVersions":"<=24.0.7","severity":"critical"},{"advisoryId":"WPSECADV/WF/0f835e7c-f921-449d-9ffc-dd0fd141119d/contest-gallery","title":"Contest Gallery <= 26.0.6 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"0f835e7c-f921-449d-9ffc-dd0fd141119d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f835e7c-f921-449d-9ffc-dd0fd141119d?source=api-prod","cve":"CVE-2025-48291","affectedVersions":"<=26.0.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/10e05707-02cb-42de-8399-4556d76b01b3/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Unauthenticated SQL Injection via cg_Fields\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"10e05707-02cb-42de-8399-4556d76b01b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/10e05707-02cb-42de-8399-4556d76b01b3?source=api-prod","cve":"CVE-2022-4158","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/16bbabe5-e8cf-43fa-ae7d-326045464192/contest-gallery","title":"Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"16bbabe5-e8cf-43fa-ae7d-326045464192"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/16bbabe5-e8cf-43fa-ae7d-326045464192?source=api-prod","cve":"CVE-2026-24964","affectedVersions":"<=28.1.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/18003103-3a14-4cbc-8bed-87a8ab050308/contest-gallery","title":"Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-31 16:20:34","sources":[{"name":"Wordfence","remoteId":"18003103-3a14-4cbc-8bed-87a8ab050308"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/18003103-3a14-4cbc-8bed-87a8ab050308?source=api-prod","cve":"CVE-2025-7725","affectedVersions":"<=26.1.0","severity":"high"},{"advisoryId":"WPSECADV/WF/1a0fa7f6-cc1a-45fe-881d-694c81b841c7/contest-gallery","title":"Contest Gallery <= 19.1.5 - Unauthenticated SQL Injection via user_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"1a0fa7f6-cc1a-45fe-881d-694c81b841c7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1a0fa7f6-cc1a-45fe-881d-694c81b841c7?source=api-prod","cve":"CVE-2022-4156","affectedVersions":"<=19.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/1b5cf360-0163-4a7c-8979-ec89ec80ad62/contest-gallery","title":"Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-27 16:40:04","sources":[{"name":"Wordfence","remoteId":"1b5cf360-0163-4a7c-8979-ec89ec80ad62"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b5cf360-0163-4a7c-8979-ec89ec80ad62?source=api-prod","cve":"CVE-2025-1513","affectedVersions":"<=26.0.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/1dba61bb-2d26-483e-835f-c3841f07efe6/contest-gallery","title":"Contest Gallery <= 23.1.2 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1dba61bb-2d26-483e-835f-c3841f07efe6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1dba61bb-2d26-483e-835f-c3841f07efe6?source=api-prod","cve":"CVE-2024-39631","affectedVersions":"<=23.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/1f9d8bbe-205f-44b6-a0c6-89b9135e6363/contest-gallery","title":"Contest Gallery – Files Upload and Contest Plugin for WordPress <= 17.0.4 - Admin+ SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-06-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"1f9d8bbe-205f-44b6-a0c6-89b9135e6363"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1f9d8bbe-205f-44b6-a0c6-89b9135e6363?source=api-prod","affectedVersions":"<=17.0.4","severity":"high"},{"advisoryId":"WPSECADV/WF/1fb84512-82c3-4def-a11b-ba0b7d64c41f/contest-gallery","title":"Contest Gallery <= 25.1.0 - Authenticated (Author+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"1fb84512-82c3-4def-a11b-ba0b7d64c41f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1fb84512-82c3-4def-a11b-ba0b7d64c41f?source=api-prod","cve":"CVE-2025-22693","affectedVersions":"<=25.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/213fde1b-13dc-442a-8f48-4b1074155a6f/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_option_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"213fde1b-13dc-442a-8f48-4b1074155a6f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/213fde1b-13dc-442a-8f48-4b1074155a6f?source=api-prod","cve":"CVE-2022-4157","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/250788a8-55d1-416b-bf1c-2170e8483ccc/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via wp_user_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"250788a8-55d1-416b-bf1c-2170e8483ccc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/250788a8-55d1-416b-bf1c-2170e8483ccc?source=api-prod","cve":"CVE-2022-4155","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/2aa5b7e8-3030-47d3-9440-3b1b5c94b5ec/contest-gallery","title":"Contest Gallery <= 24.0.3 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"2aa5b7e8-3030-47d3-9440-3b1b5c94b5ec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2aa5b7e8-3030-47d3-9440-3b1b5c94b5ec?source=api-prod","cve":"CVE-2024-56237","affectedVersions":"<=24.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2d3150b3-fba1-4e89-8f4e-b6c605227395/contest-gallery","title":"Photos and Files Contest Gallery <= 21.3.2 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"2d3150b3-fba1-4e89-8f4e-b6c605227395"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2d3150b3-fba1-4e89-8f4e-b6c605227395?source=api-prod","cve":"CVE-2024-30238","affectedVersions":"<=21.3.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/31196bdf-2ddd-49ea-840d-8fd78611629e/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via option_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"31196bdf-2ddd-49ea-840d-8fd78611629e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/31196bdf-2ddd-49ea-840d-8fd78611629e?source=api-prod","cve":"CVE-2022-4151","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/3184c304-52d3-4baa-b3c2-90957e1d8e79/contest-gallery","title":"Contest Gallery – Photo Contest Plugin for WordPress <= 13.1.0.5 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-04-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"3184c304-52d3-4baa-b3c2-90957e1d8e79"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3184c304-52d3-4baa-b3c2-90957e1d8e79?source=api-prod","cve":"CVE-2021-24915","affectedVersions":"<=13.1.0.5","severity":"critical"},{"advisoryId":"WPSECADV/WF/3b1b1a55-7872-456f-a754-023aad354359/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_multiple_files_for_post\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"3b1b1a55-7872-456f-a754-023aad354359"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3b1b1a55-7872-456f-a754-023aad354359?source=api-prod","cve":"CVE-2022-4164","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/3e3c9f08-9e73-4791-b6ca-2c8b9dc3fb81/contest-gallery","title":"Contest Gallery < 21.2.8.1 - Unauthenticated Stored Cross-Site Scripting via headers\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"3e3c9f08-9e73-4791-b6ca-2c8b9dc3fb81"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3e3c9f08-9e73-4791-b6ca-2c8b9dc3fb81?source=api-prod","cve":"CVE-2023-5307","affectedVersions":"<21.2.8.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/3e9672b1-6d00-45bc-91ef-0c5583b5306e/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_copy_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"3e9672b1-6d00-45bc-91ef-0c5583b5306e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3e9672b1-6d00-45bc-91ef-0c5583b5306e?source=api-prod","cve":"CVE-2022-4160","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/407d8ebe-f3fc-433a-856f-de2ad4e58b9e/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_copy_start\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"407d8ebe-f3fc-433a-856f-de2ad4e58b9e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/407d8ebe-f3fc-433a-856f-de2ad4e58b9e?source=api-prod","cve":"CVE-2022-4161","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/5d080f5b-6646-47ef-8ae7-8b94270f9f59/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_activate and cg_deactivate\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"5d080f5b-6646-47ef-8ae7-8b94270f9f59"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5d080f5b-6646-47ef-8ae7-8b94270f9f59?source=api-prod","cve":"CVE-2022-4163","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/691eb4c1-18ba-433b-8725-70f2ecf89b0a/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via option_id GET\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"691eb4c1-18ba-433b-8725-70f2ecf89b0a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/691eb4c1-18ba-433b-8725-70f2ecf89b0a?source=api-prod","cve":"CVE-2022-4152","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/6f854ffc-244b-45c3-94ce-198e85c11869/contest-gallery","title":"Contest Gallery <= 28.0.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f854ffc-244b-45c3-94ce-198e85c11869"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f854ffc-244b-45c3-94ce-198e85c11869?source=api-prod","cve":"CVE-2025-62950","affectedVersions":"<=28.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/6f946251-c7be-4ef6-885f-8b378c0c234c/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_order\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f946251-c7be-4ef6-885f-8b378c0c234c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f946251-c7be-4ef6-885f-8b378c0c234c?source=api-prod","cve":"CVE-2022-4165","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/75c6697c-bc1d-456f-baee-ee9c57e40d21/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_row\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"75c6697c-bc1d-456f-baee-ee9c57e40d21"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/75c6697c-bc1d-456f-baee-ee9c57e40d21?source=api-prod","cve":"CVE-2022-4162","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/768d0d53-8724-4598-ae73-305225b52633/contest-gallery","title":"Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"768d0d53-8724-4598-ae73-305225b52633"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/768d0d53-8724-4598-ae73-305225b52633?source=api-prod","cve":"CVE-2026-40771","affectedVersions":"<=28.1.6","severity":"high"},{"advisoryId":"WPSECADV/WF/7759b209-4211-4ee5-ae7a-42645f5d5e96/contest-gallery","title":"Contest Gallery < 13.1.0.7 - Authenticated Email Address Disclosure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"7759b209-4211-4ee5-ae7a-42645f5d5e96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7759b209-4211-4ee5-ae7a-42645f5d5e96?source=api-prod","affectedVersions":"<13.1.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/78f745f9-c44e-4458-9381-f639c842a31e/contest-gallery","title":"Contest Gallery <= 13.1.0.9 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-12-20 12:39:00","sources":[{"name":"Wordfence","remoteId":"78f745f9-c44e-4458-9381-f639c842a31e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/78f745f9-c44e-4458-9381-f639c842a31e?source=api-prod","cve":"CVE-2022-27853","affectedVersions":"<=13.1.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/79fb4f24-8a59-4e57-b583-c87ee2493cdb/contest-gallery","title":"Photos and Files Contest Gallery <= 21.3.4 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"79fb4f24-8a59-4e57-b583-c87ee2493cdb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/79fb4f24-8a59-4e57-b583-c87ee2493cdb?source=api-prod","cve":"CVE-2024-30236","affectedVersions":"<=21.3.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/7c2482cc-1717-4fae-b45b-3a1a1ce95fdc/contest-gallery","title":"Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"7c2482cc-1717-4fae-b45b-3a1a1ce95fdc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c2482cc-1717-4fae-b45b-3a1a1ce95fdc?source=api-prod","cve":"CVE-2026-42657","affectedVersions":"<=28.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/7db0a94e-2633-4f62-adb6-9acb3f884cb8/contest-gallery","title":"Contest Gallery <= 28.1.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"7db0a94e-2633-4f62-adb6-9acb3f884cb8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7db0a94e-2633-4f62-adb6-9acb3f884cb8?source=api-prod","cve":"CVE-2026-24965","affectedVersions":"<=28.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/7dbd3b23-cebc-4212-bcae-c6f23031c040/contest-gallery","title":"Contest Gallery <= 21.1.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"7dbd3b23-cebc-4212-bcae-c6f23031c040"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7dbd3b23-cebc-4212-bcae-c6f23031c040?source=api-prod","cve":"CVE-2023-28784","affectedVersions":"<=21.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/7ef37e72-f98f-4df6-8adb-514690350a82/contest-gallery","title":"Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress <= 21.3.0 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"7ef37e72-f98f-4df6-8adb-514690350a82"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7ef37e72-f98f-4df6-8adb-514690350a82?source=api-prod","cve":"CVE-2024-1487","affectedVersions":"<=21.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/8b0c54f2-3942-48bd-b821-b66a57fd1506/contest-gallery","title":"Contest Gallery <= 21.3.5 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"8b0c54f2-3942-48bd-b821-b66a57fd1506"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8b0c54f2-3942-48bd-b821-b66a57fd1506?source=api-prod","cve":"CVE-2024-30428","affectedVersions":"<=21.3.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/8ed63de5-ef65-4e90-afc1-b7a075e99316/contest-gallery","title":"Contest Gallery <= 21.3.4 - Authenticated (Author+) Arbitrary File Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ed63de5-ef65-4e90-afc1-b7a075e99316"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ed63de5-ef65-4e90-afc1-b7a075e99316?source=api-prod","cve":"CVE-2024-32778","affectedVersions":"<=21.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/91d52a64-8dc1-4923-be0b-06800382151e/contest-gallery","title":"Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 04:44:39","sources":[{"name":"Wordfence","remoteId":"91d52a64-8dc1-4923-be0b-06800382151e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91d52a64-8dc1-4923-be0b-06800382151e?source=api-prod","cve":"CVE-2026-3180","affectedVersions":"<=28.1.4","severity":"high"},{"advisoryId":"WPSECADV/WF/9a0dc62c-786d-40f3-b9c9-bd199a176192/contest-gallery","title":"Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-10 19:47:00","sources":[{"name":"Wordfence","remoteId":"9a0dc62c-786d-40f3-b9c9-bd199a176192"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9a0dc62c-786d-40f3-b9c9-bd199a176192?source=api-prod","cve":"CVE-2025-11254","affectedVersions":"<=27.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/a1525119-732d-4948-9c33-75e9f3517c0d/contest-gallery","title":"Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"a1525119-732d-4948-9c33-75e9f3517c0d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a1525119-732d-4948-9c33-75e9f3517c0d?source=api-prod","cve":"CVE-2026-42656","affectedVersions":"<=28.1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/a1b043a1-7bee-4ef0-86d9-19cf202cfc71/contest-gallery","title":"Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 22:33:58","sources":[{"name":"Wordfence","remoteId":"a1b043a1-7bee-4ef0-86d9-19cf202cfc71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a1b043a1-7bee-4ef0-86d9-19cf202cfc71?source=api-prod","cve":"CVE-2025-3862","affectedVersions":"<=26.0.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/a443e857-a915-4aa4-9879-1465d50544cc/contest-gallery","title":"Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Authenticated (Subscriber+) Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"a443e857-a915-4aa4-9879-1465d50544cc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a443e857-a915-4aa4-9879-1465d50544cc?source=api-prod","cve":"CVE-2026-42660","affectedVersions":"<=28.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/b24625d7-2a38-451b-ab79-a1d9c5b8822a/contest-gallery","title":"Contest Gallery <= 19.1.5 - Authenticated (Author+) SQL Injection via cg_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"b24625d7-2a38-451b-ab79-a1d9c5b8822a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b24625d7-2a38-451b-ab79-a1d9c5b8822a?source=api-prod","cve":"CVE-2022-4159","affectedVersions":"<=19.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/cf24ee30-7d9f-47c3-bc2a-1c3c92971ba8/contest-gallery","title":"Contest Gallery <= 19.1.5 - Authenticated (Author+) SQL Injection via upload[]\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"cf24ee30-7d9f-47c3-bc2a-1c3c92971ba8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cf24ee30-7d9f-47c3-bc2a-1c3c92971ba8?source=api-prod","cve":"CVE-2022-4153","affectedVersions":"<=19.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/de379f74-660a-4e59-b1c4-4b88dff8a843/contest-gallery","title":"Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-03 14:48:39","sources":[{"name":"Wordfence","remoteId":"de379f74-660a-4e59-b1c4-4b88dff8a843"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/de379f74-660a-4e59-b1c4-4b88dff8a843?source=api-prod","cve":"CVE-2025-10383","affectedVersions":"<=27.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e000c4ad-43ec-4ad0-89f9-74e9e6d8b917/contest-gallery","title":"Contest Gallery <= 28.0.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-14 18:27:20","sources":[{"name":"Wordfence","remoteId":"e000c4ad-43ec-4ad0-89f9-74e9e6d8b917"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e000c4ad-43ec-4ad0-89f9-74e9e6d8b917?source=api-prod","cve":"CVE-2025-12849","affectedVersions":"<=28.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e4ed8c6e-5f80-4360-9478-fff49b1fee94/contest-gallery","title":"Contest Gallery <= 21.2.8.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"e4ed8c6e-5f80-4360-9478-fff49b1fee94"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e4ed8c6e-5f80-4360-9478-fff49b1fee94?source=api-prod","cve":"CVE-2024-24887","affectedVersions":"<=21.2.8.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/e54caaf5-f37b-4842-ab3d-8e37cbed58da/contest-gallery","title":"Contest Gallery <= 26.0.8 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-10 18:41:31","sources":[{"name":"Wordfence","remoteId":"e54caaf5-f37b-4842-ab3d-8e37cbed58da"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e54caaf5-f37b-4842-ab3d-8e37cbed58da?source=api-prod","cve":"CVE-2025-6716","affectedVersions":"<=26.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/e7fcda2b-d679-44af-9592-4a96a0115a08/contest-gallery","title":"Contest Gallery (Pro) <= 19.1.5 - SQL Injection via option_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7fcda2b-d679-44af-9592-4a96a0115a08"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7fcda2b-d679-44af-9592-4a96a0115a08?source=api-prod","cve":"CVE-2022-4150","affectedVersions":"<=19.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/f185709e-0d13-48d3-9c15-03466b72dac2/contest-gallery","title":"Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via addCountS\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"f185709e-0d13-48d3-9c15-03466b72dac2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f185709e-0d13-48d3-9c15-03466b72dac2?source=api-prod","cve":"CVE-2022-4166","affectedVersions":"<=19.1.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/f1b9725b-dee5-44ca-bb33-c6812fb76adc/contest-gallery","title":"Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 11:19:11","sources":[{"name":"Wordfence","remoteId":"f1b9725b-dee5-44ca-bb33-c6812fb76adc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f1b9725b-dee5-44ca-bb33-c6812fb76adc?source=api-prod","cve":"CVE-2026-4021","affectedVersions":"<=28.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/f2b5213d-fdc5-4c98-9a05-15d83bd7308f/contest-gallery","title":"Contest Gallery <= 21.2.8.4 - Cross-Site Request Forgery\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"f2b5213d-fdc5-4c98-9a05-15d83bd7308f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2b5213d-fdc5-4c98-9a05-15d83bd7308f?source=api-prod","affectedVersions":"<=21.2.8.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/f36af71c-78af-402c-9d3a-3752368e7584/contest-gallery","title":"Contest Gallery <= 13.1.0.9 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"f36af71c-78af-402c-9d3a-3752368e7584"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f36af71c-78af-402c-9d3a-3752368e7584?source=api-prod","cve":"CVE-2022-45848","affectedVersions":"<=13.1.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/f5e400f8-35b4-4be4-bb00-c59e14ddd57f/contest-gallery","title":"Contest Gallery <= 23.1.2 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"f5e400f8-35b4-4be4-bb00-c59e14ddd57f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5e400f8-35b4-4be4-bb00-c59e14ddd57f?source=api-prod","cve":"CVE-2024-43283","affectedVersions":"<=23.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f9b90e03-cdaa-4bd3-9afd-5d5c91a17962/contest-gallery","title":"Contest Gallery <= 17.0.4 - Authenticated (Author+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"f9b90e03-cdaa-4bd3-9afd-5d5c91a17962"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f9b90e03-cdaa-4bd3-9afd-5d5c91a17962?source=api-prod","cve":"CVE-2022-36394","affectedVersions":"<=17.0.4","severity":"high"},{"advisoryId":"WPSECADV/WF/fb4b6d33-82cd-4c41-ba54-dbc7fe5f6ac6/contest-gallery","title":"Contest Gallery – Photo Contest Plugin for WordPress <= 10.4.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-06-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"fb4b6d33-82cd-4c41-ba54-dbc7fe5f6ac6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fb4b6d33-82cd-4c41-ba54-dbc7fe5f6ac6?source=api-prod","cve":"CVE-2019-5974","affectedVersions":"<=10.4.4","severity":"high"},{"advisoryId":"WPSECADV/WF/fd3b4c44-d47a-45de-bcb2-0820e475b331/contest-gallery","title":"Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-04 21:11:26","sources":[{"name":"Wordfence","remoteId":"fd3b4c44-d47a-45de-bcb2-0820e475b331"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd3b4c44-d47a-45de-bcb2-0820e475b331?source=api-prod","cve":"CVE-2024-10687","affectedVersions":"<=24.0.3","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_637573746f6d2d726567697374726174696f6e2d666f726d2d6275696c6465722d776974682d7375626d697373696f6e2d6d616e61676572811c9dc5_gen.json b/internal/data/assets/plugin_637573746f6d2d726567697374726174696f6e2d666f726d2d6275696c6465722d776974682d7375626d697373696f6e2d6d616e61676572811c9dc5_gen.json index 472d036a..3fd69aca 100644 --- a/internal/data/assets/plugin_637573746f6d2d726567697374726174696f6e2d666f726d2d6275696c6465722d776974682d7375626d697373696f6e2d6d616e61676572811c9dc5_gen.json +++ b/internal/data/assets/plugin_637573746f6d2d726567697374726174696f6e2d666f726d2d6275696c6465722d776974682d7375626d697373696f6e2d6d616e61676572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0633bf06-6580-4feb-b98a-c465df3e2bed/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.9 - Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 21:54:57","sources":[{"name":"Wordfence","remoteId":"0633bf06-6580-4feb-b98a-c465df3e2bed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0633bf06-6580-4feb-b98a-c465df3e2bed?source=api-prod","cve":"CVE-2025-14444","affectedVersions":"<=6.0.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/0d041b14-0d05-4bfe-bd5c-7e06d7b108b8/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.3.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d041b14-0d05-4bfe-bd5c-7e06d7b108b8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d041b14-0d05-4bfe-bd5c-7e06d7b108b8?source=api-prod","cve":"CVE-2023-49831","affectedVersions":"<=5.2.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/184b9ae4-945a-4602-99da-679ff9db3029/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.1.0 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"184b9ae4-945a-4602-99da-679ff9db3029"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/184b9ae4-945a-4602-99da-679ff9db3029?source=api-prod","cve":"CVE-2024-43317","affectedVersions":"<=6.0.1.0","severity":"high"},{"advisoryId":"WPSECADV/WF/1c23d163-1053-403f-80bc-ea8f76fff4e2/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms and User Login <= 4.6.0.3 - Cross-Site Request Forgery to Settings Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c23d163-1053-403f-80bc-ea8f76fff4e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c23d163-1053-403f-80bc-ea8f76fff4e2?source=api-prod","cve":"CVE-2020-9454","affectedVersions":"<4.6.0.4","severity":"high"},{"advisoryId":"WPSECADV/WF/241dc2e4-b079-407b-b610-c40b23d038cb/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms and User Login <= 4.6.0.3 - Authenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"241dc2e4-b079-407b-b610-c40b23d038cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/241dc2e4-b079-407b-b610-c40b23d038cb?source=api-prod","cve":"CVE-2020-9456","affectedVersions":"<4.6.0.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/24f2eafc-c8eb-4d78-af5e-1a589d7e4d21/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.3.2.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"24f2eafc-c8eb-4d78-af5e-1a589d7e4d21"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/24f2eafc-c8eb-4d78-af5e-1a589d7e4d21?source=api-prod","cve":"CVE-2024-33947","affectedVersions":"<=5.3.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/26d70dee-c098-40f1-962a-db56791ae221/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.5.9 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"26d70dee-c098-40f1-962a-db56791ae221"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/26d70dee-c098-40f1-962a-db56791ae221?source=api-prod","cve":"CVE-2024-25935","affectedVersions":"<=5.2.5.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/2d010e55-d57a-49f7-a991-76b676b88f1e/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.4.1 - Reflected Cross-Site Scripting via section_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"2d010e55-d57a-49f7-a991-76b676b88f1e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2d010e55-d57a-49f7-a991-76b676b88f1e?source=api-prod","cve":"CVE-2023-51509","affectedVersions":"<5.2.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/41985e86-eda4-4914-a7f8-3758afcc6193/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.0.1 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"41985e86-eda4-4914-a7f8-3758afcc6193"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/41985e86-eda4-4914-a7f8-3758afcc6193?source=api-prod","cve":"CVE-2024-39643","affectedVersions":"<=6.0.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/4532cb38-453b-460c-879d-6f0e1caacafc/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.2 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-07 16:05:36","sources":[{"name":"Wordfence","remoteId":"4532cb38-453b-460c-879d-6f0e1caacafc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4532cb38-453b-460c-879d-6f0e1caacafc?source=api-prod","cve":"CVE-2025-11204","affectedVersions":"<=6.0.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/4b37b57c-4a11-4971-b38f-12c70d71b76b/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.5.0 - IP Spoofing\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"4b37b57c-4a11-4971-b38f-12c70d71b76b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4b37b57c-4a11-4971-b38f-12c70d71b76b?source=api-prod","cve":"CVE-2023-51543","affectedVersions":"<=5.2.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/4b71b187-2e05-4bea-9177-cbf66fe08a44/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic - Custom Registration Forms, User Registration and User Login Plugin <= 4.6.0.2 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"4b71b187-2e05-4bea-9177-cbf66fe08a44"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4b71b187-2e05-4bea-9177-cbf66fe08a44?source=api-prod","cve":"CVE-2020-8435","affectedVersions":"<4.6.0.3","severity":"high"},{"advisoryId":"WPSECADV/WF/4be512bd-190a-415a-bd20-a49373f63fbb/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'RM_Forms' Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 02:16:59","sources":[{"name":"Wordfence","remoteId":"4be512bd-190a-415a-bd20-a49373f63fbb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4be512bd-190a-415a-bd20-a49373f63fbb?source=api-prod","cve":"CVE-2025-13610","affectedVersions":"<=6.0.6.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/52efc168-fed9-45c6-9a2c-1e3a198f71f9/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.0.2.1 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"52efc168-fed9-45c6-9a2c-1e3a198f71f9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/52efc168-fed9-45c6-9a2c-1e3a198f71f9?source=api-prod","cve":"CVE-2022-0420","affectedVersions":"<5.0.2.2","severity":"high"},{"advisoryId":"WPSECADV/WF/547e5814-0201-4dbf-9d2d-8028ca055402/custom-registration-form-builder-with-submission-manager","title":"Registration Magic <= 5.0.1.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-12-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"547e5814-0201-4dbf-9d2d-8028ca055402"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/547e5814-0201-4dbf-9d2d-8028ca055402?source=api-prod","cve":"CVE-2021-24648","affectedVersions":"<=5.0.1.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/63099a49-913f-428d-b9a4-85e1bc5afe56/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.7.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"63099a49-913f-428d-b9a4-85e1bc5afe56"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63099a49-913f-428d-b9a4-85e1bc5afe56?source=api-prod","cve":"CVE-2026-32385","affectedVersions":"<=6.0.7.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/6478cdbc-a20e-4fe2-bbd6-8a550e5da895/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.1.0 - Authenticated (Contributor+) SQL Injection via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"6478cdbc-a20e-4fe2-bbd6-8a550e5da895"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6478cdbc-a20e-4fe2-bbd6-8a550e5da895?source=api-prod","cve":"CVE-2024-1990","affectedVersions":"<=5.3.1.0","severity":"high"},{"advisoryId":"WPSECADV/WF/68dd9f6f-ccee-4a27-bd21-2fb32b92cc62/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-16 13:22:33","sources":[{"name":"Wordfence","remoteId":"68dd9f6f-ccee-4a27-bd21-2fb32b92cc62"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/68dd9f6f-ccee-4a27-bd21-2fb32b92cc62?source=api-prod","cve":"CVE-2025-15403","affectedVersions":"<=6.0.7.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/6f6883e4-3de6-4ca9-a26c-0b4f3bd5b70f/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic - Custom Registration Forms <= 3.7.9.4 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-12-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f6883e4-3de6-4ca9-a26c-0b4f3bd5b70f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f6883e4-3de6-4ca9-a26c-0b4f3bd5b70f?source=api-prod","affectedVersions":"<=3.7.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/6fde9239-edac-4f85-be12-80825595a332/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic - Custom Registration Forms <= 3.8.0.4 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-12-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"6fde9239-edac-4f85-be12-80825595a332"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6fde9239-edac-4f85-be12-80825595a332?source=api-prod","affectedVersions":"<=3.8.0.4","severity":"high"},{"advisoryId":"WPSECADV/WF/766e3966-157a-4db3-9179-813032343f76/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.0.0 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"766e3966-157a-4db3-9179-813032343f76"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/766e3966-157a-4db3-9179-813032343f76?source=api-prod","cve":"CVE-2024-1991","affectedVersions":"<=5.3.0.0","severity":"high"},{"advisoryId":"WPSECADV/WF/7dcde10d-4eb7-42fe-926e-05e56affc521/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.2.6 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"7dcde10d-4eb7-42fe-926e-05e56affc521"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7dcde10d-4eb7-42fe-926e-05e56affc521?source=api-prod","cve":"CVE-2023-47645","affectedVersions":"<=5.2.2.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/7f7d16d2-ecc0-4352-b7b9-2c3242f43dbf/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms and User Login <= 4.6.0.3 - Authenticated Settings and User Data Export\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"7f7d16d2-ecc0-4352-b7b9-2c3242f43dbf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7f7d16d2-ecc0-4352-b7b9-2c3242f43dbf?source=api-prod","cve":"CVE-2020-9458","affectedVersions":"<4.6.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/86ebb3d1-5fd1-48cb-95b7-f82014323f01/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.5.0 - Form Submission Limit Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"86ebb3d1-5fd1-48cb-95b7-f82014323f01"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/86ebb3d1-5fd1-48cb-95b7-f82014323f01?source=api-prod","cve":"CVE-2023-51544","affectedVersions":"<=5.2.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/87ec5542-b6e7-4b18-a3ec-c258e749d32e/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.1.0 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"87ec5542-b6e7-4b18-a3ec-c258e749d32e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/87ec5542-b6e7-4b18-a3ec-c258e749d32e?source=api-prod","cve":"CVE-2023-2499","affectedVersions":"<=5.2.1.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/91a83f52-069e-4611-9b46-4a1913e23f42/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic < 6.0.7.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"91a83f52-069e-4611-9b46-4a1913e23f42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91a83f52-069e-4611-9b46-4a1913e23f42?source=api-prod","cve":"CVE-2026-0929","affectedVersions":"<6.0.7.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9396c350-d72e-472b-8cbc-44edce557256/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.5.9 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"9396c350-d72e-472b-8cbc-44edce557256"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9396c350-d72e-472b-8cbc-44edce557256?source=api-prod","cve":"CVE-2024-29113","affectedVersions":"<=5.2.5.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/9b378df7-b182-4a56-a7fa-3228c06f960f/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic Plugin <= 5.2.4.5 - Authenticated(Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"9b378df7-b182-4a56-a7fa-3228c06f960f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9b378df7-b182-4a56-a7fa-3228c06f960f?source=api-prod","cve":"CVE-2023-50846","affectedVersions":"<5.2.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/9c0c3932-bdb0-4edb-bfec-2ed52cbc5cb6/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"9c0c3932-bdb0-4edb-bfec-2ed52cbc5cb6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9c0c3932-bdb0-4edb-bfec-2ed52cbc5cb6?source=api-prod","cve":"CVE-2025-2836","affectedVersions":"<=6.0.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/a023cdc5-3814-4120-86b2-6a60d385f898/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms and User Login <= 4.6.0.3 - Authenticated Email Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"a023cdc5-3814-4120-86b2-6a60d385f898"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a023cdc5-3814-4120-86b2-6a60d385f898?source=api-prod","cve":"CVE-2020-9455","affectedVersions":"<=4.6.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6da046f-a16f-4a93-b3c6-04270538b7a9/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.3.0.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"b6da046f-a16f-4a93-b3c6-04270538b7a9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6da046f-a16f-4a93-b3c6-04270538b7a9?source=api-prod","cve":"CVE-2024-2951","affectedVersions":"<=5.3.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/bfbc406b-49af-419e-adeb-0510794b7e3f/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.0.5 - Authenticated (Admin+) Insecure Direct Object Reference to Arbitrary User Password Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"bfbc406b-49af-419e-adeb-0510794b7e3f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bfbc406b-49af-419e-adeb-0510794b7e3f?source=api-prod","cve":"CVE-2023-2548","affectedVersions":"<=5.2.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/c2b79193-f8fc-4ea2-8973-fe292cfb926b/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic - Custom Registration Forms <= 3.7.9.2 - PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-10-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"c2b79193-f8fc-4ea2-8973-fe292cfb926b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c2b79193-f8fc-4ea2-8973-fe292cfb926b?source=api-prod","cve":"CVE-2017-20208","affectedVersions":"<3.7.9.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/c4679fa7-be6b-4f50-8cdf-ff9822794f19/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"c4679fa7-be6b-4f50-8cdf-ff9822794f19"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c4679fa7-be6b-4f50-8cdf-ff9822794f19?source=api-prod","cve":"CVE-2024-10508","affectedVersions":"<=6.0.2.6","severity":"critical"},{"advisoryId":"WPSECADV/WF/cb269a48-e813-4cda-821a-ee70431372d2/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.2 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"cb269a48-e813-4cda-821a-ee70431372d2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cb269a48-e813-4cda-821a-ee70431372d2?source=api-prod","cve":"CVE-2024-9390","affectedVersions":"<=6.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/d3088e5b-9e3c-4021-b99a-26ac90ece82e/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.6.9 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"d3088e5b-9e3c-4021-b99a-26ac90ece82e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d3088e5b-9e3c-4021-b99a-26ac90ece82e?source=api-prod","cve":"CVE-2026-24374","affectedVersions":"<=6.0.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/d46f8e8a-80cb-4407-ac07-f4c93be691b6/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin <= 4.6.0.1 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-01-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"d46f8e8a-80cb-4407-ac07-f4c93be691b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d46f8e8a-80cb-4407-ac07-f4c93be691b6?source=api-prod","cve":"CVE-2020-8436","affectedVersions":"<=4.6.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/d590e730-ad5f-4046-b897-c3b8aed250b3/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.1 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"d590e730-ad5f-4046-b897-c3b8aed250b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d590e730-ad5f-4046-b897-c3b8aed250b3?source=api-prod","cve":"CVE-2026-24373","affectedVersions":"<=6.0.7.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/d87c4534-3f71-4e7e-bf17-222e77fee24f/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.1 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"d87c4534-3f71-4e7e-bf17-222e77fee24f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d87c4534-3f71-4e7e-bf17-222e77fee24f?source=api-prod","cve":"CVE-2025-15520","affectedVersions":"<=6.0.7.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/d8ba4a74-6649-4566-b9d5-19662539158b/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.0.1.5 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"d8ba4a74-6649-4566-b9d5-19662539158b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d8ba4a74-6649-4566-b9d5-19662539158b?source=api-prod","cve":"CVE-2021-24862","affectedVersions":"<=5.0.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/daf4d246-85f3-48b3-985f-982fea4772f1/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.7.4 - Missing Authorization to Unauthenticated Arbitrary Settings Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-27 19:10:54","sources":[{"name":"Wordfence","remoteId":"daf4d246-85f3-48b3-985f-982fea4772f1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/daf4d246-85f3-48b3-985f-982fea4772f1?source=api-prod","cve":"CVE-2026-1054","affectedVersions":"<=6.0.7.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/e7939401-822c-4d27-9d8c-c5680165e6a7/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms and User Login <= 4.6.0.3 - Authenticated Settings Import to Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7939401-822c-4d27-9d8c-c5680165e6a7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7939401-822c-4d27-9d8c-c5680165e6a7?source=api-prod","cve":"CVE-2020-9457","affectedVersions":"<=4.6.0.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/f6515d70-438b-47b7-a3c4-5b8dc401a40e/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"f6515d70-438b-47b7-a3c4-5b8dc401a40e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f6515d70-438b-47b7-a3c4-5b8dc401a40e?source=api-prod","cve":"CVE-2026-32498","affectedVersions":"<=6.0.7.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/fbd978fd-f759-4983-90b0-af7338e21d30/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.0.1.7 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-12-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"fbd978fd-f759-4983-90b0-af7338e21d30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fbd978fd-f759-4983-90b0-af7338e21d30?source=api-prod","cve":"CVE-2021-4073","affectedVersions":"<=5.0.1.7","severity":"critical"},{"advisoryId":"WPSECADV/WF/fcfb3a6e-7b58-4568-8439-e9c68a2223b9/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.1.9.2 - Cross-Site Request Forgery leading to Form Metadata Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"fcfb3a6e-7b58-4568-8439-e9c68a2223b9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fcfb3a6e-7b58-4568-8439-e9c68a2223b9?source=api-prod","cve":"CVE-2023-25991","affectedVersions":"<=5.1.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/fd78d162-d9aa-4623-9b89-5f1455739836/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.3.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd78d162-d9aa-4623-9b89-5f1455739836"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd78d162-d9aa-4623-9b89-5f1455739836?source=api-prod","cve":"CVE-2025-24686","affectedVersions":"<=6.0.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/fde0ab44-a354-4cbe-8548-0e5c08529082/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.1.9.2 - Missing Authorization to Unauthenticated Content Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"fde0ab44-a354-4cbe-8548-0e5c08529082"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fde0ab44-a354-4cbe-8548-0e5c08529082?source=api-prod","cve":"CVE-2023-23989","affectedVersions":"<=5.1.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/feeb70e4-b602-40ce-bdeb-d947c6b6784d/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.1.9.2 - Improper Authorization to Price Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"feeb70e4-b602-40ce-bdeb-d947c6b6784d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/feeb70e4-b602-40ce-bdeb-d947c6b6784d?source=api-prod","cve":"CVE-2023-23976","affectedVersions":"<=5.1.9.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0633bf06-6580-4feb-b98a-c465df3e2bed/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.9 - Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 21:54:57","sources":[{"name":"Wordfence","remoteId":"0633bf06-6580-4feb-b98a-c465df3e2bed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0633bf06-6580-4feb-b98a-c465df3e2bed?source=api-prod","cve":"CVE-2025-14444","affectedVersions":"<=6.0.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/0d041b14-0d05-4bfe-bd5c-7e06d7b108b8/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.3.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d041b14-0d05-4bfe-bd5c-7e06d7b108b8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d041b14-0d05-4bfe-bd5c-7e06d7b108b8?source=api-prod","cve":"CVE-2023-49831","affectedVersions":"<=5.2.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/184b9ae4-945a-4602-99da-679ff9db3029/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.1.0 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"184b9ae4-945a-4602-99da-679ff9db3029"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/184b9ae4-945a-4602-99da-679ff9db3029?source=api-prod","cve":"CVE-2024-43317","affectedVersions":"<=6.0.1.0","severity":"high"},{"advisoryId":"WPSECADV/WF/1c23d163-1053-403f-80bc-ea8f76fff4e2/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms and User Login <= 4.6.0.3 - Cross-Site Request Forgery to Settings Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c23d163-1053-403f-80bc-ea8f76fff4e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c23d163-1053-403f-80bc-ea8f76fff4e2?source=api-prod","cve":"CVE-2020-9454","affectedVersions":"<4.6.0.4","severity":"high"},{"advisoryId":"WPSECADV/WF/241dc2e4-b079-407b-b610-c40b23d038cb/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms and User Login <= 4.6.0.3 - Authenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"241dc2e4-b079-407b-b610-c40b23d038cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/241dc2e4-b079-407b-b610-c40b23d038cb?source=api-prod","cve":"CVE-2020-9456","affectedVersions":"<4.6.0.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/24f2eafc-c8eb-4d78-af5e-1a589d7e4d21/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.3.2.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"24f2eafc-c8eb-4d78-af5e-1a589d7e4d21"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/24f2eafc-c8eb-4d78-af5e-1a589d7e4d21?source=api-prod","cve":"CVE-2024-33947","affectedVersions":"<=5.3.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/26d70dee-c098-40f1-962a-db56791ae221/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.5.9 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"26d70dee-c098-40f1-962a-db56791ae221"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/26d70dee-c098-40f1-962a-db56791ae221?source=api-prod","cve":"CVE-2024-25935","affectedVersions":"<=5.2.5.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/2d010e55-d57a-49f7-a991-76b676b88f1e/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.4.1 - Reflected Cross-Site Scripting via section_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"2d010e55-d57a-49f7-a991-76b676b88f1e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2d010e55-d57a-49f7-a991-76b676b88f1e?source=api-prod","cve":"CVE-2023-51509","affectedVersions":"<5.2.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/41985e86-eda4-4914-a7f8-3758afcc6193/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.0.1 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"41985e86-eda4-4914-a7f8-3758afcc6193"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/41985e86-eda4-4914-a7f8-3758afcc6193?source=api-prod","cve":"CVE-2024-39643","affectedVersions":"<=6.0.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/4532cb38-453b-460c-879d-6f0e1caacafc/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.2 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-07 16:05:36","sources":[{"name":"Wordfence","remoteId":"4532cb38-453b-460c-879d-6f0e1caacafc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4532cb38-453b-460c-879d-6f0e1caacafc?source=api-prod","cve":"CVE-2025-11204","affectedVersions":"<=6.0.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/4b37b57c-4a11-4971-b38f-12c70d71b76b/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.5.0 - IP Spoofing\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"4b37b57c-4a11-4971-b38f-12c70d71b76b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4b37b57c-4a11-4971-b38f-12c70d71b76b?source=api-prod","cve":"CVE-2023-51543","affectedVersions":"<=5.2.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/4b71b187-2e05-4bea-9177-cbf66fe08a44/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic - Custom Registration Forms, User Registration and User Login Plugin <= 4.6.0.2 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"4b71b187-2e05-4bea-9177-cbf66fe08a44"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4b71b187-2e05-4bea-9177-cbf66fe08a44?source=api-prod","cve":"CVE-2020-8435","affectedVersions":"<4.6.0.3","severity":"high"},{"advisoryId":"WPSECADV/WF/4be512bd-190a-415a-bd20-a49373f63fbb/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'RM_Forms' Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 02:16:59","sources":[{"name":"Wordfence","remoteId":"4be512bd-190a-415a-bd20-a49373f63fbb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4be512bd-190a-415a-bd20-a49373f63fbb?source=api-prod","cve":"CVE-2025-13610","affectedVersions":"<=6.0.6.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/52efc168-fed9-45c6-9a2c-1e3a198f71f9/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.0.2.1 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"52efc168-fed9-45c6-9a2c-1e3a198f71f9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/52efc168-fed9-45c6-9a2c-1e3a198f71f9?source=api-prod","cve":"CVE-2022-0420","affectedVersions":"<5.0.2.2","severity":"high"},{"advisoryId":"WPSECADV/WF/547e5814-0201-4dbf-9d2d-8028ca055402/custom-registration-form-builder-with-submission-manager","title":"Registration Magic <= 5.0.1.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-12-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"547e5814-0201-4dbf-9d2d-8028ca055402"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/547e5814-0201-4dbf-9d2d-8028ca055402?source=api-prod","cve":"CVE-2021-24648","affectedVersions":"<=5.0.1.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/63099a49-913f-428d-b9a4-85e1bc5afe56/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.7.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"63099a49-913f-428d-b9a4-85e1bc5afe56"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63099a49-913f-428d-b9a4-85e1bc5afe56?source=api-prod","cve":"CVE-2026-32385","affectedVersions":"<=6.0.7.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/6478cdbc-a20e-4fe2-bbd6-8a550e5da895/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.1.0 - Authenticated (Contributor+) SQL Injection via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"6478cdbc-a20e-4fe2-bbd6-8a550e5da895"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6478cdbc-a20e-4fe2-bbd6-8a550e5da895?source=api-prod","cve":"CVE-2024-1990","affectedVersions":"<=5.3.1.0","severity":"high"},{"advisoryId":"WPSECADV/WF/68dd9f6f-ccee-4a27-bd21-2fb32b92cc62/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-16 13:22:33","sources":[{"name":"Wordfence","remoteId":"68dd9f6f-ccee-4a27-bd21-2fb32b92cc62"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/68dd9f6f-ccee-4a27-bd21-2fb32b92cc62?source=api-prod","cve":"CVE-2025-15403","affectedVersions":"<=6.0.7.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/6f6883e4-3de6-4ca9-a26c-0b4f3bd5b70f/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic - Custom Registration Forms <= 3.7.9.4 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-12-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f6883e4-3de6-4ca9-a26c-0b4f3bd5b70f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f6883e4-3de6-4ca9-a26c-0b4f3bd5b70f?source=api-prod","affectedVersions":"<=3.7.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/6fde9239-edac-4f85-be12-80825595a332/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic - Custom Registration Forms <= 3.8.0.4 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-12-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"6fde9239-edac-4f85-be12-80825595a332"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6fde9239-edac-4f85-be12-80825595a332?source=api-prod","affectedVersions":"<=3.8.0.4","severity":"high"},{"advisoryId":"WPSECADV/WF/766e3966-157a-4db3-9179-813032343f76/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.0.0 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"766e3966-157a-4db3-9179-813032343f76"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/766e3966-157a-4db3-9179-813032343f76?source=api-prod","cve":"CVE-2024-1991","affectedVersions":"<=5.3.0.0","severity":"high"},{"advisoryId":"WPSECADV/WF/7dcde10d-4eb7-42fe-926e-05e56affc521/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.2.6 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"7dcde10d-4eb7-42fe-926e-05e56affc521"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7dcde10d-4eb7-42fe-926e-05e56affc521?source=api-prod","cve":"CVE-2023-47645","affectedVersions":"<=5.2.2.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/7f7d16d2-ecc0-4352-b7b9-2c3242f43dbf/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms and User Login <= 4.6.0.3 - Authenticated Settings and User Data Export\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"7f7d16d2-ecc0-4352-b7b9-2c3242f43dbf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7f7d16d2-ecc0-4352-b7b9-2c3242f43dbf?source=api-prod","cve":"CVE-2020-9458","affectedVersions":"<4.6.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/86ebb3d1-5fd1-48cb-95b7-f82014323f01/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.5.0 - Form Submission Limit Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"86ebb3d1-5fd1-48cb-95b7-f82014323f01"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/86ebb3d1-5fd1-48cb-95b7-f82014323f01?source=api-prod","cve":"CVE-2023-51544","affectedVersions":"<=5.2.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/87ec5542-b6e7-4b18-a3ec-c258e749d32e/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.1.0 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"87ec5542-b6e7-4b18-a3ec-c258e749d32e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/87ec5542-b6e7-4b18-a3ec-c258e749d32e?source=api-prod","cve":"CVE-2023-2499","affectedVersions":"<=5.2.1.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/91a83f52-069e-4611-9b46-4a1913e23f42/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic < 6.0.7.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"91a83f52-069e-4611-9b46-4a1913e23f42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91a83f52-069e-4611-9b46-4a1913e23f42?source=api-prod","cve":"CVE-2026-0929","affectedVersions":"<6.0.7.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9396c350-d72e-472b-8cbc-44edce557256/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.5.9 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"9396c350-d72e-472b-8cbc-44edce557256"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9396c350-d72e-472b-8cbc-44edce557256?source=api-prod","cve":"CVE-2024-29113","affectedVersions":"<=5.2.5.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/9b378df7-b182-4a56-a7fa-3228c06f960f/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic Plugin <= 5.2.4.5 - Authenticated(Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"9b378df7-b182-4a56-a7fa-3228c06f960f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9b378df7-b182-4a56-a7fa-3228c06f960f?source=api-prod","cve":"CVE-2023-50846","affectedVersions":"<5.2.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/9c0c3932-bdb0-4edb-bfec-2ed52cbc5cb6/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"9c0c3932-bdb0-4edb-bfec-2ed52cbc5cb6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9c0c3932-bdb0-4edb-bfec-2ed52cbc5cb6?source=api-prod","cve":"CVE-2025-2836","affectedVersions":"<=6.0.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/a023cdc5-3814-4120-86b2-6a60d385f898/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms and User Login <= 4.6.0.3 - Authenticated Email Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"a023cdc5-3814-4120-86b2-6a60d385f898"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a023cdc5-3814-4120-86b2-6a60d385f898?source=api-prod","cve":"CVE-2020-9455","affectedVersions":"<=4.6.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6da046f-a16f-4a93-b3c6-04270538b7a9/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.3.0.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"b6da046f-a16f-4a93-b3c6-04270538b7a9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6da046f-a16f-4a93-b3c6-04270538b7a9?source=api-prod","cve":"CVE-2024-2951","affectedVersions":"<=5.3.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/bfbc406b-49af-419e-adeb-0510794b7e3f/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.2.0.5 - Authenticated (Admin+) Insecure Direct Object Reference to Arbitrary User Password Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"bfbc406b-49af-419e-adeb-0510794b7e3f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bfbc406b-49af-419e-adeb-0510794b7e3f?source=api-prod","cve":"CVE-2023-2548","affectedVersions":"<=5.2.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/c2b79193-f8fc-4ea2-8973-fe292cfb926b/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic - Custom Registration Forms <= 3.7.9.2 - PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-10-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"c2b79193-f8fc-4ea2-8973-fe292cfb926b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c2b79193-f8fc-4ea2-8973-fe292cfb926b?source=api-prod","cve":"CVE-2017-20208","affectedVersions":"<3.7.9.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/c4679fa7-be6b-4f50-8cdf-ff9822794f19/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"c4679fa7-be6b-4f50-8cdf-ff9822794f19"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c4679fa7-be6b-4f50-8cdf-ff9822794f19?source=api-prod","cve":"CVE-2024-10508","affectedVersions":"<=6.0.2.6","severity":"critical"},{"advisoryId":"WPSECADV/WF/cb269a48-e813-4cda-821a-ee70431372d2/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.2 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"cb269a48-e813-4cda-821a-ee70431372d2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cb269a48-e813-4cda-821a-ee70431372d2?source=api-prod","cve":"CVE-2024-9390","affectedVersions":"<=6.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/d3088e5b-9e3c-4021-b99a-26ac90ece82e/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.6.9 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"d3088e5b-9e3c-4021-b99a-26ac90ece82e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d3088e5b-9e3c-4021-b99a-26ac90ece82e?source=api-prod","cve":"CVE-2026-24374","affectedVersions":"<=6.0.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/d46f8e8a-80cb-4407-ac07-f4c93be691b6/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin <= 4.6.0.1 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-01-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"d46f8e8a-80cb-4407-ac07-f4c93be691b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d46f8e8a-80cb-4407-ac07-f4c93be691b6?source=api-prod","cve":"CVE-2020-8436","affectedVersions":"<=4.6.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/d590e730-ad5f-4046-b897-c3b8aed250b3/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.1 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"d590e730-ad5f-4046-b897-c3b8aed250b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d590e730-ad5f-4046-b897-c3b8aed250b3?source=api-prod","cve":"CVE-2026-24373","affectedVersions":"<=6.0.7.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/d87c4534-3f71-4e7e-bf17-222e77fee24f/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.1 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"d87c4534-3f71-4e7e-bf17-222e77fee24f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d87c4534-3f71-4e7e-bf17-222e77fee24f?source=api-prod","cve":"CVE-2025-15520","affectedVersions":"<=6.0.7.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/d8ba4a74-6649-4566-b9d5-19662539158b/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.0.1.5 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"d8ba4a74-6649-4566-b9d5-19662539158b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d8ba4a74-6649-4566-b9d5-19662539158b?source=api-prod","cve":"CVE-2021-24862","affectedVersions":"<=5.0.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/daf4d246-85f3-48b3-985f-982fea4772f1/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 6.0.7.4 - Missing Authorization to Unauthenticated Arbitrary Settings Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-27 19:10:54","sources":[{"name":"Wordfence","remoteId":"daf4d246-85f3-48b3-985f-982fea4772f1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/daf4d246-85f3-48b3-985f-982fea4772f1?source=api-prod","cve":"CVE-2026-1054","affectedVersions":"<=6.0.7.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/e7939401-822c-4d27-9d8c-c5680165e6a7/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms and User Login <= 4.6.0.3 - Authenticated Settings Import to Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7939401-822c-4d27-9d8c-c5680165e6a7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7939401-822c-4d27-9d8c-c5680165e6a7?source=api-prod","cve":"CVE-2020-9457","affectedVersions":"<=4.6.0.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/f6515d70-438b-47b7-a3c4-5b8dc401a40e/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"f6515d70-438b-47b7-a3c4-5b8dc401a40e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f6515d70-438b-47b7-a3c4-5b8dc401a40e?source=api-prod","cve":"CVE-2026-32498","affectedVersions":"<=6.0.7.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/fbd978fd-f759-4983-90b0-af7338e21d30/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.0.1.7 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-12-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"fbd978fd-f759-4983-90b0-af7338e21d30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fbd978fd-f759-4983-90b0-af7338e21d30?source=api-prod","cve":"CVE-2021-4073","affectedVersions":"<=5.0.1.7","severity":"critical"},{"advisoryId":"WPSECADV/WF/fcfb3a6e-7b58-4568-8439-e9c68a2223b9/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.1.9.2 - Cross-Site Request Forgery leading to Form Metadata Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"fcfb3a6e-7b58-4568-8439-e9c68a2223b9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fcfb3a6e-7b58-4568-8439-e9c68a2223b9?source=api-prod","cve":"CVE-2023-25991","affectedVersions":"<=5.1.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/fd78d162-d9aa-4623-9b89-5f1455739836/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.3.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd78d162-d9aa-4623-9b89-5f1455739836"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd78d162-d9aa-4623-9b89-5f1455739836?source=api-prod","cve":"CVE-2025-24686","affectedVersions":"<=6.0.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/fde0ab44-a354-4cbe-8548-0e5c08529082/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.1.9.2 - Missing Authorization to Unauthenticated Content Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"fde0ab44-a354-4cbe-8548-0e5c08529082"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fde0ab44-a354-4cbe-8548-0e5c08529082?source=api-prod","cve":"CVE-2023-23989","affectedVersions":"<=5.1.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/feeb70e4-b602-40ce-bdeb-d947c6b6784d/custom-registration-form-builder-with-submission-manager","title":"RegistrationMagic <= 5.1.9.2 - Improper Authorization to Price Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"feeb70e4-b602-40ce-bdeb-d947c6b6784d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/feeb70e4-b602-40ce-bdeb-d947c6b6784d?source=api-prod","cve":"CVE-2023-23976","affectedVersions":"<=5.1.9.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_637573746f6d65722d61726561811c9dc5_gen.json b/internal/data/assets/plugin_637573746f6d65722d61726561811c9dc5_gen.json index 290eed7c..0df4ceb1 100644 --- a/internal/data/assets/plugin_637573746f6d65722d61726561811c9dc5_gen.json +++ b/internal/data/assets/plugin_637573746f6d65722d61726561811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/125eb557-0566-48e2-a966-f9255e877e0f/customer-area","title":"WP Customer Area <= 8.2.4 - Cross-Site Request Forgery to Event Log Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"125eb557-0566-48e2-a966-f9255e877e0f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/125eb557-0566-48e2-a966-f9255e877e0f?source=api-prod","cve":"CVE-2024-12280","affectedVersions":"<=8.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/32713069-ea40-46ef-a789-9646eab2e651/customer-area","title":"WP Customer Area <= 8.2.1 - Insecure Direct Object Reference to Address Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"32713069-ea40-46ef-a789-9646eab2e651"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/32713069-ea40-46ef-a789-9646eab2e651?source=api-prod","cve":"CVE-2023-6741","affectedVersions":"<=8.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/33fd9697-803f-4cfb-894b-b3ca6a5ffebf/customer-area","title":"Customer Area <= 8.2.7 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"33fd9697-803f-4cfb-894b-b3ca6a5ffebf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/33fd9697-803f-4cfb-894b-b3ca6a5ffebf?source=api-prod","cve":"CVE-2025-60201","affectedVersions":"<=8.2.7","severity":"high"},{"advisoryId":"WPSECADV/WF/567d62ec-e868-45e2-b07a-8cc661d7c5e1/customer-area","title":"WP Customer Area <= 8.2.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"567d62ec-e868-45e2-b07a-8cc661d7c5e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/567d62ec-e868-45e2-b07a-8cc661d7c5e1?source=api-prod","cve":"CVE-2024-0665","affectedVersions":"<=8.2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/aadf1f4c-c852-4167-9b09-7e679a953725/customer-area","title":"WP Customer Area <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Read/Deletion via ajax_attach_file\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-17 04:24:04","sources":[{"name":"Wordfence","remoteId":"aadf1f4c-c852-4167-9b09-7e679a953725"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aadf1f4c-c852-4167-9b09-7e679a953725?source=api-prod","cve":"CVE-2026-3464","affectedVersions":"<=8.3.4","severity":"high"},{"advisoryId":"WPSECADV/WF/ad5aeea0-ba5a-488a-9087-9b7567f31c70/customer-area","title":"WP Customer Area <= 8.1.3 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad5aeea0-ba5a-488a-9087-9b7567f31c70"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad5aeea0-ba5a-488a-9087-9b7567f31c70?source=api-prod","cve":"CVE-2022-4745","affectedVersions":"<=8.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/cc0087a8-ec3a-4c16-8ce3-d346ae0ca58d/customer-area","title":"WP Customer Area <= 8.2.0 - Insecure Direct Object Reference to Account Address Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"cc0087a8-ec3a-4c16-8ce3-d346ae0ca58d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc0087a8-ec3a-4c16-8ce3-d346ae0ca58d?source=api-prod","cve":"CVE-2023-6824","affectedVersions":"<=8.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/df04f598-941f-4a85-a7e0-948213f6e815/customer-area","title":"WP Customer Area <= 8.2.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"df04f598-941f-4a85-a7e0-948213f6e815"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/df04f598-941f-4a85-a7e0-948213f6e815?source=api-prod","cve":"CVE-2025-49982","affectedVersions":"<=8.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/ec015f49-cdb6-4a08-81cd-6fa505086537/customer-area","title":"WP Customer Area <= 7.4.2 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-11-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"ec015f49-cdb6-4a08-81cd-6fa505086537"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ec015f49-cdb6-4a08-81cd-6fa505086537?source=api-prod","cve":"CVE-2017-18519","affectedVersions":"<7.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/f5cb0b5d-062c-47ac-bcd0-f30f82da6491/customer-area","title":"WP Customer Area <= 8.2.4 - Cross-Site Request Forgery to Bulk Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"f5cb0b5d-062c-47ac-bcd0-f30f82da6491"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5cb0b5d-062c-47ac-bcd0-f30f82da6491?source=api-prod","cve":"CVE-2024-12436","affectedVersions":"<=8.2.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/125eb557-0566-48e2-a966-f9255e877e0f/customer-area","title":"WP Customer Area <= 8.2.4 - Cross-Site Request Forgery to Event Log Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"125eb557-0566-48e2-a966-f9255e877e0f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/125eb557-0566-48e2-a966-f9255e877e0f?source=api-prod","cve":"CVE-2024-12280","affectedVersions":"<=8.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/32713069-ea40-46ef-a789-9646eab2e651/customer-area","title":"WP Customer Area <= 8.2.1 - Insecure Direct Object Reference to Address Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"32713069-ea40-46ef-a789-9646eab2e651"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/32713069-ea40-46ef-a789-9646eab2e651?source=api-prod","cve":"CVE-2023-6741","affectedVersions":"<=8.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/33fd9697-803f-4cfb-894b-b3ca6a5ffebf/customer-area","title":"Customer Area <= 8.2.7 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"33fd9697-803f-4cfb-894b-b3ca6a5ffebf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/33fd9697-803f-4cfb-894b-b3ca6a5ffebf?source=api-prod","cve":"CVE-2025-60201","affectedVersions":"<=8.2.7","severity":"high"},{"advisoryId":"WPSECADV/WF/567d62ec-e868-45e2-b07a-8cc661d7c5e1/customer-area","title":"WP Customer Area <= 8.2.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"567d62ec-e868-45e2-b07a-8cc661d7c5e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/567d62ec-e868-45e2-b07a-8cc661d7c5e1?source=api-prod","cve":"CVE-2024-0665","affectedVersions":"<=8.2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/aadf1f4c-c852-4167-9b09-7e679a953725/customer-area","title":"WP Customer Area <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Read/Deletion via ajax_attach_file\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-17 04:24:04","sources":[{"name":"Wordfence","remoteId":"aadf1f4c-c852-4167-9b09-7e679a953725"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aadf1f4c-c852-4167-9b09-7e679a953725?source=api-prod","cve":"CVE-2026-3464","affectedVersions":"<=8.3.4","severity":"high"},{"advisoryId":"WPSECADV/WF/ad5aeea0-ba5a-488a-9087-9b7567f31c70/customer-area","title":"WP Customer Area <= 8.1.3 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad5aeea0-ba5a-488a-9087-9b7567f31c70"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad5aeea0-ba5a-488a-9087-9b7567f31c70?source=api-prod","cve":"CVE-2022-4745","affectedVersions":"<=8.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/cc0087a8-ec3a-4c16-8ce3-d346ae0ca58d/customer-area","title":"WP Customer Area <= 8.2.0 - Insecure Direct Object Reference to Account Address Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"cc0087a8-ec3a-4c16-8ce3-d346ae0ca58d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc0087a8-ec3a-4c16-8ce3-d346ae0ca58d?source=api-prod","cve":"CVE-2023-6824","affectedVersions":"<=8.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/d731f7bf-d2de-4f5f-8c4a-627713bec348/customer-area","title":"WP Customer Area <= 8.3.4 - Authenticated (Custom+) Path Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"d731f7bf-d2de-4f5f-8c4a-627713bec348"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d731f7bf-d2de-4f5f-8c4a-627713bec348?source=api-prod","cve":"CVE-2026-42661","affectedVersions":"<=8.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/df04f598-941f-4a85-a7e0-948213f6e815/customer-area","title":"WP Customer Area <= 8.2.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"df04f598-941f-4a85-a7e0-948213f6e815"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/df04f598-941f-4a85-a7e0-948213f6e815?source=api-prod","cve":"CVE-2025-49982","affectedVersions":"<=8.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/ec015f49-cdb6-4a08-81cd-6fa505086537/customer-area","title":"WP Customer Area <= 7.4.2 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-11-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"ec015f49-cdb6-4a08-81cd-6fa505086537"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ec015f49-cdb6-4a08-81cd-6fa505086537?source=api-prod","cve":"CVE-2017-18519","affectedVersions":"<7.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/f5cb0b5d-062c-47ac-bcd0-f30f82da6491/customer-area","title":"WP Customer Area <= 8.2.4 - Cross-Site Request Forgery to Bulk Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"f5cb0b5d-062c-47ac-bcd0-f30f82da6491"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5cb0b5d-062c-47ac-bcd0-f30f82da6491?source=api-prod","cve":"CVE-2024-12436","affectedVersions":"<=8.2.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_64656275672d746f6f6c811c9dc5_gen.json b/internal/data/assets/plugin_64656275672d746f6f6c811c9dc5_gen.json index 48dabaa7..f5822c83 100644 --- a/internal/data/assets/plugin_64656275672d746f6f6c811c9dc5_gen.json +++ b/internal/data/assets/plugin_64656275672d746f6f6c811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/1b01991c-de16-43c4-bb11-c8730230ce51/debug-tool","title":"Debug Tool <= 2.2 - Missing Authorization to Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-08 14:06:33","sources":[{"name":"Wordfence","remoteId":"1b01991c-de16-43c4-bb11-c8730230ce51"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b01991c-de16-43c4-bb11-c8730230ce51?source=api-prod","cve":"CVE-2024-10588","affectedVersions":"<=2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/5e9d5c93-dcd7-450e-8c52-5c95fc5473d2/debug-tool","title":"Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-08 14:06:42","sources":[{"name":"Wordfence","remoteId":"5e9d5c93-dcd7-450e-8c52-5c95fc5473d2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5e9d5c93-dcd7-450e-8c52-5c95fc5473d2?source=api-prod","cve":"CVE-2024-10586","affectedVersions":"<=2.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/a73c2502-2bac-47b0-baf4-645314b2048b/debug-tool","title":"Debug Tool <= 2.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"a73c2502-2bac-47b0-baf4-645314b2048b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a73c2502-2bac-47b0-baf4-645314b2048b?source=api-prod","cve":"CVE-2025-23684","affectedVersions":"<=2.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/1b01991c-de16-43c4-bb11-c8730230ce51/debug-tool","title":"Debug Tool <= 2.2 - Missing Authorization to Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-08 14:06:33","sources":[{"name":"Wordfence","remoteId":"1b01991c-de16-43c4-bb11-c8730230ce51"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b01991c-de16-43c4-bb11-c8730230ce51?source=api-prod","cve":"CVE-2024-10588","affectedVersions":"<=2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/5e9d5c93-dcd7-450e-8c52-5c95fc5473d2/debug-tool","title":"Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-08 14:06:42","sources":[{"name":"Wordfence","remoteId":"5e9d5c93-dcd7-450e-8c52-5c95fc5473d2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5e9d5c93-dcd7-450e-8c52-5c95fc5473d2?source=api-prod","cve":"CVE-2024-10586","affectedVersions":"<=2.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/7e96c65d-be0f-4333-90d2-e1cc792f54b2/debug-tool","title":"Debug Tool <= 2.2 - Unauthenticated Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"7e96c65d-be0f-4333-90d2-e1cc792f54b2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7e96c65d-be0f-4333-90d2-e1cc792f54b2?source=api-prod","cve":"CVE-2024-52416","affectedVersions":"<=2.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/a73c2502-2bac-47b0-baf4-645314b2048b/debug-tool","title":"Debug Tool <= 2.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"a73c2502-2bac-47b0-baf4-645314b2048b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a73c2502-2bac-47b0-baf4-645314b2048b?source=api-prod","cve":"CVE-2025-23684","affectedVersions":"<=2.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6469726563746f72797072657373811c9dc5_gen.json b/internal/data/assets/plugin_6469726563746f72797072657373811c9dc5_gen.json index 29155385..23f6b4d3 100644 --- a/internal/data/assets/plugin_6469726563746f72797072657373811c9dc5_gen.json +++ b/internal/data/assets/plugin_6469726563746f72797072657373811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/14acb770-9a32-4308-993d-a3d3dec91f78/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.7 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"14acb770-9a32-4308-993d-a3d3dec91f78"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/14acb770-9a32-4308-993d-a3d3dec91f78?source=api-prod","cve":"CVE-2024-32567","affectedVersions":"<=3.6.7","severity":"high"},{"advisoryId":"WPSECADV/WF/2e602223-8571-42e1-9b3f-e7cc51f8fa58/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.26 - Unauthenticated SQL Injection via 'packages'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-15 21:35:44","sources":[{"name":"Wordfence","remoteId":"2e602223-8571-42e1-9b3f-e7cc51f8fa58"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2e602223-8571-42e1-9b3f-e7cc51f8fa58?source=api-prod","cve":"CVE-2026-3489","affectedVersions":"<=3.6.26","severity":"high"},{"advisoryId":"WPSECADV/WF/4625072b-815d-41d2-bf8f-ac290efde369/directorypress","title":"DirectoryPress <= 3.6.16 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"4625072b-815d-41d2-bf8f-ac290efde369"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4625072b-815d-41d2-bf8f-ac290efde369?source=api-prod","cve":"CVE-2024-10584","affectedVersions":"<=3.6.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd/directorypress","title":"DirectoryPress <= 3.6.10 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd?source=api-prod","cve":"CVE-2024-38755","affectedVersions":"<=3.6.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/86b0558b-74ed-4ddd-9b18-e7795cefc00e/directorypress","title":"DirectoryPress <= 3.6.19 - Cross-Site Request Forgery to Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"86b0558b-74ed-4ddd-9b18-e7795cefc00e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/86b0558b-74ed-4ddd-9b18-e7795cefc00e?source=api-prod","cve":"CVE-2024-49633","affectedVersions":"<=3.6.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/8875d2d5-1de0-4a8c-8acb-69c8095effe5/directorypress","title":"DirectoryPress <= 3.6.25 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"8875d2d5-1de0-4a8c-8acb-69c8095effe5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8875d2d5-1de0-4a8c-8acb-69c8095effe5?source=api-prod","cve":"CVE-2025-62967","affectedVersions":"<=3.6.25","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6bd6979-858a-446b-a8d9-d30869e73ed5/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.26 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"b6bd6979-858a-446b-a8d9-d30869e73ed5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6bd6979-858a-446b-a8d9-d30869e73ed5?source=api-prod","cve":"CVE-2026-27387","affectedVersions":"<=3.6.26","severity":"medium"},{"advisoryId":"WPSECADV/WF/f75f83bf-3c86-44e9-b535-cd721061ee93/directorypress","title":"DirectoryPress <= 3.6.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"f75f83bf-3c86-44e9-b535-cd721061ee93"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f75f83bf-3c86-44e9-b535-cd721061ee93?source=api-prod","cve":"CVE-2023-37967","affectedVersions":"<=3.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/fa32f55a-f9e4-4129-add0-39d9e4eb1bee/directorypress","title":"DirectoryPress <= 3.6.22 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"fa32f55a-f9e4-4129-add0-39d9e4eb1bee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fa32f55a-f9e4-4129-add0-39d9e4eb1bee?source=api-prod","cve":"CVE-2025-32249","affectedVersions":"<=3.6.22","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/14acb770-9a32-4308-993d-a3d3dec91f78/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.7 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"14acb770-9a32-4308-993d-a3d3dec91f78"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/14acb770-9a32-4308-993d-a3d3dec91f78?source=api-prod","cve":"CVE-2024-32567","affectedVersions":"<=3.6.7","severity":"high"},{"advisoryId":"WPSECADV/WF/2e602223-8571-42e1-9b3f-e7cc51f8fa58/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.26 - Unauthenticated SQL Injection via 'packages'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-15 21:35:44","sources":[{"name":"Wordfence","remoteId":"2e602223-8571-42e1-9b3f-e7cc51f8fa58"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2e602223-8571-42e1-9b3f-e7cc51f8fa58?source=api-prod","cve":"CVE-2026-3489","affectedVersions":"<=3.6.26","severity":"high"},{"advisoryId":"WPSECADV/WF/4625072b-815d-41d2-bf8f-ac290efde369/directorypress","title":"DirectoryPress <= 3.6.16 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"4625072b-815d-41d2-bf8f-ac290efde369"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4625072b-815d-41d2-bf8f-ac290efde369?source=api-prod","cve":"CVE-2024-10584","affectedVersions":"<=3.6.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd/directorypress","title":"DirectoryPress <= 3.6.10 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd?source=api-prod","cve":"CVE-2024-38755","affectedVersions":"<=3.6.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/86b0558b-74ed-4ddd-9b18-e7795cefc00e/directorypress","title":"DirectoryPress <= 3.6.19 - Cross-Site Request Forgery to Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"86b0558b-74ed-4ddd-9b18-e7795cefc00e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/86b0558b-74ed-4ddd-9b18-e7795cefc00e?source=api-prod","cve":"CVE-2024-49633","affectedVersions":"<=3.6.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/8875d2d5-1de0-4a8c-8acb-69c8095effe5/directorypress","title":"DirectoryPress <= 3.6.25 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"8875d2d5-1de0-4a8c-8acb-69c8095effe5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8875d2d5-1de0-4a8c-8acb-69c8095effe5?source=api-prod","cve":"CVE-2025-62967","affectedVersions":"<=3.6.25","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6bd6979-858a-446b-a8d9-d30869e73ed5/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.26 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"b6bd6979-858a-446b-a8d9-d30869e73ed5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6bd6979-858a-446b-a8d9-d30869e73ed5?source=api-prod","cve":"CVE-2026-27387","affectedVersions":"<=3.6.26","severity":"medium"},{"advisoryId":"WPSECADV/WF/dc9602fb-59d0-43bb-aa13-adfc2319db8e/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.25 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"dc9602fb-59d0-43bb-aa13-adfc2319db8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dc9602fb-59d0-43bb-aa13-adfc2319db8e?source=api-prod","cve":"CVE-2026-23548","affectedVersions":"<=3.6.25","severity":"medium"},{"advisoryId":"WPSECADV/WF/f75f83bf-3c86-44e9-b535-cd721061ee93/directorypress","title":"DirectoryPress <= 3.6.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"f75f83bf-3c86-44e9-b535-cd721061ee93"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f75f83bf-3c86-44e9-b535-cd721061ee93?source=api-prod","cve":"CVE-2023-37967","affectedVersions":"<=3.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/fa32f55a-f9e4-4129-add0-39d9e4eb1bee/directorypress","title":"DirectoryPress <= 3.6.22 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"fa32f55a-f9e4-4129-add0-39d9e4eb1bee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fa32f55a-f9e4-4129-add0-39d9e4eb1bee?source=api-prod","cve":"CVE-2025-32249","affectedVersions":"<=3.6.22","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_647261672d616e642d64726f702d66696c652d75706c6f61642d77632d70726f811c9dc5_gen.json b/internal/data/assets/plugin_647261672d616e642d64726f702d66696c652d75706c6f61642d77632d70726f811c9dc5_gen.json new file mode 100644 index 00000000..a6e4d4bc --- /dev/null +++ b/internal/data/assets/plugin_647261672d616e642d64726f702d66696c652d75706c6f61642d77632d70726f811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/24c9a333-e60e-481b-ba27-65094f4f8d39/drag-and-drop-file-upload-wc-pro","title":"Drag and Drop Multiple File Upload (Pro) - WooCommerce <= 5.0.6 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"24c9a333-e60e-481b-ba27-65094f4f8d39"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/24c9a333-e60e-481b-ba27-65094f4f8d39?source=api-prod","cve":"CVE-2025-49885","affectedVersions":"<=5.0.6","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_64782d736f7572636573811c9dc5_gen.json b/internal/data/assets/plugin_64782d736f7572636573811c9dc5_gen.json new file mode 100644 index 00000000..59aa8d04 --- /dev/null +++ b/internal/data/assets/plugin_64782d736f7572636573811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/b3c96e57-0300-4ea7-a0c6-5d060b6e979d/dx-sources","title":"DX Sources <= 2.0.1 - Cross-Site Request Forgery to Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:06:52","sources":[{"name":"Wordfence","remoteId":"b3c96e57-0300-4ea7-a0c6-5d060b6e979d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b3c96e57-0300-4ea7-a0c6-5d060b6e979d?source=api-prod","cve":"CVE-2026-6700","affectedVersions":"<=2.0.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6563686f2d6b6e6f776c656467652d62617365811c9dc5_gen.json b/internal/data/assets/plugin_6563686f2d6b6e6f776c656467652d62617365811c9dc5_gen.json index 58614bda..5efd95e2 100644 --- a/internal/data/assets/plugin_6563686f2d6b6e6f776c656467652d62617365811c9dc5_gen.json +++ b/internal/data/assets/plugin_6563686f2d6b6e6f776c656467652d62617365811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/41cfe1d7-2fab-413c-80e5-40d77133d229/echo-knowledge-base","title":"Knowledge Base for Documentation, FAQs with AI Assistance <= 11.30.2 - Unauthenticated PHP Object Injection in is_article_recently_viewed\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"41cfe1d7-2fab-413c-80e5-40d77133d229"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/41cfe1d7-2fab-413c-80e5-40d77133d229?source=api-prod","cve":"CVE-2024-24842","affectedVersions":"<=11.30.2","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/41cfe1d7-2fab-413c-80e5-40d77133d229/echo-knowledge-base","title":"Knowledge Base for Documentation, FAQs with AI Assistance <= 11.30.2 - Unauthenticated PHP Object Injection in is_article_recently_viewed\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"41cfe1d7-2fab-413c-80e5-40d77133d229"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/41cfe1d7-2fab-413c-80e5-40d77133d229?source=api-prod","cve":"CVE-2024-24842","affectedVersions":"<=11.30.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/b4bfd3d4-8454-4db2-b6fc-570bc7f99f36/echo-knowledge-base","title":"Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search <= 16.011.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"b4bfd3d4-8454-4db2-b6fc-570bc7f99f36"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b4bfd3d4-8454-4db2-b6fc-570bc7f99f36?source=api-prod","cve":"CVE-2026-25402","affectedVersions":"<=16.011.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_656c656d656e74736b69742d6c697465811c9dc5_gen.json b/internal/data/assets/plugin_656c656d656e74736b69742d6c697465811c9dc5_gen.json index 5634b1f9..8767dd10 100644 --- a/internal/data/assets/plugin_656c656d656e74736b69742d6c697465811c9dc5_gen.json +++ b/internal/data/assets/plugin_656c656d656e74736b69742d6c697465811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/00b278af-6ce6-4e70-a83a-a1b035542cd4/elementskit-lite","title":"ElementsKit Elementor addons <= 3.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-25 14:08:18","sources":[{"name":"Wordfence","remoteId":"00b278af-6ce6-4e70-a83a-a1b035542cd4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00b278af-6ce6-4e70-a83a-a1b035542cd4?source=api-prod","cve":"CVE-2024-10091","affectedVersions":"<=3.2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/1627e235-7836-43dc-a3f6-7f79da6ab229/elementskit-lite","title":"ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-24 09:38:18","sources":[{"name":"Wordfence","remoteId":"1627e235-7836-43dc-a3f6-7f79da6ab229"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1627e235-7836-43dc-a3f6-7f79da6ab229?source=api-prod","cve":"CVE-2025-3614","affectedVersions":"<=3.5.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/1822fd58-0dba-4b15-9702-32e3aa4405b3/elementskit-lite","title":"ElementsKit Elementor addons <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"1822fd58-0dba-4b15-9702-32e3aa4405b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1822fd58-0dba-4b15-9702-32e3aa4405b3?source=api-prod","cve":"CVE-2024-1239","affectedVersions":"<=3.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/35969379-e668-4045-8de7-696f196ba5b0/elementskit-lite","title":"ElementsKit Elementor addons <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"35969379-e668-4045-8de7-696f196ba5b0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/35969379-e668-4045-8de7-696f196ba5b0?source=api-prod","cve":"CVE-2024-11180","affectedVersions":"<=3.4.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/413e6326-14c6-4734-8adc-114a7842c574/elementskit-lite","title":"ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Local File Inclusion in render_raw\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"413e6326-14c6-4734-8adc-114a7842c574"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/413e6326-14c6-4734-8adc-114a7842c574?source=api-prod","cve":"CVE-2024-2047","affectedVersions":"<=3.0.6","severity":"high"},{"advisoryId":"WPSECADV/WF/432ac3b1-8f1d-442f-8e8d-62a1f26ba259/elementskit-lite","title":"ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-18 22:37:28","sources":[{"name":"Wordfence","remoteId":"432ac3b1-8f1d-442f-8e8d-62a1f26ba259"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/432ac3b1-8f1d-442f-8e8d-62a1f26ba259?source=api-prod","cve":"CVE-2025-0968","affectedVersions":"<=3.4.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/4c33c640-0876-4b07-829e-35cae445b420/elementskit-lite","title":"ElementsKit Elementor Addons and Templates <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Simple Tab Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-03 19:37:48","sources":[{"name":"Wordfence","remoteId":"4c33c640-0876-4b07-829e-35cae445b420"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4c33c640-0876-4b07-829e-35cae445b420?source=api-prod","cve":"CVE-2026-2600","affectedVersions":"<=3.7.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/5b74d6aa-ad59-42be-b454-9c27428cab01/elementskit-lite","title":"ElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-14 21:06:53","sources":[{"name":"Wordfence","remoteId":"5b74d6aa-ad59-42be-b454-9c27428cab01"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5b74d6aa-ad59-42be-b454-9c27428cab01?source=api-prod","cve":"CVE-2025-1005","affectedVersions":"<=3.4.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/5ff589ec-756d-4183-8bb8-61dae9be7c5d/elementskit-lite","title":"Elements kit Elementor addons <= 2.9.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5ff589ec-756d-4183-8bb8-61dae9be7c5d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ff589ec-756d-4183-8bb8-61dae9be7c5d?source=api-prod","cve":"CVE-2023-39993","affectedVersions":"<=2.9.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/6158ec37-a6fb-42f9-bab6-bf547ea28ea0/elementskit-lite","title":"ElementsKit Elementor addons <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"6158ec37-a6fb-42f9-bab6-bf547ea28ea0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6158ec37-a6fb-42f9-bab6-bf547ea28ea0?source=api-prod","cve":"CVE-2024-3499","affectedVersions":"<=3.1.0","severity":"high"},{"advisoryId":"WPSECADV/WF/75d5366e-2908-4b8d-9ee2-1f11e483add1/elementskit-lite","title":"Elements Kit Lite/Pro <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-04-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"75d5366e-2908-4b8d-9ee2-1f11e483add1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/75d5366e-2908-4b8d-9ee2-1f11e483add1?source=api-prod","cve":"CVE-2021-24258","affectedVersions":"<=2.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/7c336530-09b2-4ead-923f-f1a6266e3e8e/elementskit-lite","title":"ElementsKit Elementor addons <= 3.2.0 - Unauthenticated Information Exposure via ekit_widgetarea_content Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-18 08:02:02","sources":[{"name":"Wordfence","remoteId":"7c336530-09b2-4ead-923f-f1a6266e3e8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c336530-09b2-4ead-923f-f1a6266e3e8e?source=api-prod","cve":"CVE-2024-6455","affectedVersions":"<=3.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/85025fb9-6e19-4c0f-bf16-4b890ba5f7f5/elementskit-lite","title":"ElementsKit Elementor addons Lite < 3.7.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"85025fb9-6e19-4c0f-bf16-4b890ba5f7f5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/85025fb9-6e19-4c0f-bf16-4b890ba5f7f5?source=api-prod","cve":"CVE-2026-23693","affectedVersions":"<3.7.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/93dcbab7-fdf5-4631-8605-77f8f190512d/elementskit-lite","title":"ElementsKit Elementor addons 3.0.7 - 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"93dcbab7-fdf5-4631-8605-77f8f190512d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/93dcbab7-fdf5-4631-8605-77f8f190512d?source=api-prod","cve":"CVE-2024-3650","affectedVersions":">=3.0.7,<=3.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/a1cf8b8f-bf74-444c-88cc-cc836ee45f26/elementskit-lite","title":"Elements kit Elementor addons <= 3.1.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"a1cf8b8f-bf74-444c-88cc-cc836ee45f26"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a1cf8b8f-bf74-444c-88cc-cc836ee45f26?source=api-prod","cve":"CVE-2024-37255","affectedVersions":"<=3.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/b1c44ad9-e61e-4f29-9c0b-7c0a89b0c8da/elementskit-lite","title":"ElementsKit Elementor addons <= 3.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"b1c44ad9-e61e-4f29-9c0b-7c0a89b0c8da"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b1c44ad9-e61e-4f29-9c0b-7c0a89b0c8da?source=api-prod","cve":"CVE-2024-2803","affectedVersions":"<=3.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/b3ae99bb-03c3-4869-9314-0dbd76ca25c0/elementskit-lite","title":"ElementsKit Elementor addons Lite <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"b3ae99bb-03c3-4869-9314-0dbd76ca25c0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b3ae99bb-03c3-4869-9314-0dbd76ca25c0?source=api-prod","cve":"CVE-2024-32505","affectedVersions":"<=3.0.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/be4ce3e6-8baa-419f-a48e-4256c306fbc1/elementskit-lite","title":"ElementsKit Elementor addons <= 3.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"be4ce3e6-8baa-419f-a48e-4256c306fbc1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be4ce3e6-8baa-419f-a48e-4256c306fbc1?source=api-prod","cve":"CVE-2024-2042","affectedVersions":"<=3.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/c2995828-8a3e-400d-9e2b-aba8fd17cf00/elementskit-lite","title":"ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-18 15:03:12","sources":[{"name":"Wordfence","remoteId":"c2995828-8a3e-400d-9e2b-aba8fd17cf00"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c2995828-8a3e-400d-9e2b-aba8fd17cf00?source=api-prod","cve":"CVE-2025-4479","affectedVersions":"<=3.5.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/cf195cca-4e07-41ff-bf26-9ad5fca3635d/elementskit-lite","title":"ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"cf195cca-4e07-41ff-bf26-9ad5fca3635d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cf195cca-4e07-41ff-bf26-9ad5fca3635d?source=api-prod","cve":"CVE-2024-1238","affectedVersions":"<=3.0.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/d21aeeb6-2e7d-426e-82c5-ff65e33bc5cb/elementskit-lite","title":"ElementsKit Elementor addons <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-24 23:43:47","sources":[{"name":"Wordfence","remoteId":"d21aeeb6-2e7d-426e-82c5-ff65e33bc5cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d21aeeb6-2e7d-426e-82c5-ff65e33bc5cb?source=api-prod","cve":"CVE-2024-8546","affectedVersions":"<=3.2.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/e724394d-97aa-42e4-b36e-6e49bfefa2f6/elementskit-lite","title":"ElementsKit Elementor addons <= 3.0.3 - Authenticated(Editor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"e724394d-97aa-42e4-b36e-6e49bfefa2f6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e724394d-97aa-42e4-b36e-6e49bfefa2f6?source=api-prod","cve":"CVE-2023-6525","affectedVersions":"<=3.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/ff4ae5c8-d164-4c2f-9bf3-83934c22cf4c/elementskit-lite","title":"ElementsKit Lite <= 3.0.3 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"ff4ae5c8-d164-4c2f-9bf3-83934c22cf4c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ff4ae5c8-d164-4c2f-9bf3-83934c22cf4c?source=api-prod","cve":"CVE-2023-6582","affectedVersions":"<=3.0.3","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/00b278af-6ce6-4e70-a83a-a1b035542cd4/elementskit-lite","title":"ElementsKit Elementor addons <= 3.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-25 14:08:18","sources":[{"name":"Wordfence","remoteId":"00b278af-6ce6-4e70-a83a-a1b035542cd4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00b278af-6ce6-4e70-a83a-a1b035542cd4?source=api-prod","cve":"CVE-2024-10091","affectedVersions":"<=3.2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/1627e235-7836-43dc-a3f6-7f79da6ab229/elementskit-lite","title":"ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-24 09:38:18","sources":[{"name":"Wordfence","remoteId":"1627e235-7836-43dc-a3f6-7f79da6ab229"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1627e235-7836-43dc-a3f6-7f79da6ab229?source=api-prod","cve":"CVE-2025-3614","affectedVersions":"<=3.5.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/1822fd58-0dba-4b15-9702-32e3aa4405b3/elementskit-lite","title":"ElementsKit Elementor addons <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"1822fd58-0dba-4b15-9702-32e3aa4405b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1822fd58-0dba-4b15-9702-32e3aa4405b3?source=api-prod","cve":"CVE-2024-1239","affectedVersions":"<=3.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/35969379-e668-4045-8de7-696f196ba5b0/elementskit-lite","title":"ElementsKit Elementor addons <= 3.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"35969379-e668-4045-8de7-696f196ba5b0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/35969379-e668-4045-8de7-696f196ba5b0?source=api-prod","cve":"CVE-2024-11180","affectedVersions":"<=3.4.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/413e6326-14c6-4734-8adc-114a7842c574/elementskit-lite","title":"ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Local File Inclusion in render_raw\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"413e6326-14c6-4734-8adc-114a7842c574"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/413e6326-14c6-4734-8adc-114a7842c574?source=api-prod","cve":"CVE-2024-2047","affectedVersions":"<=3.0.6","severity":"high"},{"advisoryId":"WPSECADV/WF/432ac3b1-8f1d-442f-8e8d-62a1f26ba259/elementskit-lite","title":"ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-18 22:37:28","sources":[{"name":"Wordfence","remoteId":"432ac3b1-8f1d-442f-8e8d-62a1f26ba259"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/432ac3b1-8f1d-442f-8e8d-62a1f26ba259?source=api-prod","cve":"CVE-2025-0968","affectedVersions":"<=3.4.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/4c33c640-0876-4b07-829e-35cae445b420/elementskit-lite","title":"ElementsKit Elementor Addons and Templates <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Simple Tab Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-03 19:37:48","sources":[{"name":"Wordfence","remoteId":"4c33c640-0876-4b07-829e-35cae445b420"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4c33c640-0876-4b07-829e-35cae445b420?source=api-prod","cve":"CVE-2026-2600","affectedVersions":"<=3.7.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/5b74d6aa-ad59-42be-b454-9c27428cab01/elementskit-lite","title":"ElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-14 21:06:53","sources":[{"name":"Wordfence","remoteId":"5b74d6aa-ad59-42be-b454-9c27428cab01"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5b74d6aa-ad59-42be-b454-9c27428cab01?source=api-prod","cve":"CVE-2025-1005","affectedVersions":"<=3.4.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/5ff589ec-756d-4183-8bb8-61dae9be7c5d/elementskit-lite","title":"Elements kit Elementor addons <= 2.9.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5ff589ec-756d-4183-8bb8-61dae9be7c5d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ff589ec-756d-4183-8bb8-61dae9be7c5d?source=api-prod","cve":"CVE-2023-39993","affectedVersions":"<=2.9.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/6158ec37-a6fb-42f9-bab6-bf547ea28ea0/elementskit-lite","title":"ElementsKit Elementor addons <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"6158ec37-a6fb-42f9-bab6-bf547ea28ea0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6158ec37-a6fb-42f9-bab6-bf547ea28ea0?source=api-prod","cve":"CVE-2024-3499","affectedVersions":"<=3.1.0","severity":"high"},{"advisoryId":"WPSECADV/WF/75d5366e-2908-4b8d-9ee2-1f11e483add1/elementskit-lite","title":"Elements Kit Lite/Pro <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-04-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"75d5366e-2908-4b8d-9ee2-1f11e483add1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/75d5366e-2908-4b8d-9ee2-1f11e483add1?source=api-prod","cve":"CVE-2021-24258","affectedVersions":"<=2.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/7740fdfb-65b2-4d27-935f-b0e73487f0c4/elementskit-lite","title":"ElementsKit Elementor Addons <= 3.8.2 - Missing Authorization to Unauthenticated Widget Content Overwrite\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 16:06:48","sources":[{"name":"Wordfence","remoteId":"7740fdfb-65b2-4d27-935f-b0e73487f0c4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7740fdfb-65b2-4d27-935f-b0e73487f0c4?source=api-prod","cve":"CVE-2026-4362","affectedVersions":"<=3.8.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/7c336530-09b2-4ead-923f-f1a6266e3e8e/elementskit-lite","title":"ElementsKit Elementor addons <= 3.2.0 - Unauthenticated Information Exposure via ekit_widgetarea_content Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-18 08:02:02","sources":[{"name":"Wordfence","remoteId":"7c336530-09b2-4ead-923f-f1a6266e3e8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c336530-09b2-4ead-923f-f1a6266e3e8e?source=api-prod","cve":"CVE-2024-6455","affectedVersions":"<=3.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/85025fb9-6e19-4c0f-bf16-4b890ba5f7f5/elementskit-lite","title":"ElementsKit Elementor addons Lite < 3.7.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"85025fb9-6e19-4c0f-bf16-4b890ba5f7f5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/85025fb9-6e19-4c0f-bf16-4b890ba5f7f5?source=api-prod","cve":"CVE-2026-23693","affectedVersions":"<3.7.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/93dcbab7-fdf5-4631-8605-77f8f190512d/elementskit-lite","title":"ElementsKit Elementor addons 3.0.7 - 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"93dcbab7-fdf5-4631-8605-77f8f190512d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/93dcbab7-fdf5-4631-8605-77f8f190512d?source=api-prod","cve":"CVE-2024-3650","affectedVersions":">=3.0.7,<=3.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/a1cf8b8f-bf74-444c-88cc-cc836ee45f26/elementskit-lite","title":"Elements kit Elementor addons <= 3.1.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"a1cf8b8f-bf74-444c-88cc-cc836ee45f26"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a1cf8b8f-bf74-444c-88cc-cc836ee45f26?source=api-prod","cve":"CVE-2024-37255","affectedVersions":"<=3.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/b1c44ad9-e61e-4f29-9c0b-7c0a89b0c8da/elementskit-lite","title":"ElementsKit Elementor addons <= 3.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"b1c44ad9-e61e-4f29-9c0b-7c0a89b0c8da"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b1c44ad9-e61e-4f29-9c0b-7c0a89b0c8da?source=api-prod","cve":"CVE-2024-2803","affectedVersions":"<=3.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/b3ae99bb-03c3-4869-9314-0dbd76ca25c0/elementskit-lite","title":"ElementsKit Elementor addons Lite <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"b3ae99bb-03c3-4869-9314-0dbd76ca25c0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b3ae99bb-03c3-4869-9314-0dbd76ca25c0?source=api-prod","cve":"CVE-2024-32505","affectedVersions":"<=3.0.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/be4ce3e6-8baa-419f-a48e-4256c306fbc1/elementskit-lite","title":"ElementsKit Elementor addons <= 3.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"be4ce3e6-8baa-419f-a48e-4256c306fbc1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be4ce3e6-8baa-419f-a48e-4256c306fbc1?source=api-prod","cve":"CVE-2024-2042","affectedVersions":"<=3.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/c2995828-8a3e-400d-9e2b-aba8fd17cf00/elementskit-lite","title":"ElementsKit Lite <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-18 15:03:12","sources":[{"name":"Wordfence","remoteId":"c2995828-8a3e-400d-9e2b-aba8fd17cf00"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c2995828-8a3e-400d-9e2b-aba8fd17cf00?source=api-prod","cve":"CVE-2025-4479","affectedVersions":"<=3.5.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/cf195cca-4e07-41ff-bf26-9ad5fca3635d/elementskit-lite","title":"ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"cf195cca-4e07-41ff-bf26-9ad5fca3635d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cf195cca-4e07-41ff-bf26-9ad5fca3635d?source=api-prod","cve":"CVE-2024-1238","affectedVersions":"<=3.0.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/d21aeeb6-2e7d-426e-82c5-ff65e33bc5cb/elementskit-lite","title":"ElementsKit Elementor addons <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-24 23:43:47","sources":[{"name":"Wordfence","remoteId":"d21aeeb6-2e7d-426e-82c5-ff65e33bc5cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d21aeeb6-2e7d-426e-82c5-ff65e33bc5cb?source=api-prod","cve":"CVE-2024-8546","affectedVersions":"<=3.2.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/e724394d-97aa-42e4-b36e-6e49bfefa2f6/elementskit-lite","title":"ElementsKit Elementor addons <= 3.0.3 - Authenticated(Editor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"e724394d-97aa-42e4-b36e-6e49bfefa2f6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e724394d-97aa-42e4-b36e-6e49bfefa2f6?source=api-prod","cve":"CVE-2023-6525","affectedVersions":"<=3.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/ff4ae5c8-d164-4c2f-9bf3-83934c22cf4c/elementskit-lite","title":"ElementsKit Lite <= 3.0.3 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"ff4ae5c8-d164-4c2f-9bf3-83934c22cf4c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ff4ae5c8-d164-4c2f-9bf3-83934c22cf4c?source=api-prod","cve":"CVE-2023-6582","affectedVersions":"<=3.0.3","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_656d61696c6b6974811c9dc5_gen.json b/internal/data/assets/plugin_656d61696c6b6974811c9dc5_gen.json index 2900fc28..615853de 100644 --- a/internal/data/assets/plugin_656d61696c6b6974811c9dc5_gen.json +++ b/internal/data/assets/plugin_656d61696c6b6974811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/33fdd325-2a9e-4049-a2b0-c3eddc773c96/emailkit","title":"EmailKit <= 1.6.0 - Missing Authorization to Authenticated (Author+) Arbitrary Content Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"33fdd325-2a9e-4049-a2b0-c3eddc773c96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/33fdd325-2a9e-4049-a2b0-c3eddc773c96?source=api-prod","cve":"CVE-2025-60106","affectedVersions":"<=1.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/91ebe8cb-99ec-4380-a77e-17e17144a17e/emailkit","title":"EmailKit <= 1.6.1 - Authenticated (Author+) Arbitrary File Read via Path Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 14:21:45","sources":[{"name":"Wordfence","remoteId":"91ebe8cb-99ec-4380-a77e-17e17144a17e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91ebe8cb-99ec-4380-a77e-17e17144a17e?source=api-prod","cve":"CVE-2025-14059","affectedVersions":"<=1.6.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/d8c11ebc-5c83-46a2-a8dd-b838cd50ddc6/emailkit","title":"EmailKit <= 1.6.3 - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 11:00:41","sources":[{"name":"Wordfence","remoteId":"d8c11ebc-5c83-46a2-a8dd-b838cd50ddc6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d8c11ebc-5c83-46a2-a8dd-b838cd50ddc6?source=api-prod","cve":"CVE-2026-3474","affectedVersions":"<=1.6.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/f131ea1e-d652-4854-abea-6a307ca8118f/emailkit","title":"EmailKit – Email Customizer for WooCommerce & WP <= 1.6.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Title Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 16:26:56","sources":[{"name":"Wordfence","remoteId":"f131ea1e-d652-4854-abea-6a307ca8118f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f131ea1e-d652-4854-abea-6a307ca8118f?source=api-prod","cve":"CVE-2026-1925","affectedVersions":"<=1.6.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/33fdd325-2a9e-4049-a2b0-c3eddc773c96/emailkit","title":"EmailKit <= 1.6.0 - Missing Authorization to Authenticated (Author+) Arbitrary Content Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"33fdd325-2a9e-4049-a2b0-c3eddc773c96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/33fdd325-2a9e-4049-a2b0-c3eddc773c96?source=api-prod","cve":"CVE-2025-60106","affectedVersions":"<=1.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/91ebe8cb-99ec-4380-a77e-17e17144a17e/emailkit","title":"EmailKit <= 1.6.1 - Authenticated (Author+) Arbitrary File Read via Path Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 14:21:45","sources":[{"name":"Wordfence","remoteId":"91ebe8cb-99ec-4380-a77e-17e17144a17e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91ebe8cb-99ec-4380-a77e-17e17144a17e?source=api-prod","cve":"CVE-2025-14059","affectedVersions":"<=1.6.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/ae58e5b0-b587-4503-8519-c5a50245891a/emailkit","title":"EmailKit <= 1.6.5 - Authenticated (Author+) Arbitrary File Read via 'emailkit-editor-template' REST Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:47:21","sources":[{"name":"Wordfence","remoteId":"ae58e5b0-b587-4503-8519-c5a50245891a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ae58e5b0-b587-4503-8519-c5a50245891a?source=api-prod","cve":"CVE-2026-5957","affectedVersions":"<=1.6.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/d8c11ebc-5c83-46a2-a8dd-b838cd50ddc6/emailkit","title":"EmailKit <= 1.6.3 - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 11:00:41","sources":[{"name":"Wordfence","remoteId":"d8c11ebc-5c83-46a2-a8dd-b838cd50ddc6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d8c11ebc-5c83-46a2-a8dd-b838cd50ddc6?source=api-prod","cve":"CVE-2026-3474","affectedVersions":"<=1.6.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/f131ea1e-d652-4854-abea-6a307ca8118f/emailkit","title":"EmailKit – Email Customizer for WooCommerce & WP <= 1.6.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Title Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 16:26:56","sources":[{"name":"Wordfence","remoteId":"f131ea1e-d652-4854-abea-6a307ca8118f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f131ea1e-d652-4854-abea-6a307ca8118f?source=api-prod","cve":"CVE-2026-1925","affectedVersions":"<=1.6.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_656e646c6573732d706f7374732d6e617669676174696f6e811c9dc5_gen.json b/internal/data/assets/plugin_656e646c6573732d706f7374732d6e617669676174696f6e811c9dc5_gen.json index 907de748..a82b51b9 100644 --- a/internal/data/assets/plugin_656e646c6573732d706f7374732d6e617669676174696f6e811c9dc5_gen.json +++ b/internal/data/assets/plugin_656e646c6573732d706f7374732d6e617669676174696f6e811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/f5030dd8-b723-443f-9dff-1f4d4c37b4fb/endless-posts-navigation","title":"Endless Posts Navigation <= 2.2.7 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"f5030dd8-b723-443f-9dff-1f4d4c37b4fb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5030dd8-b723-443f-9dff-1f4d4c37b4fb?source=api-prod","cve":"CVE-2024-49629","affectedVersions":"<=2.2.7","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/28206bc1-008f-407e-b1c9-e318abe09438/endless-posts-navigation","title":"Endless Posts Navigation <= 2.2.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"28206bc1-008f-407e-b1c9-e318abe09438"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/28206bc1-008f-407e-b1c9-e318abe09438?source=api-prod","cve":"CVE-2026-25332","affectedVersions":"<=2.2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/f5030dd8-b723-443f-9dff-1f4d4c37b4fb/endless-posts-navigation","title":"Endless Posts Navigation <= 2.2.7 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"f5030dd8-b723-443f-9dff-1f4d4c37b4fb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5030dd8-b723-443f-9dff-1f4d4c37b4fb?source=api-prod","cve":"CVE-2024-49629","affectedVersions":"<=2.2.7","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_657373656e7469616c2d6164646f6e732d666f722d656c656d656e746f722d6c697465811c9dc5_gen.json b/internal/data/assets/plugin_657373656e7469616c2d6164646f6e732d666f722d656c656d656e746f722d6c697465811c9dc5_gen.json index c4a8d79e..a1034b11 100644 --- a/internal/data/assets/plugin_657373656e7469616c2d6164646f6e732d666f722d656c656d656e746f722d6c697465811c9dc5_gen.json +++ b/internal/data/assets/plugin_657373656e7469616c2d6164646f6e732d666f722d656c656d656e746f722d6c697465811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/014f1aae-10a0-4bc8-b176-dbdad94a6ad8/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.0.4 - Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"014f1aae-10a0-4bc8-b176-dbdad94a6ad8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/014f1aae-10a0-4bc8-b176-dbdad94a6ad8?source=api-prod","cve":"CVE-2022-0320","affectedVersions":">=1.0.0,<=5.0.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/06ef9a21-e2b9-40c7-9de5-cff175fa10a5/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.5.5 - Missing Authorization to Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-15 20:04:09","sources":[{"name":"Wordfence","remoteId":"06ef9a21-e2b9-40c7-9de5-cff175fa10a5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/06ef9a21-e2b9-40c7-9de5-cff175fa10a5?source=api-prod","cve":"CVE-2026-1004","affectedVersions":"<=6.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/0eb2c608-1a1f-4c74-aa24-b955db052559/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.2.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"0eb2c608-1a1f-4c74-aa24-b955db052559"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0eb2c608-1a1f-4c74-aa24-b955db052559?source=api-prod","cve":"CVE-2025-64352","affectedVersions":"<=6.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/12dc9e63-17bb-4755-be3c-ae8b26edd3cd/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"12dc9e63-17bb-4755-be3c-ae8b26edd3cd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/12dc9e63-17bb-4755-be3c-ae8b26edd3cd?source=api-prod","cve":"CVE-2024-1536","affectedVersions":"<=5.9.9","severity":"high"},{"advisoryId":"WPSECADV/WF/167d3e1d-be74-4bfb-b3bf-e2c53d90e12f/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"167d3e1d-be74-4bfb-b3bf-e2c53d90e12f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/167d3e1d-be74-4bfb-b3bf-e2c53d90e12f?source=api-prod","cve":"CVE-2024-56063","affectedVersions":"<=6.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/1cf3190c-e247-4bcc-99e0-2ab2d2fa0590/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1cf3190c-e247-4bcc-99e0-2ab2d2fa0590"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1cf3190c-e247-4bcc-99e0-2ab2d2fa0590?source=api-prod","cve":"CVE-2024-4003","affectedVersions":"<=5.9.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/21e12c72-7898-4896-9852-ebb10e5f9a3b/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-09 19:32:53","sources":[{"name":"Wordfence","remoteId":"21e12c72-7898-4896-9852-ebb10e5f9a3b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/21e12c72-7898-4896-9852-ebb10e5f9a3b?source=api-prod","cve":"CVE-2024-4448","affectedVersions":"<=5.9.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/23a66e6b-cec0-4110-9bef-a5d41ce1c954/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"23a66e6b-cec0-4110-9bef-a5d41ce1c954"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/23a66e6b-cec0-4110-9bef-a5d41ce1c954?source=api-prod","cve":"CVE-2024-4156","affectedVersions":"<=5.9.17","severity":"medium"},{"advisoryId":"WPSECADV/WF/283fb581-8b61-4008-a5c4-2e1490fab33e/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 4.6.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-05-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"283fb581-8b61-4008-a5c4-2e1490fab33e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/283fb581-8b61-4008-a5c4-2e1490fab33e?source=api-prod","cve":"CVE-2021-4446","affectedVersions":"<=4.6.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/284ea577-ff67-4681-995b-f7bb5ef0ff3e/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"284ea577-ff67-4681-995b-f7bb5ef0ff3e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/284ea577-ff67-4681-995b-f7bb5ef0ff3e?source=api-prod","cve":"CVE-2024-3728","affectedVersions":"<=5.9.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/342049e5-834e-4867-8174-01ca7bb0caa2/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpassword\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"342049e5-834e-4867-8174-01ca7bb0caa2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/342049e5-834e-4867-8174-01ca7bb0caa2?source=api-prod","cve":"CVE-2024-3018","affectedVersions":"<=5.9.13","severity":"high"},{"advisoryId":"WPSECADV/WF/34d09086-be33-40cf-b5bf-d6c03cf0b68a/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"34d09086-be33-40cf-b5bf-d6c03cf0b68a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/34d09086-be33-40cf-b5bf-d6c03cf0b68a?source=api-prod","cve":"CVE-2024-8979","affectedVersions":"<=6.0.9","severity":"high"},{"advisoryId":"WPSECADV/WF/3d604f7a-947c-43f4-bba6-e7e98b2d7844/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"3d604f7a-947c-43f4-bba6-e7e98b2d7844"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3d604f7a-947c-43f4-bba6-e7e98b2d7844?source=api-prod","cve":"CVE-2024-3733","affectedVersions":"<=5.9.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/417baa1c-29f0-4fec-8008-5b52359b3328/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"417baa1c-29f0-4fec-8008-5b52359b3328"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/417baa1c-29f0-4fec-8008-5b52359b3328?source=api-prod","cve":"CVE-2024-0585","affectedVersions":"<=5.9.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/43014ecd-72d9-44cc-be24-c0c9790ddc20/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"43014ecd-72d9-44cc-be24-c0c9790ddc20"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/43014ecd-72d9-44cc-be24-c0c9790ddc20?source=api-prod","cve":"CVE-2024-1236","affectedVersions":"<=5.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/434b140a-43b7-41bc-8cc2-ed82787b90c3/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.1.9 - Authenticated (Contributor+) Information Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"434b140a-43b7-41bc-8cc2-ed82787b90c3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/434b140a-43b7-41bc-8cc2-ed82787b90c3?source=api-prod","cve":"CVE-2025-39589","affectedVersions":"<=6.1.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/45ef20aa-18e3-4ad8-a94e-76e29de5b562/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-14 18:35:38","sources":[{"name":"Wordfence","remoteId":"45ef20aa-18e3-4ad8-a94e-76e29de5b562"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/45ef20aa-18e3-4ad8-a94e-76e29de5b562?source=api-prod","cve":"CVE-2024-8961","affectedVersions":"<=6.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/4917652a-1c83-4570-98c5-1a34e637814e/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"4917652a-1c83-4570-98c5-1a34e637814e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4917652a-1c83-4570-98c5-1a34e637814e?source=api-prod","cve":"CVE-2025-8451","affectedVersions":"<=6.2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/56ba7d1b-7afd-4069-8b18-1158911fce3f/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"56ba7d1b-7afd-4069-8b18-1158911fce3f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/56ba7d1b-7afd-4069-8b18-1158911fce3f?source=api-prod","cve":"CVE-2025-69092","affectedVersions":"<=6.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/57ed6c7e-ca8d-476d-adce-905b2cd2eda8/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.9.19 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Several Widgets\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-09 19:27:26","sources":[{"name":"Wordfence","remoteId":"57ed6c7e-ca8d-476d-adce-905b2cd2eda8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/57ed6c7e-ca8d-476d-adce-905b2cd2eda8?source=api-prod","cve":"CVE-2024-4449","affectedVersions":"<=5.9.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/5a1d5fd1-80b6-4d62-9837-59ee1e020373/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.22 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"5a1d5fd1-80b6-4d62-9837-59ee1e020373"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5a1d5fd1-80b6-4d62-9837-59ee1e020373?source=api-prod","cve":"CVE-2024-5188","affectedVersions":"<=5.9.22","severity":"medium"},{"advisoryId":"WPSECADV/WF/6e770e98-3c13-4e37-b51b-4c39bce2cb42/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"6e770e98-3c13-4e37-b51b-4c39bce2cb42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6e770e98-3c13-4e37-b51b-4c39bce2cb42?source=api-prod","cve":"CVE-2023-7044","affectedVersions":"<=5.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/710e1c2c-4b5d-412c-950d-b5e530abf3a7/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.0.14 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"710e1c2c-4b5d-412c-950d-b5e530abf3a7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/710e1c2c-4b5d-412c-950d-b5e530abf3a7?source=api-prod","cve":"CVE-2025-24752","affectedVersions":"<=6.0.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/71378c94-c2e6-43a9-bb8b-f2ffb153f3fe/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"71378c94-c2e6-43a9-bb8b-f2ffb153f3fe"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/71378c94-c2e6-43a9-bb8b-f2ffb153f3fe?source=api-prod","cve":"CVE-2025-39590","affectedVersions":"<=6.1.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/718c60c1-6117-4959-a907-d0ef457f7185/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via no_more_items_text Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-12 16:05:31","sources":[{"name":"Wordfence","remoteId":"718c60c1-6117-4959-a907-d0ef457f7185"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/718c60c1-6117-4959-a907-d0ef457f7185?source=api-prod","cve":"CVE-2024-7092","affectedVersions":"<=5.9.27","severity":"medium"},{"advisoryId":"WPSECADV/WF/7242d808-9c33-4b3f-bda6-b4b72ca37de9/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7242d808-9c33-4b3f-bda6-b4b72ca37de9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7242d808-9c33-4b3f-bda6-b4b72ca37de9?source=api-prod","cve":"CVE-2024-2650","affectedVersions":"<=5.9.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/76c292dc-e9da-4256-82df-58ac5def4771/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-12 17:39:27","sources":[{"name":"Wordfence","remoteId":"76c292dc-e9da-4256-82df-58ac5def4771"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/76c292dc-e9da-4256-82df-58ac5def4771?source=api-prod","cve":"CVE-2024-8742","affectedVersions":"<=6.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/78f96d7f-aeca-4959-9573-0fb6402de007/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"78f96d7f-aeca-4959-9573-0fb6402de007"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/78f96d7f-aeca-4959-9573-0fb6402de007?source=api-prod","cve":"CVE-2024-2974","affectedVersions":"<=5.9.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/81a48c61-4191-4252-9230-9df8fc5e3443/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"81a48c61-4191-4252-9230-9df8fc5e3443"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/81a48c61-4191-4252-9230-9df8fc5e3443?source=api-prod","cve":"CVE-2024-1537","affectedVersions":"<=5.9.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/847a4fc7-3580-421e-8045-41b5a85f2d97/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-07 13:19:56","sources":[{"name":"Wordfence","remoteId":"847a4fc7-3580-421e-8045-41b5a85f2d97"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/847a4fc7-3580-421e-8045-41b5a85f2d97?source=api-prod","cve":"CVE-2025-6244","affectedVersions":"<=6.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/855ae993-d887-4416-9b3c-8274a90dce5f/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-06 21:37:15","sources":[{"name":"Wordfence","remoteId":"855ae993-d887-4416-9b3c-8274a90dce5f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/855ae993-d887-4416-9b3c-8274a90dce5f?source=api-prod","cve":"CVE-2024-9994","affectedVersions":"<=6.1.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/875db71d-c799-40b9-95e1-74d53046b0a9/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"875db71d-c799-40b9-95e1-74d53046b0a9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/875db71d-c799-40b9-95e1-74d53046b0a9?source=api-prod","cve":"CVE-2024-0954","affectedVersions":"<=5.9.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/8869a4fc-279f-4828-a271-8680d037fa85/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor Lite <= 5.0.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"8869a4fc-279f-4828-a271-8680d037fa85"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8869a4fc-279f-4828-a271-8680d037fa85?source=api-prod","cve":"CVE-2022-0683","affectedVersions":"<=5.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/8c13701e-424d-462f-b152-4dc5ad3ef197/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.8.8 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"8c13701e-424d-462f-b152-4dc5ad3ef197"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c13701e-424d-462f-b152-4dc5ad3ef197?source=api-prod","cve":"CVE-2023-41955","affectedVersions":"<=5.8.8","severity":"high"},{"advisoryId":"WPSECADV/WF/91f50b65-f001-4c73-bfe3-1aed3fc10d26/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Interactive Circles'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-09 19:28:58","sources":[{"name":"Wordfence","remoteId":"91f50b65-f001-4c73-bfe3-1aed3fc10d26"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91f50b65-f001-4c73-bfe3-1aed3fc10d26?source=api-prod","cve":"CVE-2024-4275","affectedVersions":"<=5.9.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/a0de0b28-fbad-4fcf-a7ab-35c545c19a4a/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-16 15:08:24","sources":[{"name":"Wordfence","remoteId":"a0de0b28-fbad-4fcf-a7ab-35c545c19a4a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a0de0b28-fbad-4fcf-a7ab-35c545c19a4a?source=api-prod","cve":"CVE-2025-13977","affectedVersions":"<=6.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/a2552407-0b32-4129-b131-792305ed023e/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Popular Elementor Templates & Widgets < 6.6.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"a2552407-0b32-4129-b131-792305ed023e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a2552407-0b32-4129-b131-792305ed023e?source=api-prod","cve":"CVE-2026-25440","affectedVersions":"<6.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/a8de8a0b-0b70-4e8a-8cc4-06cc50d06a02/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-06 21:37:20","sources":[{"name":"Wordfence","remoteId":"a8de8a0b-0b70-4e8a-8cc4-06cc50d06a02"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a8de8a0b-0b70-4e8a-8cc4-06cc50d06a02?source=api-prod","cve":"CVE-2024-9993","affectedVersions":"<=6.1.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/aa5bdaf9-fbde-40d4-a72a-fd24489818b3/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.9.14 - Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"aa5bdaf9-fbde-40d4-a72a-fd24489818b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa5bdaf9-fbde-40d4-a72a-fd24489818b3?source=api-prod","cve":"CVE-2024-3333","affectedVersions":"<=5.9.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/aa70238b-530e-4c90-82f4-c3113887d0e1/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.23 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"aa70238b-530e-4c90-82f4-c3113887d0e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa70238b-530e-4c90-82f4-c3113887d0e1?source=api-prod","cve":"CVE-2024-5189","affectedVersions":"<=5.9.23","severity":"medium"},{"advisoryId":"WPSECADV/WF/af8bee01-15bc-485e-8b01-8b68b199b34d/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"af8bee01-15bc-485e-8b01-8b68b199b34d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af8bee01-15bc-485e-8b01-8b68b199b34d?source=api-prod","cve":"CVE-2024-1276","affectedVersions":"<=5.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/baa92aee-a0a0-45d4-aa12-1449a829930c/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"baa92aee-a0a0-45d4-aa12-1449a829930c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/baa92aee-a0a0-45d4-aa12-1449a829930c?source=api-prod","cve":"CVE-2024-2623","affectedVersions":"<=5.9.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/baae8fb9-b87c-4f61-88da-871c4c83615b/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Contributor+) Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"baae8fb9-b87c-4f61-88da-871c4c83615b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/baae8fb9-b87c-4f61-88da-871c4c83615b?source=api-prod","cve":"CVE-2024-8978","affectedVersions":"<=6.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/be098ee9-b749-4908-85e8-e717d019609a/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-05-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"be098ee9-b749-4908-85e8-e717d019609a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be098ee9-b749-4908-85e8-e717d019609a?source=api-prod","cve":"CVE-2021-4447","affectedVersions":"<=4.6.4","severity":"high"},{"advisoryId":"WPSECADV/WF/bedad627-0ccb-41c1-be8d-753f57be618f/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.20 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"bedad627-0ccb-41c1-be8d-753f57be618f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bedad627-0ccb-41c1-be8d-753f57be618f?source=api-prod","cve":"CVE-2024-4624","affectedVersions":"<=5.9.20","severity":"medium"},{"advisoryId":"WPSECADV/WF/c00ff4bd-d846-4e3f-95ed-2a6430c47ebf/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scritping\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"c00ff4bd-d846-4e3f-95ed-2a6430c47ebf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c00ff4bd-d846-4e3f-95ed-2a6430c47ebf?source=api-prod","cve":"CVE-2024-0586","affectedVersions":"<=5.9.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/c5960396-5320-4978-aa82-2e33700daa43/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-10 17:52:37","sources":[{"name":"Wordfence","remoteId":"c5960396-5320-4978-aa82-2e33700daa43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c5960396-5320-4978-aa82-2e33700daa43?source=api-prod","cve":"CVE-2024-8440","affectedVersions":"<=6.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8db80ef-5863-41dd-b33f-850984a72ee6/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Feed\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-29 18:31:01","sources":[{"name":"Wordfence","remoteId":"c8db80ef-5863-41dd-b33f-850984a72ee6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8db80ef-5863-41dd-b33f-850984a72ee6?source=api-prod","cve":"CVE-2024-5073","affectedVersions":"<=5.9.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/d652f383-ca3d-440e-a30f-64a50efd65e1/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-13 21:37:33","sources":[{"name":"Wordfence","remoteId":"d652f383-ca3d-440e-a30f-64a50efd65e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d652f383-ca3d-440e-a30f-64a50efd65e1?source=api-prod","cve":"CVE-2026-1512","affectedVersions":"<=6.5.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/dae80fc2-3076-4a32-876d-5df1c62de9bd/essential-addons-for-elementor-lite","title":"Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"dae80fc2-3076-4a32-876d-5df1c62de9bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dae80fc2-3076-4a32-876d-5df1c62de9bd?source=api-prod","cve":"CVE-2024-5647","affectedVersions":"<=6.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/de614bbd-42ae-4c2a-aec6-31245124de76/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor Lite <= 4.5.3 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-04-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"de614bbd-42ae-4c2a-aec6-31245124de76"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/de614bbd-42ae-4c2a-aec6-31245124de76?source=api-prod","cve":"CVE-2021-24255","affectedVersions":"<4.5.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/dfb6961b-1398-409d-ada2-cf5424cb2b73/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"dfb6961b-1398-409d-ada2-cf5424cb2b73"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dfb6961b-1398-409d-ada2-cf5424cb2b73?source=api-prod","cve":"CVE-2024-34764","affectedVersions":"<=5.9.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/e007c713-74bc-4ff5-a198-70dcc8a8ee68/essential-addons-for-elementor-lite","title":"Essential Addons For Elementor <=5.8.1 - Unauthenticated MailChimp API Key Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"e007c713-74bc-4ff5-a198-70dcc8a8ee68"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e007c713-74bc-4ff5-a198-70dcc8a8ee68?source=api-prod","cve":"CVE-2023-3779","affectedVersions":"<=5.8.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/e988d042-147c-4782-b728-71f5a50cecd8/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.7.1 - Unauthenticated Arbitrary Password Reset to Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"e988d042-147c-4782-b728-71f5a50cecd8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e988d042-147c-4782-b728-71f5a50cecd8?source=api-prod","cve":"CVE-2023-32243","affectedVersions":"<=5.7.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/eee7cad6-7910-4860-add9-c500d1f6eff3/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.9.26 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"eee7cad6-7910-4860-add9-c500d1f6eff3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eee7cad6-7910-4860-add9-c500d1f6eff3?source=api-prod","cve":"CVE-2024-39649","affectedVersions":"<=5.9.26","severity":"medium"},{"advisoryId":"WPSECADV/WF/f2ff2cc6-b584-442b-890b-033a0a047c24/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"f2ff2cc6-b584-442b-890b-033a0a047c24"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2ff2cc6-b584-442b-890b-033a0a047c24?source=api-prod","cve":"CVE-2024-1172","affectedVersions":"<=5.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/fafdd087-9637-41df-bc5a-97e1a02ea744/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"fafdd087-9637-41df-bc5a-97e1a02ea744"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fafdd087-9637-41df-bc5a-97e1a02ea744?source=api-prod","cve":"CVE-2024-1171","affectedVersions":"<=5.9.8","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/014f1aae-10a0-4bc8-b176-dbdad94a6ad8/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.0.4 - Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"014f1aae-10a0-4bc8-b176-dbdad94a6ad8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/014f1aae-10a0-4bc8-b176-dbdad94a6ad8?source=api-prod","cve":"CVE-2022-0320","affectedVersions":">=1.0.0,<=5.0.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/063b50e3-1369-4240-b695-6ac336f4ea75/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.5.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"063b50e3-1369-4240-b695-6ac336f4ea75"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/063b50e3-1369-4240-b695-6ac336f4ea75?source=api-prod","cve":"CVE-2026-23543","affectedVersions":"<=6.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/06ef9a21-e2b9-40c7-9de5-cff175fa10a5/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.5.5 - Missing Authorization to Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-15 20:04:09","sources":[{"name":"Wordfence","remoteId":"06ef9a21-e2b9-40c7-9de5-cff175fa10a5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/06ef9a21-e2b9-40c7-9de5-cff175fa10a5?source=api-prod","cve":"CVE-2026-1004","affectedVersions":"<=6.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/0eb2c608-1a1f-4c74-aa24-b955db052559/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.2.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"0eb2c608-1a1f-4c74-aa24-b955db052559"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0eb2c608-1a1f-4c74-aa24-b955db052559?source=api-prod","cve":"CVE-2025-64352","affectedVersions":"<=6.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/12dc9e63-17bb-4755-be3c-ae8b26edd3cd/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"12dc9e63-17bb-4755-be3c-ae8b26edd3cd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/12dc9e63-17bb-4755-be3c-ae8b26edd3cd?source=api-prod","cve":"CVE-2024-1536","affectedVersions":"<=5.9.9","severity":"high"},{"advisoryId":"WPSECADV/WF/167d3e1d-be74-4bfb-b3bf-e2c53d90e12f/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"167d3e1d-be74-4bfb-b3bf-e2c53d90e12f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/167d3e1d-be74-4bfb-b3bf-e2c53d90e12f?source=api-prod","cve":"CVE-2024-56063","affectedVersions":"<=6.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/1cf3190c-e247-4bcc-99e0-2ab2d2fa0590/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1cf3190c-e247-4bcc-99e0-2ab2d2fa0590"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1cf3190c-e247-4bcc-99e0-2ab2d2fa0590?source=api-prod","cve":"CVE-2024-4003","affectedVersions":"<=5.9.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/21e12c72-7898-4896-9852-ebb10e5f9a3b/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-09 19:32:53","sources":[{"name":"Wordfence","remoteId":"21e12c72-7898-4896-9852-ebb10e5f9a3b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/21e12c72-7898-4896-9852-ebb10e5f9a3b?source=api-prod","cve":"CVE-2024-4448","affectedVersions":"<=5.9.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/23a66e6b-cec0-4110-9bef-a5d41ce1c954/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"23a66e6b-cec0-4110-9bef-a5d41ce1c954"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/23a66e6b-cec0-4110-9bef-a5d41ce1c954?source=api-prod","cve":"CVE-2024-4156","affectedVersions":"<=5.9.17","severity":"medium"},{"advisoryId":"WPSECADV/WF/283fb581-8b61-4008-a5c4-2e1490fab33e/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 4.6.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-05-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"283fb581-8b61-4008-a5c4-2e1490fab33e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/283fb581-8b61-4008-a5c4-2e1490fab33e?source=api-prod","cve":"CVE-2021-4446","affectedVersions":"<=4.6.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/284ea577-ff67-4681-995b-f7bb5ef0ff3e/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"284ea577-ff67-4681-995b-f7bb5ef0ff3e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/284ea577-ff67-4681-995b-f7bb5ef0ff3e?source=api-prod","cve":"CVE-2024-3728","affectedVersions":"<=5.9.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/342049e5-834e-4867-8174-01ca7bb0caa2/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpassword\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"342049e5-834e-4867-8174-01ca7bb0caa2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/342049e5-834e-4867-8174-01ca7bb0caa2?source=api-prod","cve":"CVE-2024-3018","affectedVersions":"<=5.9.13","severity":"high"},{"advisoryId":"WPSECADV/WF/34d09086-be33-40cf-b5bf-d6c03cf0b68a/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"34d09086-be33-40cf-b5bf-d6c03cf0b68a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/34d09086-be33-40cf-b5bf-d6c03cf0b68a?source=api-prod","cve":"CVE-2024-8979","affectedVersions":"<=6.0.9","severity":"high"},{"advisoryId":"WPSECADV/WF/3d604f7a-947c-43f4-bba6-e7e98b2d7844/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"3d604f7a-947c-43f4-bba6-e7e98b2d7844"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3d604f7a-947c-43f4-bba6-e7e98b2d7844?source=api-prod","cve":"CVE-2024-3733","affectedVersions":"<=5.9.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/417baa1c-29f0-4fec-8008-5b52359b3328/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"417baa1c-29f0-4fec-8008-5b52359b3328"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/417baa1c-29f0-4fec-8008-5b52359b3328?source=api-prod","cve":"CVE-2024-0585","affectedVersions":"<=5.9.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/43014ecd-72d9-44cc-be24-c0c9790ddc20/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"43014ecd-72d9-44cc-be24-c0c9790ddc20"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/43014ecd-72d9-44cc-be24-c0c9790ddc20?source=api-prod","cve":"CVE-2024-1236","affectedVersions":"<=5.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/434b140a-43b7-41bc-8cc2-ed82787b90c3/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.1.9 - Authenticated (Contributor+) Information Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"434b140a-43b7-41bc-8cc2-ed82787b90c3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/434b140a-43b7-41bc-8cc2-ed82787b90c3?source=api-prod","cve":"CVE-2025-39589","affectedVersions":"<=6.1.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/45ef20aa-18e3-4ad8-a94e-76e29de5b562/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-14 18:35:38","sources":[{"name":"Wordfence","remoteId":"45ef20aa-18e3-4ad8-a94e-76e29de5b562"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/45ef20aa-18e3-4ad8-a94e-76e29de5b562?source=api-prod","cve":"CVE-2024-8961","affectedVersions":"<=6.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/4917652a-1c83-4570-98c5-1a34e637814e/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"4917652a-1c83-4570-98c5-1a34e637814e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4917652a-1c83-4570-98c5-1a34e637814e?source=api-prod","cve":"CVE-2025-8451","affectedVersions":"<=6.2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/56ba7d1b-7afd-4069-8b18-1158911fce3f/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"56ba7d1b-7afd-4069-8b18-1158911fce3f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/56ba7d1b-7afd-4069-8b18-1158911fce3f?source=api-prod","cve":"CVE-2025-69092","affectedVersions":"<=6.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/57ed6c7e-ca8d-476d-adce-905b2cd2eda8/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.9.19 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Several Widgets\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-09 19:27:26","sources":[{"name":"Wordfence","remoteId":"57ed6c7e-ca8d-476d-adce-905b2cd2eda8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/57ed6c7e-ca8d-476d-adce-905b2cd2eda8?source=api-prod","cve":"CVE-2024-4449","affectedVersions":"<=5.9.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/5a1d5fd1-80b6-4d62-9837-59ee1e020373/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.22 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"5a1d5fd1-80b6-4d62-9837-59ee1e020373"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5a1d5fd1-80b6-4d62-9837-59ee1e020373?source=api-prod","cve":"CVE-2024-5188","affectedVersions":"<=5.9.22","severity":"medium"},{"advisoryId":"WPSECADV/WF/6e770e98-3c13-4e37-b51b-4c39bce2cb42/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"6e770e98-3c13-4e37-b51b-4c39bce2cb42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6e770e98-3c13-4e37-b51b-4c39bce2cb42?source=api-prod","cve":"CVE-2023-7044","affectedVersions":"<=5.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/710e1c2c-4b5d-412c-950d-b5e530abf3a7/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.0.14 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"710e1c2c-4b5d-412c-950d-b5e530abf3a7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/710e1c2c-4b5d-412c-950d-b5e530abf3a7?source=api-prod","cve":"CVE-2025-24752","affectedVersions":"<=6.0.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/71378c94-c2e6-43a9-bb8b-f2ffb153f3fe/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"71378c94-c2e6-43a9-bb8b-f2ffb153f3fe"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/71378c94-c2e6-43a9-bb8b-f2ffb153f3fe?source=api-prod","cve":"CVE-2025-39590","affectedVersions":"<=6.1.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/718c60c1-6117-4959-a907-d0ef457f7185/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via no_more_items_text Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-12 16:05:31","sources":[{"name":"Wordfence","remoteId":"718c60c1-6117-4959-a907-d0ef457f7185"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/718c60c1-6117-4959-a907-d0ef457f7185?source=api-prod","cve":"CVE-2024-7092","affectedVersions":"<=5.9.27","severity":"medium"},{"advisoryId":"WPSECADV/WF/7242d808-9c33-4b3f-bda6-b4b72ca37de9/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7242d808-9c33-4b3f-bda6-b4b72ca37de9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7242d808-9c33-4b3f-bda6-b4b72ca37de9?source=api-prod","cve":"CVE-2024-2650","affectedVersions":"<=5.9.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/76c292dc-e9da-4256-82df-58ac5def4771/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-12 17:39:27","sources":[{"name":"Wordfence","remoteId":"76c292dc-e9da-4256-82df-58ac5def4771"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/76c292dc-e9da-4256-82df-58ac5def4771?source=api-prod","cve":"CVE-2024-8742","affectedVersions":"<=6.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/78f96d7f-aeca-4959-9573-0fb6402de007/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"78f96d7f-aeca-4959-9573-0fb6402de007"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/78f96d7f-aeca-4959-9573-0fb6402de007?source=api-prod","cve":"CVE-2024-2974","affectedVersions":"<=5.9.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/81a48c61-4191-4252-9230-9df8fc5e3443/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"81a48c61-4191-4252-9230-9df8fc5e3443"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/81a48c61-4191-4252-9230-9df8fc5e3443?source=api-prod","cve":"CVE-2024-1537","affectedVersions":"<=5.9.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/847a4fc7-3580-421e-8045-41b5a85f2d97/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-07 13:19:56","sources":[{"name":"Wordfence","remoteId":"847a4fc7-3580-421e-8045-41b5a85f2d97"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/847a4fc7-3580-421e-8045-41b5a85f2d97?source=api-prod","cve":"CVE-2025-6244","affectedVersions":"<=6.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/855ae993-d887-4416-9b3c-8274a90dce5f/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-06 21:37:15","sources":[{"name":"Wordfence","remoteId":"855ae993-d887-4416-9b3c-8274a90dce5f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/855ae993-d887-4416-9b3c-8274a90dce5f?source=api-prod","cve":"CVE-2024-9994","affectedVersions":"<=6.1.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/875db71d-c799-40b9-95e1-74d53046b0a9/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"875db71d-c799-40b9-95e1-74d53046b0a9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/875db71d-c799-40b9-95e1-74d53046b0a9?source=api-prod","cve":"CVE-2024-0954","affectedVersions":"<=5.9.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/8869a4fc-279f-4828-a271-8680d037fa85/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor Lite <= 5.0.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"8869a4fc-279f-4828-a271-8680d037fa85"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8869a4fc-279f-4828-a271-8680d037fa85?source=api-prod","cve":"CVE-2022-0683","affectedVersions":"<=5.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/8c13701e-424d-462f-b152-4dc5ad3ef197/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.8.8 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"8c13701e-424d-462f-b152-4dc5ad3ef197"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c13701e-424d-462f-b152-4dc5ad3ef197?source=api-prod","cve":"CVE-2023-41955","affectedVersions":"<=5.8.8","severity":"high"},{"advisoryId":"WPSECADV/WF/91f50b65-f001-4c73-bfe3-1aed3fc10d26/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Interactive Circles'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-09 19:28:58","sources":[{"name":"Wordfence","remoteId":"91f50b65-f001-4c73-bfe3-1aed3fc10d26"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91f50b65-f001-4c73-bfe3-1aed3fc10d26?source=api-prod","cve":"CVE-2024-4275","affectedVersions":"<=5.9.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/a0de0b28-fbad-4fcf-a7ab-35c545c19a4a/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-16 15:08:24","sources":[{"name":"Wordfence","remoteId":"a0de0b28-fbad-4fcf-a7ab-35c545c19a4a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a0de0b28-fbad-4fcf-a7ab-35c545c19a4a?source=api-prod","cve":"CVE-2025-13977","affectedVersions":"<=6.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/a2552407-0b32-4129-b131-792305ed023e/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Popular Elementor Templates & Widgets < 6.6.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"a2552407-0b32-4129-b131-792305ed023e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a2552407-0b32-4129-b131-792305ed023e?source=api-prod","cve":"CVE-2026-25440","affectedVersions":"<6.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/a8de8a0b-0b70-4e8a-8cc4-06cc50d06a02/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-06 21:37:20","sources":[{"name":"Wordfence","remoteId":"a8de8a0b-0b70-4e8a-8cc4-06cc50d06a02"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a8de8a0b-0b70-4e8a-8cc4-06cc50d06a02?source=api-prod","cve":"CVE-2024-9993","affectedVersions":"<=6.1.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/aa5bdaf9-fbde-40d4-a72a-fd24489818b3/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.9.14 - Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"aa5bdaf9-fbde-40d4-a72a-fd24489818b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa5bdaf9-fbde-40d4-a72a-fd24489818b3?source=api-prod","cve":"CVE-2024-3333","affectedVersions":"<=5.9.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/aa70238b-530e-4c90-82f4-c3113887d0e1/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.23 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"aa70238b-530e-4c90-82f4-c3113887d0e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa70238b-530e-4c90-82f4-c3113887d0e1?source=api-prod","cve":"CVE-2024-5189","affectedVersions":"<=5.9.23","severity":"medium"},{"advisoryId":"WPSECADV/WF/af8bee01-15bc-485e-8b01-8b68b199b34d/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"af8bee01-15bc-485e-8b01-8b68b199b34d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af8bee01-15bc-485e-8b01-8b68b199b34d?source=api-prod","cve":"CVE-2024-1276","affectedVersions":"<=5.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/baa92aee-a0a0-45d4-aa12-1449a829930c/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"baa92aee-a0a0-45d4-aa12-1449a829930c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/baa92aee-a0a0-45d4-aa12-1449a829930c?source=api-prod","cve":"CVE-2024-2623","affectedVersions":"<=5.9.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/baae8fb9-b87c-4f61-88da-871c4c83615b/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Contributor+) Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"baae8fb9-b87c-4f61-88da-871c4c83615b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/baae8fb9-b87c-4f61-88da-871c4c83615b?source=api-prod","cve":"CVE-2024-8978","affectedVersions":"<=6.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/be098ee9-b749-4908-85e8-e717d019609a/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-05-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"be098ee9-b749-4908-85e8-e717d019609a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be098ee9-b749-4908-85e8-e717d019609a?source=api-prod","cve":"CVE-2021-4447","affectedVersions":"<=4.6.4","severity":"high"},{"advisoryId":"WPSECADV/WF/bedad627-0ccb-41c1-be8d-753f57be618f/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.20 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"bedad627-0ccb-41c1-be8d-753f57be618f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bedad627-0ccb-41c1-be8d-753f57be618f?source=api-prod","cve":"CVE-2024-4624","affectedVersions":"<=5.9.20","severity":"medium"},{"advisoryId":"WPSECADV/WF/c00ff4bd-d846-4e3f-95ed-2a6430c47ebf/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scritping\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"c00ff4bd-d846-4e3f-95ed-2a6430c47ebf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c00ff4bd-d846-4e3f-95ed-2a6430c47ebf?source=api-prod","cve":"CVE-2024-0586","affectedVersions":"<=5.9.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/c5960396-5320-4978-aa82-2e33700daa43/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-10 17:52:37","sources":[{"name":"Wordfence","remoteId":"c5960396-5320-4978-aa82-2e33700daa43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c5960396-5320-4978-aa82-2e33700daa43?source=api-prod","cve":"CVE-2024-8440","affectedVersions":"<=6.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8db80ef-5863-41dd-b33f-850984a72ee6/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Feed\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-29 18:31:01","sources":[{"name":"Wordfence","remoteId":"c8db80ef-5863-41dd-b33f-850984a72ee6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8db80ef-5863-41dd-b33f-850984a72ee6?source=api-prod","cve":"CVE-2024-5073","affectedVersions":"<=5.9.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/d652f383-ca3d-440e-a30f-64a50efd65e1/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 6.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-13 21:37:33","sources":[{"name":"Wordfence","remoteId":"d652f383-ca3d-440e-a30f-64a50efd65e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d652f383-ca3d-440e-a30f-64a50efd65e1?source=api-prod","cve":"CVE-2026-1512","affectedVersions":"<=6.5.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/dae80fc2-3076-4a32-876d-5df1c62de9bd/essential-addons-for-elementor-lite","title":"Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"dae80fc2-3076-4a32-876d-5df1c62de9bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dae80fc2-3076-4a32-876d-5df1c62de9bd?source=api-prod","cve":"CVE-2024-5647","affectedVersions":"<=6.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/de614bbd-42ae-4c2a-aec6-31245124de76/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor Lite <= 4.5.3 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-04-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"de614bbd-42ae-4c2a-aec6-31245124de76"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/de614bbd-42ae-4c2a-aec6-31245124de76?source=api-prod","cve":"CVE-2021-24255","affectedVersions":"<4.5.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/dfb6961b-1398-409d-ada2-cf5424cb2b73/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"dfb6961b-1398-409d-ada2-cf5424cb2b73"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dfb6961b-1398-409d-ada2-cf5424cb2b73?source=api-prod","cve":"CVE-2024-34764","affectedVersions":"<=5.9.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/e007c713-74bc-4ff5-a198-70dcc8a8ee68/essential-addons-for-elementor-lite","title":"Essential Addons For Elementor <=5.8.1 - Unauthenticated MailChimp API Key Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"e007c713-74bc-4ff5-a198-70dcc8a8ee68"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e007c713-74bc-4ff5-a198-70dcc8a8ee68?source=api-prod","cve":"CVE-2023-3779","affectedVersions":"<=5.8.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/e988d042-147c-4782-b728-71f5a50cecd8/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.7.1 - Unauthenticated Arbitrary Password Reset to Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"e988d042-147c-4782-b728-71f5a50cecd8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e988d042-147c-4782-b728-71f5a50cecd8?source=api-prod","cve":"CVE-2023-32243","affectedVersions":"<=5.7.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/eee7cad6-7910-4860-add9-c500d1f6eff3/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor <= 5.9.26 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"eee7cad6-7910-4860-add9-c500d1f6eff3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eee7cad6-7910-4860-add9-c500d1f6eff3?source=api-prod","cve":"CVE-2024-39649","affectedVersions":"<=5.9.26","severity":"medium"},{"advisoryId":"WPSECADV/WF/f2ff2cc6-b584-442b-890b-033a0a047c24/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"f2ff2cc6-b584-442b-890b-033a0a047c24"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2ff2cc6-b584-442b-890b-033a0a047c24?source=api-prod","cve":"CVE-2024-1172","affectedVersions":"<=5.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/fafdd087-9637-41df-bc5a-97e1a02ea744/essential-addons-for-elementor-lite","title":"Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"fafdd087-9637-41df-bc5a-97e1a02ea744"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fafdd087-9637-41df-bc5a-97e1a02ea744?source=api-prod","cve":"CVE-2024-1171","affectedVersions":"<=5.9.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_65742d636f72652d706c7567696e811c9dc5_gen.json b/internal/data/assets/plugin_65742d636f72652d706c7567696e811c9dc5_gen.json index 361a830c..a1bb14eb 100644 --- a/internal/data/assets/plugin_65742d636f72652d706c7567696e811c9dc5_gen.json +++ b/internal/data/assets/plugin_65742d636f72652d706c7567696e811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/01f798e7-f4e1-4cd8-b284-68101582fc2d/et-core-plugin","title":"XStore Core <= 5.6.4 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"01f798e7-f4e1-4cd8-b284-68101582fc2d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/01f798e7-f4e1-4cd8-b284-68101582fc2d?source=api-prod","cve":"CVE-2026-25306","affectedVersions":"<=5.6.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/02399fc5-fe74-4ee5-ac63-78d971d2f99e/et-core-plugin","title":"XStore Core <= 5.3.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"02399fc5-fe74-4ee5-ac63-78d971d2f99e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/02399fc5-fe74-4ee5-ac63-78d971d2f99e?source=api-prod","cve":"CVE-2024-33554","affectedVersions":"<=5.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/050b6ad4-f1e4-403f-9e0e-7fc18504f661/et-core-plugin","title":"XStore Core <= 5.3.8 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"050b6ad4-f1e4-403f-9e0e-7fc18504f661"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/050b6ad4-f1e4-403f-9e0e-7fc18504f661?source=api-prod","cve":"CVE-2024-33551","affectedVersions":"<=5.3.8","severity":"critical"},{"advisoryId":"WPSECADV/WF/120c9d81-0dff-4b70-b565-fedda2c089e8/et-core-plugin","title":"XStore Core < 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"120c9d81-0dff-4b70-b565-fedda2c089e8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/120c9d81-0dff-4b70-b565-fedda2c089e8?source=api-prod","cve":"CVE-2025-64190","affectedVersions":"<5.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/4167f0ad-aeef-4525-82c9-336f9f48a55e/et-core-plugin","title":"XStore Core <= 5.3.8 - Authenticated (Subscriber+) Limited Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"4167f0ad-aeef-4525-82c9-336f9f48a55e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4167f0ad-aeef-4525-82c9-336f9f48a55e?source=api-prod","cve":"CVE-2024-33556","affectedVersions":"<=5.3.8","severity":"critical"},{"advisoryId":"WPSECADV/WF/46bc15d6-dc1b-40ec-8bb9-5342a4f84372/et-core-plugin","title":"XStore Core <= 5.3.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"46bc15d6-dc1b-40ec-8bb9-5342a4f84372"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/46bc15d6-dc1b-40ec-8bb9-5342a4f84372?source=api-prod","cve":"CVE-2024-33555","affectedVersions":"<=5.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/7019b542-9b9a-4d16-94a0-412cccf1e6eb/et-core-plugin","title":"XStore Core <= 5.3.8 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7019b542-9b9a-4d16-94a0-412cccf1e6eb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7019b542-9b9a-4d16-94a0-412cccf1e6eb?source=api-prod","cve":"CVE-2024-33552","affectedVersions":"<=5.3.8","severity":"critical"},{"advisoryId":"WPSECADV/WF/856e3e77-d330-4fa0-9f07-f77a56dbb5bd/et-core-plugin","title":"XStore Core <= 5.3.8 - Authenticated (Subscriber+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"856e3e77-d330-4fa0-9f07-f77a56dbb5bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/856e3e77-d330-4fa0-9f07-f77a56dbb5bd?source=api-prod","cve":"CVE-2024-33557","affectedVersions":"<=5.3.8","severity":"high"},{"advisoryId":"WPSECADV/WF/9d5fc7a7-8461-4bd3-9d4e-1f5c98827d83/et-core-plugin","title":"XStore Core < 5.6 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"9d5fc7a7-8461-4bd3-9d4e-1f5c98827d83"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9d5fc7a7-8461-4bd3-9d4e-1f5c98827d83?source=api-prod","cve":"CVE-2025-64189","affectedVersions":"<5.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6986569-a273-4aea-bc74-ef7277781661/et-core-plugin","title":"XStore Core <= 5.3.8 - Authenticated (Subscriber+) Limited Arbitrary File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"b6986569-a273-4aea-bc74-ef7277781661"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6986569-a273-4aea-bc74-ef7277781661?source=api-prod","cve":"CVE-2024-33558","affectedVersions":"<=5.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/ba502aac-13f7-40e2-9672-bf26a0fefef7/et-core-plugin","title":"XStore Core <= 5.3.8 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"ba502aac-13f7-40e2-9672-bf26a0fefef7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ba502aac-13f7-40e2-9672-bf26a0fefef7?source=api-prod","cve":"CVE-2024-33553","affectedVersions":"<=5.3.8","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/00d5c081-d703-4195-aa92-204624d72203/et-core-plugin","title":"XStore Core < 5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"00d5c081-d703-4195-aa92-204624d72203"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00d5c081-d703-4195-aa92-204624d72203?source=api-prod","cve":"CVE-2026-25307","affectedVersions":"<5.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/01f798e7-f4e1-4cd8-b284-68101582fc2d/et-core-plugin","title":"XStore Core <= 5.6.4 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"01f798e7-f4e1-4cd8-b284-68101582fc2d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/01f798e7-f4e1-4cd8-b284-68101582fc2d?source=api-prod","cve":"CVE-2026-25306","affectedVersions":"<=5.6.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/02399fc5-fe74-4ee5-ac63-78d971d2f99e/et-core-plugin","title":"XStore Core <= 5.3.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"02399fc5-fe74-4ee5-ac63-78d971d2f99e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/02399fc5-fe74-4ee5-ac63-78d971d2f99e?source=api-prod","cve":"CVE-2024-33554","affectedVersions":"<=5.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/050b6ad4-f1e4-403f-9e0e-7fc18504f661/et-core-plugin","title":"XStore Core <= 5.3.8 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"050b6ad4-f1e4-403f-9e0e-7fc18504f661"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/050b6ad4-f1e4-403f-9e0e-7fc18504f661?source=api-prod","cve":"CVE-2024-33551","affectedVersions":"<=5.3.8","severity":"critical"},{"advisoryId":"WPSECADV/WF/120c9d81-0dff-4b70-b565-fedda2c089e8/et-core-plugin","title":"XStore Core < 5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"120c9d81-0dff-4b70-b565-fedda2c089e8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/120c9d81-0dff-4b70-b565-fedda2c089e8?source=api-prod","cve":"CVE-2025-64190","affectedVersions":"<5.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/4167f0ad-aeef-4525-82c9-336f9f48a55e/et-core-plugin","title":"XStore Core <= 5.3.8 - Authenticated (Subscriber+) Limited Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"4167f0ad-aeef-4525-82c9-336f9f48a55e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4167f0ad-aeef-4525-82c9-336f9f48a55e?source=api-prod","cve":"CVE-2024-33556","affectedVersions":"<=5.3.8","severity":"critical"},{"advisoryId":"WPSECADV/WF/46bc15d6-dc1b-40ec-8bb9-5342a4f84372/et-core-plugin","title":"XStore Core <= 5.3.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"46bc15d6-dc1b-40ec-8bb9-5342a4f84372"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/46bc15d6-dc1b-40ec-8bb9-5342a4f84372?source=api-prod","cve":"CVE-2024-33555","affectedVersions":"<=5.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/7019b542-9b9a-4d16-94a0-412cccf1e6eb/et-core-plugin","title":"XStore Core <= 5.3.8 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7019b542-9b9a-4d16-94a0-412cccf1e6eb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7019b542-9b9a-4d16-94a0-412cccf1e6eb?source=api-prod","cve":"CVE-2024-33552","affectedVersions":"<=5.3.8","severity":"critical"},{"advisoryId":"WPSECADV/WF/856e3e77-d330-4fa0-9f07-f77a56dbb5bd/et-core-plugin","title":"XStore Core <= 5.3.8 - Authenticated (Subscriber+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"856e3e77-d330-4fa0-9f07-f77a56dbb5bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/856e3e77-d330-4fa0-9f07-f77a56dbb5bd?source=api-prod","cve":"CVE-2024-33557","affectedVersions":"<=5.3.8","severity":"high"},{"advisoryId":"WPSECADV/WF/9d5fc7a7-8461-4bd3-9d4e-1f5c98827d83/et-core-plugin","title":"XStore Core < 5.6 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"9d5fc7a7-8461-4bd3-9d4e-1f5c98827d83"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9d5fc7a7-8461-4bd3-9d4e-1f5c98827d83?source=api-prod","cve":"CVE-2025-64189","affectedVersions":"<5.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6986569-a273-4aea-bc74-ef7277781661/et-core-plugin","title":"XStore Core <= 5.3.8 - Authenticated (Subscriber+) Limited Arbitrary File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"b6986569-a273-4aea-bc74-ef7277781661"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6986569-a273-4aea-bc74-ef7277781661?source=api-prod","cve":"CVE-2024-33558","affectedVersions":"<=5.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/ba502aac-13f7-40e2-9672-bf26a0fefef7/et-core-plugin","title":"XStore Core <= 5.3.8 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"ba502aac-13f7-40e2-9672-bf26a0fefef7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ba502aac-13f7-40e2-9672-bf26a0fefef7?source=api-prod","cve":"CVE-2024-33553","affectedVersions":"<=5.3.8","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6576656e742d7469636b657473811c9dc5_gen.json b/internal/data/assets/plugin_6576656e742d7469636b657473811c9dc5_gen.json index 5002cca9..d9c02a17 100644 --- a/internal/data/assets/plugin_6576656e742d7469636b657473811c9dc5_gen.json +++ b/internal/data/assets/plugin_6576656e742d7469636b657473811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0cc2261a-889e-40ec-8382-48de65b91b34/event-tickets","title":"Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-29 18:25:56","sources":[{"name":"Wordfence","remoteId":"0cc2261a-889e-40ec-8382-48de65b91b34"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0cc2261a-889e-40ec-8382-48de65b91b34?source=api-prod","cve":"CVE-2024-13457","affectedVersions":"<=5.18.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/21cd8cb8-2a29-4b66-ab7a-8d8b2f85e2e0/event-tickets","title":"Event Tickets and Registration <= 5.26.5 - Unauthenticated Ticket Payment Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-17 18:07:22","sources":[{"name":"Wordfence","remoteId":"21cd8cb8-2a29-4b66-ab7a-8d8b2f85e2e0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/21cd8cb8-2a29-4b66-ab7a-8d8b2f85e2e0?source=api-prod","cve":"CVE-2025-11517","affectedVersions":"<=5.26.5","severity":"high"},{"advisoryId":"WPSECADV/WF/2e42dd1c-adf7-471a-a14a-9038c56413a2/event-tickets","title":"Event Tickets and Registration <= 5.8.2 - Improper Authorization to Information Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"2e42dd1c-adf7-471a-a14a-9038c56413a2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2e42dd1c-adf7-471a-a14a-9038c56413a2?source=api-prod","cve":"CVE-2024-2261","affectedVersions":"<=5.8.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42/event-tickets","title":"Freemius SDK <= 2.4.2 - Missing Authorization Checks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"39fb0499-9ab4-4a2f-b0db-ece86bcf4d42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=api-prod","cve":"CVE-2022-4974","affectedVersions":"<5.3.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/5c9d08f5-7c94-40e7-979f-023456aeb54e/event-tickets","title":"Event Tickets and Registration <= 5.8.0 Events Tickets Plus <= 5.9.0 - Authenticated (Contributor+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"5c9d08f5-7c94-40e7-979f-023456aeb54e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5c9d08f5-7c94-40e7-979f-023456aeb54e?source=api-prod","cve":"CVE-2024-1316","affectedVersions":"<=5.8.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/7849addf-cdee-4de2-9b6c-bb1c92a472fd/event-tickets","title":"Event Tickets <= 5.20.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"7849addf-cdee-4de2-9b6c-bb1c92a472fd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7849addf-cdee-4de2-9b6c-bb1c92a472fd?source=api-prod","cve":"CVE-2025-30794","affectedVersions":"<=5.20.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/8e25914f-f2c6-4224-a2f4-0b691d1e77aa/event-tickets","title":"Event Tickets <= 4.10.7.1 - CSV Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-09-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e25914f-f2c6-4224-a2f4-0b691d1e77aa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e25914f-f2c6-4224-a2f4-0b691d1e77aa?source=api-prod","cve":"CVE-2019-16120","affectedVersions":"<=4.10.7.1","severity":"high"},{"advisoryId":"WPSECADV/WF/a6d5dcdc-f9db-4eb9-aac5-8ec79eb46bcf/event-tickets","title":"Event Tickets <= 5.11.0.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"a6d5dcdc-f9db-4eb9-aac5-8ec79eb46bcf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a6d5dcdc-f9db-4eb9-aac5-8ec79eb46bcf?source=api-prod","cve":"CVE-2024-38762","affectedVersions":"<=5.11.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/a7839847-2637-4a0d-bfc1-5f80b8433e24/event-tickets","title":"Event Tickets and Registration <= 5.8.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"a7839847-2637-4a0d-bfc1-5f80b8433e24"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a7839847-2637-4a0d-bfc1-5f80b8433e24?source=api-prod","cve":"CVE-2024-1053","affectedVersions":"<=5.8.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/c9ce2107-18bd-4331-bd8e-578f56fdebf7/event-tickets","title":"Event Tickets <= 5.2.1 - Open Redirect\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-12-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"c9ce2107-18bd-4331-bd8e-578f56fdebf7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c9ce2107-18bd-4331-bd8e-578f56fdebf7?source=api-prod","cve":"CVE-2021-25028","affectedVersions":"<=5.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/cab9eb4f-6ce6-473a-8248-85e7208c366e/event-tickets","title":"Event Tickets <= 5.26.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"cab9eb4f-6ce6-473a-8248-85e7208c366e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cab9eb4f-6ce6-473a-8248-85e7208c366e?source=api-prod","cve":"CVE-2025-62027","affectedVersions":"<=5.26.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/dbd838b6-7792-4378-8969-a70c6e16ff6a/event-tickets","title":"Event Tickets and Registration <= 5.19.1.1 - Missing Authorization to Ticket Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"dbd838b6-7792-4378-8969-a70c6e16ff6a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dbd838b6-7792-4378-8969-a70c6e16ff6a?source=api-prod","cve":"CVE-2025-1402","affectedVersions":"<=5.19.1.1","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0cc2261a-889e-40ec-8382-48de65b91b34/event-tickets","title":"Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-29 18:25:56","sources":[{"name":"Wordfence","remoteId":"0cc2261a-889e-40ec-8382-48de65b91b34"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0cc2261a-889e-40ec-8382-48de65b91b34?source=api-prod","cve":"CVE-2024-13457","affectedVersions":"<=5.18.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/21cd8cb8-2a29-4b66-ab7a-8d8b2f85e2e0/event-tickets","title":"Event Tickets and Registration <= 5.26.5 - Unauthenticated Ticket Payment Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-17 18:07:22","sources":[{"name":"Wordfence","remoteId":"21cd8cb8-2a29-4b66-ab7a-8d8b2f85e2e0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/21cd8cb8-2a29-4b66-ab7a-8d8b2f85e2e0?source=api-prod","cve":"CVE-2025-11517","affectedVersions":"<=5.26.5","severity":"high"},{"advisoryId":"WPSECADV/WF/2e42dd1c-adf7-471a-a14a-9038c56413a2/event-tickets","title":"Event Tickets and Registration <= 5.8.2 - Improper Authorization to Information Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"2e42dd1c-adf7-471a-a14a-9038c56413a2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2e42dd1c-adf7-471a-a14a-9038c56413a2?source=api-prod","cve":"CVE-2024-2261","affectedVersions":"<=5.8.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42/event-tickets","title":"Freemius SDK <= 2.4.2 - Missing Authorization Checks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"39fb0499-9ab4-4a2f-b0db-ece86bcf4d42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=api-prod","cve":"CVE-2022-4974","affectedVersions":"<5.3.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/438dfea4-21f1-4796-9c1b-81aebd8842f2/event-tickets","title":"Event Tickets and Registration <= 5.27.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"438dfea4-21f1-4796-9c1b-81aebd8842f2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/438dfea4-21f1-4796-9c1b-81aebd8842f2?source=api-prod","cve":"CVE-2026-42662","affectedVersions":"<=5.27.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/5c9d08f5-7c94-40e7-979f-023456aeb54e/event-tickets","title":"Event Tickets and Registration <= 5.8.0 Events Tickets Plus <= 5.9.0 - Authenticated (Contributor+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"5c9d08f5-7c94-40e7-979f-023456aeb54e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5c9d08f5-7c94-40e7-979f-023456aeb54e?source=api-prod","cve":"CVE-2024-1316","affectedVersions":"<=5.8.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/7849addf-cdee-4de2-9b6c-bb1c92a472fd/event-tickets","title":"Event Tickets <= 5.20.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"7849addf-cdee-4de2-9b6c-bb1c92a472fd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7849addf-cdee-4de2-9b6c-bb1c92a472fd?source=api-prod","cve":"CVE-2025-30794","affectedVersions":"<=5.20.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/8e25914f-f2c6-4224-a2f4-0b691d1e77aa/event-tickets","title":"Event Tickets <= 4.10.7.1 - CSV Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-09-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e25914f-f2c6-4224-a2f4-0b691d1e77aa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e25914f-f2c6-4224-a2f4-0b691d1e77aa?source=api-prod","cve":"CVE-2019-16120","affectedVersions":"<=4.10.7.1","severity":"high"},{"advisoryId":"WPSECADV/WF/a6d5dcdc-f9db-4eb9-aac5-8ec79eb46bcf/event-tickets","title":"Event Tickets <= 5.11.0.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"a6d5dcdc-f9db-4eb9-aac5-8ec79eb46bcf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a6d5dcdc-f9db-4eb9-aac5-8ec79eb46bcf?source=api-prod","cve":"CVE-2024-38762","affectedVersions":"<=5.11.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/a7839847-2637-4a0d-bfc1-5f80b8433e24/event-tickets","title":"Event Tickets and Registration <= 5.8.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"a7839847-2637-4a0d-bfc1-5f80b8433e24"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a7839847-2637-4a0d-bfc1-5f80b8433e24?source=api-prod","cve":"CVE-2024-1053","affectedVersions":"<=5.8.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/c9ce2107-18bd-4331-bd8e-578f56fdebf7/event-tickets","title":"Event Tickets <= 5.2.1 - Open Redirect\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-12-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"c9ce2107-18bd-4331-bd8e-578f56fdebf7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c9ce2107-18bd-4331-bd8e-578f56fdebf7?source=api-prod","cve":"CVE-2021-25028","affectedVersions":"<=5.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/cab9eb4f-6ce6-473a-8248-85e7208c366e/event-tickets","title":"Event Tickets <= 5.26.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"cab9eb4f-6ce6-473a-8248-85e7208c366e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cab9eb4f-6ce6-473a-8248-85e7208c366e?source=api-prod","cve":"CVE-2025-62027","affectedVersions":"<=5.26.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/dbd838b6-7792-4378-8969-a70c6e16ff6a/event-tickets","title":"Event Tickets and Registration <= 5.19.1.1 - Missing Authorization to Ticket Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"dbd838b6-7792-4378-8969-a70c6e16ff6a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dbd838b6-7792-4378-8969-a70c6e16ff6a?source=api-prod","cve":"CVE-2025-1402","affectedVersions":"<=5.19.1.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_657665726573742d666f726d73811c9dc5_gen.json b/internal/data/assets/plugin_657665726573742d666f726d73811c9dc5_gen.json index 71899287..31911b93 100644 --- a/internal/data/assets/plugin_657665726573742d666f726d73811c9dc5_gen.json +++ b/internal/data/assets/plugin_657665726573742d666f726d73811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0e5617a2-5670-4d98-a36b-942f71634642/everest-forms","title":"Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"0e5617a2-5670-4d98-a36b-942f71634642"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e5617a2-5670-4d98-a36b-942f71634642?source=api-prod","cve":"CVE-2025-3439","affectedVersions":"<=3.1.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/131614fa-fcaa-4105-b3ce-9926a413dd42/everest-forms","title":"Everest Forms <= 3.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"131614fa-fcaa-4105-b3ce-9926a413dd42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/131614fa-fcaa-4105-b3ce-9926a413dd42?source=api-prod","cve":"CVE-2024-8542","affectedVersions":"<=3.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2693ae37-790d-4b18-a9ec-054c8c27b8bc/everest-forms","title":"Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-07 11:35:53","sources":[{"name":"Wordfence","remoteId":"2693ae37-790d-4b18-a9ec-054c8c27b8bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2693ae37-790d-4b18-a9ec-054c8c27b8bc?source=api-prod","cve":"CVE-2026-3296","affectedVersions":"<=3.4.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/381ec612-2086-4925-98cd-652a6c2ac081/everest-forms","title":"Everest Forms <= 2.0.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"381ec612-2086-4925-98cd-652a6c2ac081"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/381ec612-2086-4925-98cd-652a6c2ac081?source=api-prod","cve":"CVE-2023-51695","affectedVersions":"<=2.0.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/3d5256ea-61ba-4b2d-90d6-714176bc19aa/everest-forms","title":"Contact Form, Drag and Drop Form Builder for WordPress – Everest Forms <= 1.4.9 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"3d5256ea-61ba-4b2d-90d6-714176bc19aa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3d5256ea-61ba-4b2d-90d6-714176bc19aa?source=api-prod","cve":"CVE-2019-13575","affectedVersions":"<1.5.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/3db1d9a0-ea68-4979-a36d-864c649f7aca/everest-forms","title":"Everest Forms <= 3.1.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"3db1d9a0-ea68-4979-a36d-864c649f7aca"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3db1d9a0-ea68-4979-a36d-864c649f7aca?source=api-prod","cve":"CVE-2025-3422","affectedVersions":"<=3.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/7f6f1c16-afd6-4c69-8988-70c6c0105748/everest-forms","title":"Everest Forms <= 3.0.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"7f6f1c16-afd6-4c69-8988-70c6c0105748"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7f6f1c16-afd6-4c69-8988-70c6c0105748?source=api-prod","cve":"CVE-2024-10471","affectedVersions":"<=3.0.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8641eb53-6a9a-4549-b8ef-e37acbcc7f03/everest-forms","title":"Everest Forms <= 3.4.4 - Unauthenticated Arbitrary File Read and Deletion via Upload Field 'old_files' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-20 07:13:38","sources":[{"name":"Wordfence","remoteId":"8641eb53-6a9a-4549-b8ef-e37acbcc7f03"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8641eb53-6a9a-4549-b8ef-e37acbcc7f03?source=api-prod","cve":"CVE-2026-5478","affectedVersions":"<=3.4.4","severity":"high"},{"advisoryId":"WPSECADV/WF/8c04d8c9-acad-4832-aa8a-8372c58a0387/everest-forms","title":"Everest Forms <= 3.0.9.4 - Unauthenticated Arbitrary File Upload, Read, and Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"8c04d8c9-acad-4832-aa8a-8372c58a0387"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c04d8c9-acad-4832-aa8a-8372c58a0387?source=api-prod","cve":"CVE-2025-1128","affectedVersions":"<=3.0.9.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/cc3d49c5-3054-4e1f-b571-6591a0b31d69/everest-forms","title":"Everest Forms <= 2.0.3 - Unauthorized Form Submission via Disabled Forms\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"cc3d49c5-3054-4e1f-b571-6591a0b31d69"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc3d49c5-3054-4e1f-b571-6591a0b31d69?source=api-prod","cve":"CVE-2023-51377","affectedVersions":"<=2.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/d4561441-d147-4c02-a837-c1656e17627d/everest-forms","title":"Everest Forms <= 2.0.7 - Unauthenticated Server-Side Request Forgery via font_url\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"d4561441-d147-4c02-a837-c1656e17627d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d4561441-d147-4c02-a837-c1656e17627d?source=api-prod","cve":"CVE-2024-1812","affectedVersions":"<=2.0.7","severity":"high"},{"advisoryId":"WPSECADV/WF/d55737a5-8aa5-4c26-bbb5-bbc5ea8be8d1/everest-forms","title":"Everest Forms <= 3.1.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"d55737a5-8aa5-4c26-bbb5-bbc5ea8be8d1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d55737a5-8aa5-4c26-bbb5-bbc5ea8be8d1?source=api-prod","cve":"CVE-2025-3421","affectedVersions":"<=3.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/db1f8575-aff7-43b3-83ed-8fd146914d0e/everest-forms","title":"Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.0.8 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"db1f8575-aff7-43b3-83ed-8fd146914d0e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/db1f8575-aff7-43b3-83ed-8fd146914d0e?source=api-prod","cve":"CVE-2024-13125","affectedVersions":"<=3.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/e5d67eb3-c399-437e-a504-2ccdda7c7882/everest-forms","title":"Everest Forms <= 1.7.9 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"e5d67eb3-c399-437e-a504-2ccdda7c7882"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e5d67eb3-c399-437e-a504-2ccdda7c7882?source=api-prod","cve":"CVE-2021-24907","affectedVersions":"<1.8.0","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0e5617a2-5670-4d98-a36b-942f71634642/everest-forms","title":"Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"0e5617a2-5670-4d98-a36b-942f71634642"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e5617a2-5670-4d98-a36b-942f71634642?source=api-prod","cve":"CVE-2025-3439","affectedVersions":"<=3.1.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/131614fa-fcaa-4105-b3ce-9926a413dd42/everest-forms","title":"Everest Forms <= 3.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"131614fa-fcaa-4105-b3ce-9926a413dd42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/131614fa-fcaa-4105-b3ce-9926a413dd42?source=api-prod","cve":"CVE-2024-8542","affectedVersions":"<=3.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2693ae37-790d-4b18-a9ec-054c8c27b8bc/everest-forms","title":"Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-07 11:35:53","sources":[{"name":"Wordfence","remoteId":"2693ae37-790d-4b18-a9ec-054c8c27b8bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2693ae37-790d-4b18-a9ec-054c8c27b8bc?source=api-prod","cve":"CVE-2026-3296","affectedVersions":"<=3.4.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/381ec612-2086-4925-98cd-652a6c2ac081/everest-forms","title":"Everest Forms <= 2.0.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"381ec612-2086-4925-98cd-652a6c2ac081"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/381ec612-2086-4925-98cd-652a6c2ac081?source=api-prod","cve":"CVE-2023-51695","affectedVersions":"<=2.0.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/3d5256ea-61ba-4b2d-90d6-714176bc19aa/everest-forms","title":"Contact Form, Drag and Drop Form Builder for WordPress – Everest Forms <= 1.4.9 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"3d5256ea-61ba-4b2d-90d6-714176bc19aa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3d5256ea-61ba-4b2d-90d6-714176bc19aa?source=api-prod","cve":"CVE-2019-13575","affectedVersions":"<1.5.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/3db1d9a0-ea68-4979-a36d-864c649f7aca/everest-forms","title":"Everest Forms <= 3.1.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"3db1d9a0-ea68-4979-a36d-864c649f7aca"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3db1d9a0-ea68-4979-a36d-864c649f7aca?source=api-prod","cve":"CVE-2025-3422","affectedVersions":"<=3.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/7f6f1c16-afd6-4c69-8988-70c6c0105748/everest-forms","title":"Everest Forms <= 3.0.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"7f6f1c16-afd6-4c69-8988-70c6c0105748"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7f6f1c16-afd6-4c69-8988-70c6c0105748?source=api-prod","cve":"CVE-2024-10471","affectedVersions":"<=3.0.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8641eb53-6a9a-4549-b8ef-e37acbcc7f03/everest-forms","title":"Everest Forms <= 3.4.4 - Unauthenticated Arbitrary File Read and Deletion via Upload Field 'old_files' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-20 07:13:38","sources":[{"name":"Wordfence","remoteId":"8641eb53-6a9a-4549-b8ef-e37acbcc7f03"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8641eb53-6a9a-4549-b8ef-e37acbcc7f03?source=api-prod","cve":"CVE-2026-5478","affectedVersions":"<=3.4.4","severity":"high"},{"advisoryId":"WPSECADV/WF/8b8c85f2-11c7-491f-9b91-0ddf4814e40d/everest-forms","title":"Everest Forms <= 3.4.1 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"8b8c85f2-11c7-491f-9b91-0ddf4814e40d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8b8c85f2-11c7-491f-9b91-0ddf4814e40d?source=api-prod","cve":"CVE-2026-22422","affectedVersions":"<=3.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8c04d8c9-acad-4832-aa8a-8372c58a0387/everest-forms","title":"Everest Forms <= 3.0.9.4 - Unauthenticated Arbitrary File Upload, Read, and Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"8c04d8c9-acad-4832-aa8a-8372c58a0387"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c04d8c9-acad-4832-aa8a-8372c58a0387?source=api-prod","cve":"CVE-2025-1128","affectedVersions":"<=3.0.9.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/cc3d49c5-3054-4e1f-b571-6591a0b31d69/everest-forms","title":"Everest Forms <= 2.0.3 - Unauthorized Form Submission via Disabled Forms\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"cc3d49c5-3054-4e1f-b571-6591a0b31d69"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc3d49c5-3054-4e1f-b571-6591a0b31d69?source=api-prod","cve":"CVE-2023-51377","affectedVersions":"<=2.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/d4561441-d147-4c02-a837-c1656e17627d/everest-forms","title":"Everest Forms <= 2.0.7 - Unauthenticated Server-Side Request Forgery via font_url\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"d4561441-d147-4c02-a837-c1656e17627d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d4561441-d147-4c02-a837-c1656e17627d?source=api-prod","cve":"CVE-2024-1812","affectedVersions":"<=2.0.7","severity":"high"},{"advisoryId":"WPSECADV/WF/d55737a5-8aa5-4c26-bbb5-bbc5ea8be8d1/everest-forms","title":"Everest Forms <= 3.1.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"d55737a5-8aa5-4c26-bbb5-bbc5ea8be8d1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d55737a5-8aa5-4c26-bbb5-bbc5ea8be8d1?source=api-prod","cve":"CVE-2025-3421","affectedVersions":"<=3.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/db1f8575-aff7-43b3-83ed-8fd146914d0e/everest-forms","title":"Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.0.8 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"db1f8575-aff7-43b3-83ed-8fd146914d0e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/db1f8575-aff7-43b3-83ed-8fd146914d0e?source=api-prod","cve":"CVE-2024-13125","affectedVersions":"<=3.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/e5d67eb3-c399-437e-a504-2ccdda7c7882/everest-forms","title":"Everest Forms <= 1.7.9 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"e5d67eb3-c399-437e-a504-2ccdda7c7882"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e5d67eb3-c399-437e-a504-2ccdda7c7882?source=api-prod","cve":"CVE-2021-24907","affectedVersions":"<1.8.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_657874656e642d6c696e6b811c9dc5_gen.json b/internal/data/assets/plugin_657874656e642d6c696e6b811c9dc5_gen.json new file mode 100644 index 00000000..ab5c484f --- /dev/null +++ b/internal/data/assets/plugin_657874656e642d6c696e6b811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/3bcb87df-5cd3-4234-ad17-c40eacabd305/extend-link","title":"Extend Link <= 2.0.0 - Authenticated (Contributor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"3bcb87df-5cd3-4234-ad17-c40eacabd305"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3bcb87df-5cd3-4234-ad17-c40eacabd305?source=api-prod","cve":"CVE-2026-25310","affectedVersions":"<=2.0.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_66617669636f6e2d726f7461746f72811c9dc5_gen.json b/internal/data/assets/plugin_66617669636f6e2d726f7461746f72811c9dc5_gen.json index 5e84511e..f644d4dd 100644 --- a/internal/data/assets/plugin_66617669636f6e2d726f7461746f72811c9dc5_gen.json +++ b/internal/data/assets/plugin_66617669636f6e2d726f7461746f72811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/4197dd30-bfd8-4d6c-80f5-b13e3844adf8/favicon-rotator","title":"Favicon Rotator <= 1.2.10 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"4197dd30-bfd8-4d6c-80f5-b13e3844adf8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4197dd30-bfd8-4d6c-80f5-b13e3844adf8?source=api-prod","cve":"CVE-2024-28001","affectedVersions":"<=1.2.10","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/32fa4d64-0cdd-4c47-aaf7-816824b27175/favicon-rotator","title":"Favicon Rotator <= 1.2.11 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"32fa4d64-0cdd-4c47-aaf7-816824b27175"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/32fa4d64-0cdd-4c47-aaf7-816824b27175?source=api-prod","cve":"CVE-2026-42649","affectedVersions":"<=1.2.11","severity":"high"},{"advisoryId":"WPSECADV/WF/4197dd30-bfd8-4d6c-80f5-b13e3844adf8/favicon-rotator","title":"Favicon Rotator <= 1.2.10 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"4197dd30-bfd8-4d6c-80f5-b13e3844adf8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4197dd30-bfd8-4d6c-80f5-b13e3844adf8?source=api-prod","cve":"CVE-2024-28001","affectedVersions":"<=1.2.10","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_66656c616e2d6672616d65776f726b811c9dc5_gen.json b/internal/data/assets/plugin_66656c616e2d6672616d65776f726b811c9dc5_gen.json index 4a1f2cc9..6583c20c 100644 --- a/internal/data/assets/plugin_66656c616e2d6672616d65776f726b811c9dc5_gen.json +++ b/internal/data/assets/plugin_66656c616e2d6672616d65776f726b811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/ab4c7656-544c-4f2f-a42f-264ac90e3b61/felan-framework","title":"Felan Framework <= 1.1.4 - Hardcoded Credentials\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-15 18:07:35","sources":[{"name":"Wordfence","remoteId":"ab4c7656-544c-4f2f-a42f-264ac90e3b61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ab4c7656-544c-4f2f-a42f-264ac90e3b61?source=api-prod","cve":"CVE-2025-10850","affectedVersions":"<=1.1.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/c53997b3-5123-4483-9f56-011cc627b7da/felan-framework","title":"Felan Framework <= 1.1.3 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"c53997b3-5123-4483-9f56-011cc627b7da"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c53997b3-5123-4483-9f56-011cc627b7da?source=api-prod","cve":"CVE-2025-23993","affectedVersions":"<=1.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/c5abd601-132a-4d8b-bfcc-afd5c6ed9947/felan-framework","title":"Felan Framework <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Activation/Deactivation via process_plugin_actions\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-15 18:07:34","sources":[{"name":"Wordfence","remoteId":"c5abd601-132a-4d8b-bfcc-afd5c6ed9947"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c5abd601-132a-4d8b-bfcc-afd5c6ed9947?source=api-prod","cve":"CVE-2025-10849","affectedVersions":"<=1.1.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/a35fb3c5-7a22-4954-9b4c-eea94fc0fcd4/felan-framework","title":"Felan Framework <= 1.1.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"a35fb3c5-7a22-4954-9b4c-eea94fc0fcd4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a35fb3c5-7a22-4954-9b4c-eea94fc0fcd4?source=api-prod","cve":"CVE-2025-23504","affectedVersions":"<=1.1.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/ab4c7656-544c-4f2f-a42f-264ac90e3b61/felan-framework","title":"Felan Framework <= 1.1.4 - Hardcoded Credentials\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-15 18:07:35","sources":[{"name":"Wordfence","remoteId":"ab4c7656-544c-4f2f-a42f-264ac90e3b61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ab4c7656-544c-4f2f-a42f-264ac90e3b61?source=api-prod","cve":"CVE-2025-10850","affectedVersions":"<=1.1.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/c53997b3-5123-4483-9f56-011cc627b7da/felan-framework","title":"Felan Framework <= 1.1.3 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"c53997b3-5123-4483-9f56-011cc627b7da"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c53997b3-5123-4483-9f56-011cc627b7da?source=api-prod","cve":"CVE-2025-23993","affectedVersions":"<=1.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/c5abd601-132a-4d8b-bfcc-afd5c6ed9947/felan-framework","title":"Felan Framework <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Activation/Deactivation via process_plugin_actions\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-15 18:07:34","sources":[{"name":"Wordfence","remoteId":"c5abd601-132a-4d8b-bfcc-afd5c6ed9947"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c5abd601-132a-4d8b-bfcc-afd5c6ed9947?source=api-prod","cve":"CVE-2025-10849","affectedVersions":"<=1.1.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_666c75656e74666f726d811c9dc5_gen.json b/internal/data/assets/plugin_666c75656e74666f726d811c9dc5_gen.json index f2d86b46..2a9f822a 100644 --- a/internal/data/assets/plugin_666c75656e74666f726d811c9dc5_gen.json +++ b/internal/data/assets/plugin_666c75656e74666f726d811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/00192a36-4b75-4dae-9a6e-0afb02ed5bad/fluentform","title":"Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-09 17:19:48","sources":[{"name":"Wordfence","remoteId":"00192a36-4b75-4dae-9a6e-0afb02ed5bad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00192a36-4b75-4dae-9a6e-0afb02ed5bad?source=api-prod","cve":"CVE-2026-0996","affectedVersions":"<=6.1.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/0348d465-f351-4c52-b293-8b3b058292b9/fluentform","title":"Fluent Forms <= 5.1.5 - Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"0348d465-f351-4c52-b293-8b3b058292b9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0348d465-f351-4c52-b293-8b3b058292b9?source=api-prod","cve":"CVE-2024-0618","affectedVersions":"<=5.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/071195d6-3452-4241-a8d3-92efc84e4850/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 19:02:43","sources":[{"name":"Wordfence","remoteId":"071195d6-3452-4241-a8d3-92efc84e4850"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/071195d6-3452-4241-a8d3-92efc84e4850?source=api-prod","cve":"CVE-2024-2771","affectedVersions":"<=5.1.16","severity":"critical"},{"advisoryId":"WPSECADV/WF/0814e7b3-404a-4db5-b564-46c9086ec048/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 19:02:45","sources":[{"name":"Wordfence","remoteId":"0814e7b3-404a-4db5-b564-46c9086ec048"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0814e7b3-404a-4db5-b564-46c9086ec048?source=api-prod","cve":"CVE-2024-2782","affectedVersions":"<=5.1.16","severity":"high"},{"advisoryId":"WPSECADV/WF/0a30d35c-9883-4b0f-83a2-494401c45d8e/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 23:27:30","sources":[{"name":"Wordfence","remoteId":"0a30d35c-9883-4b0f-83a2-494401c45d8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0a30d35c-9883-4b0f-83a2-494401c45d8e?source=api-prod","cve":"CVE-2024-6520","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/0b79a851-1212-4a9c-89fe-b5f2d50ec18c/fluentform","title":"FluentForms <= 4.3.24 - Authenticated(Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"0b79a851-1212-4a9c-89fe-b5f2d50ec18c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0b79a851-1212-4a9c-89fe-b5f2d50ec18c?source=api-prod","cve":"CVE-2023-0546","affectedVersions":"<=4.3.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/154fc656-3a33-4783-a941-10bb848244b3/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-16 00:53:13","sources":[{"name":"Wordfence","remoteId":"154fc656-3a33-4783-a941-10bb848244b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/154fc656-3a33-4783-a941-10bb848244b3?source=api-prod","cve":"CVE-2026-4160","affectedVersions":"=6.1.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/20f31e48-0dbb-498a-a400-681cacea7c9c/fluentform","title":"Contact Form for Plugin by Fluent Forms <= 5.0.8 - Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"20f31e48-0dbb-498a-a400-681cacea7c9c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/20f31e48-0dbb-498a-a400-681cacea7c9c?source=api-prod","cve":"CVE-2023-41952","affectedVersions":"<5.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ccba77c-fb90-4906-b0fe-77607ec5df1f/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 19:02:47","sources":[{"name":"Wordfence","remoteId":"2ccba77c-fb90-4906-b0fe-77607ec5df1f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ccba77c-fb90-4906-b0fe-77607ec5df1f?source=api-prod","cve":"CVE-2024-2772","affectedVersions":"<=5.1.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f/fluentform","title":"FluentForm <= 6.1.11 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f?source=api-prod","cve":"CVE-2025-69001","affectedVersions":"<=6.1.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/41c2ec31-360d-4145-b0b4-77d4d1d4b8a1/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-13 16:24:44","sources":[{"name":"Wordfence","remoteId":"41c2ec31-360d-4145-b0b4-77d4d1d4b8a1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/41c2ec31-360d-4145-b0b4-77d4d1d4b8a1?source=api-prod","cve":"CVE-2024-10646","affectedVersions":"<=5.2.6","severity":"high"},{"advisoryId":"WPSECADV/WF/4ed4dfee-5f14-47ce-abed-cd226c110665/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"4ed4dfee-5f14-47ce-abed-cd226c110665"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ed4dfee-5f14-47ce-abed-cd226c110665?source=api-prod","cve":"CVE-2024-9528","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/5fe317a6-a391-441a-aac8-c8fa57e73169/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"5fe317a6-a391-441a-aac8-c8fa57e73169"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5fe317a6-a391-441a-aac8-c8fa57e73169?source=api-prod","cve":"CVE-2024-4709","affectedVersions":"<=5.1.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 23:26:31","sources":[{"name":"Wordfence","remoteId":"66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9?source=api-prod","cve":"CVE-2024-6518","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/69dc9236-8079-434f-b2b5-060a0c5eba46/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"69dc9236-8079-434f-b2b5-060a0c5eba46"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/69dc9236-8079-434f-b2b5-060a0c5eba46?source=api-prod","cve":"CVE-2024-6703","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/8242e0f0-b9c5-46fe-b691-3275cd0f9a43/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-31 21:37:21","sources":[{"name":"Wordfence","remoteId":"8242e0f0-b9c5-46fe-b691-3275cd0f9a43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8242e0f0-b9c5-46fe-b691-3275cd0f9a43?source=api-prod","cve":"CVE-2024-5053","affectedVersions":"<=5.1.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/8def156a-f2f2-4640-a1c9-c21c74e1f308/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValues\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"8def156a-f2f2-4640-a1c9-c21c74e1f308"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8def156a-f2f2-4640-a1c9-c21c74e1f308?source=api-prod","cve":"CVE-2024-4157","affectedVersions":"<=5.1.15","severity":"high"},{"advisoryId":"WPSECADV/WF/8e039295-2ccf-450c-8f2a-d113117b9dce/fluentform","title":"WP Fluent Forms < 3.6.67 - Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-06-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e039295-2ccf-450c-8f2a-d113117b9dce"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e039295-2ccf-450c-8f2a-d113117b9dce?source=api-prod","cve":"CVE-2021-34620","affectedVersions":"<3.6.67","severity":"high"},{"advisoryId":"WPSECADV/WF/938e5d6b-1ad6-4021-a148-1d1c9e8a0a83/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-02 10:27:32","sources":[{"name":"Wordfence","remoteId":"938e5d6b-1ad6-4021-a148-1d1c9e8a0a83"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/938e5d6b-1ad6-4021-a148-1d1c9e8a0a83?source=api-prod","cve":"CVE-2025-9260","affectedVersions":">=5.1.16,<=6.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/954e7509-3ebf-429a-8c65-9825ea190d53/fluentform","title":"FluentForm <= 4.3.25 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"954e7509-3ebf-429a-8c65-9825ea190d53"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/954e7509-3ebf-429a-8c65-9825ea190d53?source=api-prod","cve":"CVE-2023-24410","affectedVersions":"<=4.3.25","severity":"high"},{"advisoryId":"WPSECADV/WF/9e6a1af3-d53c-4e23-95d2-3b799bc10827/fluentform","title":"Contact Form Plugin by FluentForm <= 4.3.12 - CSV Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"9e6a1af3-d53c-4e23-95d2-3b799bc10827"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9e6a1af3-d53c-4e23-95d2-3b799bc10827?source=api-prod","cve":"CVE-2022-3463","affectedVersions":"<=4.3.12","severity":"high"},{"advisoryId":"WPSECADV/WF/be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 23:10:10","sources":[{"name":"Wordfence","remoteId":"be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7?source=api-prod","cve":"CVE-2024-6521","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/c2aee799-4e4c-4a41-8b76-e2ad576fe2e2/fluentform","title":"Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-05 18:10:08","sources":[{"name":"Wordfence","remoteId":"c2aee799-4e4c-4a41-8b76-e2ad576fe2e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c2aee799-4e4c-4a41-8b76-e2ad576fe2e2?source=api-prod","cve":"CVE-2025-13748","affectedVersions":"<=6.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca329b94-1d4c-439c-b45a-6b39ccf3d1eb/fluentform","title":"Fluent Forms <= 5.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca329b94-1d4c-439c-b45a-6b39ccf3d1eb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca329b94-1d4c-439c-b45a-6b39ccf3d1eb?source=api-prod","cve":"CVE-2024-9651","affectedVersions":"<=5.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e06fe8e4-e27a-4492-b175-3b0846e4cf10/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-21 19:39:05","sources":[{"name":"Wordfence","remoteId":"e06fe8e4-e27a-4492-b175-3b0846e4cf10"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e06fe8e4-e27a-4492-b175-3b0846e4cf10?source=api-prod","cve":"CVE-2024-13666","affectedVersions":"<=5.2.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/f31bd18e-57d4-4c87-8a7c-a168e7e70061/fluentform","title":"Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 19:17:45","sources":[{"name":"Wordfence","remoteId":"f31bd18e-57d4-4c87-8a7c-a168e7e70061"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f31bd18e-57d4-4c87-8a7c-a168e7e70061?source=api-prod","cve":"CVE-2025-3615","affectedVersions":"<=6.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f4050403-6b8c-4023-b170-39f3cb68583e/fluentform","title":"Fluent Forms <= 5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"f4050403-6b8c-4023-b170-39f3cb68583e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f4050403-6b8c-4023-b170-39f3cb68583e?source=api-prod","cve":"CVE-2023-6957","affectedVersions":"<=5.1.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/f7dbf179-7099-4dfb-8dad-780f996a7005/fluentform","title":"Fluent Forms <= 6.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 20:40:48","sources":[{"name":"Wordfence","remoteId":"f7dbf179-7099-4dfb-8dad-780f996a7005"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f7dbf179-7099-4dfb-8dad-780f996a7005?source=api-prod","cve":"CVE-2025-13722","affectedVersions":"<=6.1.7","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/00192a36-4b75-4dae-9a6e-0afb02ed5bad/fluentform","title":"Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-09 17:19:48","sources":[{"name":"Wordfence","remoteId":"00192a36-4b75-4dae-9a6e-0afb02ed5bad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00192a36-4b75-4dae-9a6e-0afb02ed5bad?source=api-prod","cve":"CVE-2026-0996","affectedVersions":"<=6.1.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/0348d465-f351-4c52-b293-8b3b058292b9/fluentform","title":"Fluent Forms <= 5.1.5 - Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"0348d465-f351-4c52-b293-8b3b058292b9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0348d465-f351-4c52-b293-8b3b058292b9?source=api-prod","cve":"CVE-2024-0618","affectedVersions":"<=5.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/071195d6-3452-4241-a8d3-92efc84e4850/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 19:02:43","sources":[{"name":"Wordfence","remoteId":"071195d6-3452-4241-a8d3-92efc84e4850"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/071195d6-3452-4241-a8d3-92efc84e4850?source=api-prod","cve":"CVE-2024-2771","affectedVersions":"<=5.1.16","severity":"critical"},{"advisoryId":"WPSECADV/WF/0814e7b3-404a-4db5-b564-46c9086ec048/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 19:02:45","sources":[{"name":"Wordfence","remoteId":"0814e7b3-404a-4db5-b564-46c9086ec048"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0814e7b3-404a-4db5-b564-46c9086ec048?source=api-prod","cve":"CVE-2024-2782","affectedVersions":"<=5.1.16","severity":"high"},{"advisoryId":"WPSECADV/WF/0a30d35c-9883-4b0f-83a2-494401c45d8e/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 23:27:30","sources":[{"name":"Wordfence","remoteId":"0a30d35c-9883-4b0f-83a2-494401c45d8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0a30d35c-9883-4b0f-83a2-494401c45d8e?source=api-prod","cve":"CVE-2024-6520","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/0b79a851-1212-4a9c-89fe-b5f2d50ec18c/fluentform","title":"FluentForms <= 4.3.24 - Authenticated(Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"0b79a851-1212-4a9c-89fe-b5f2d50ec18c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0b79a851-1212-4a9c-89fe-b5f2d50ec18c?source=api-prod","cve":"CVE-2023-0546","affectedVersions":"<=4.3.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/154fc656-3a33-4783-a941-10bb848244b3/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-16 00:53:13","sources":[{"name":"Wordfence","remoteId":"154fc656-3a33-4783-a941-10bb848244b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/154fc656-3a33-4783-a941-10bb848244b3?source=api-prod","cve":"CVE-2026-4160","affectedVersions":"=6.1.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/20f31e48-0dbb-498a-a400-681cacea7c9c/fluentform","title":"Contact Form for Plugin by Fluent Forms <= 5.0.8 - Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"20f31e48-0dbb-498a-a400-681cacea7c9c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/20f31e48-0dbb-498a-a400-681cacea7c9c?source=api-prod","cve":"CVE-2023-41952","affectedVersions":"<5.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ccba77c-fb90-4906-b0fe-77607ec5df1f/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 19:02:47","sources":[{"name":"Wordfence","remoteId":"2ccba77c-fb90-4906-b0fe-77607ec5df1f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ccba77c-fb90-4906-b0fe-77607ec5df1f?source=api-prod","cve":"CVE-2024-2772","affectedVersions":"<=5.1.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f/fluentform","title":"FluentForm <= 6.1.11 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f?source=api-prod","cve":"CVE-2025-69001","affectedVersions":"<=6.1.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/41c2ec31-360d-4145-b0b4-77d4d1d4b8a1/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-13 16:24:44","sources":[{"name":"Wordfence","remoteId":"41c2ec31-360d-4145-b0b4-77d4d1d4b8a1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/41c2ec31-360d-4145-b0b4-77d4d1d4b8a1?source=api-prod","cve":"CVE-2024-10646","affectedVersions":"<=5.2.6","severity":"high"},{"advisoryId":"WPSECADV/WF/4ed4dfee-5f14-47ce-abed-cd226c110665/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"4ed4dfee-5f14-47ce-abed-cd226c110665"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ed4dfee-5f14-47ce-abed-cd226c110665?source=api-prod","cve":"CVE-2024-9528","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/5a85c367-99f5-4a46-94bc-ed6e6626514b/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.14 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"5a85c367-99f5-4a46-94bc-ed6e6626514b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5a85c367-99f5-4a46-94bc-ed6e6626514b?source=api-prod","cve":"CVE-2026-25313","affectedVersions":"<=6.1.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/5fe317a6-a391-441a-aac8-c8fa57e73169/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"5fe317a6-a391-441a-aac8-c8fa57e73169"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5fe317a6-a391-441a-aac8-c8fa57e73169?source=api-prod","cve":"CVE-2024-4709","affectedVersions":"<=5.1.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 23:26:31","sources":[{"name":"Wordfence","remoteId":"66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9?source=api-prod","cve":"CVE-2024-6518","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/69dc9236-8079-434f-b2b5-060a0c5eba46/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"69dc9236-8079-434f-b2b5-060a0c5eba46"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/69dc9236-8079-434f-b2b5-060a0c5eba46?source=api-prod","cve":"CVE-2024-6703","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/8242e0f0-b9c5-46fe-b691-3275cd0f9a43/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-31 21:37:21","sources":[{"name":"Wordfence","remoteId":"8242e0f0-b9c5-46fe-b691-3275cd0f9a43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8242e0f0-b9c5-46fe-b691-3275cd0f9a43?source=api-prod","cve":"CVE-2024-5053","affectedVersions":"<=5.1.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/8def156a-f2f2-4640-a1c9-c21c74e1f308/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValues\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"8def156a-f2f2-4640-a1c9-c21c74e1f308"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8def156a-f2f2-4640-a1c9-c21c74e1f308?source=api-prod","cve":"CVE-2024-4157","affectedVersions":"<=5.1.15","severity":"high"},{"advisoryId":"WPSECADV/WF/8e039295-2ccf-450c-8f2a-d113117b9dce/fluentform","title":"WP Fluent Forms < 3.6.67 - Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-06-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e039295-2ccf-450c-8f2a-d113117b9dce"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e039295-2ccf-450c-8f2a-d113117b9dce?source=api-prod","cve":"CVE-2021-34620","affectedVersions":"<3.6.67","severity":"high"},{"advisoryId":"WPSECADV/WF/938e5d6b-1ad6-4021-a148-1d1c9e8a0a83/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-02 10:27:32","sources":[{"name":"Wordfence","remoteId":"938e5d6b-1ad6-4021-a148-1d1c9e8a0a83"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/938e5d6b-1ad6-4021-a148-1d1c9e8a0a83?source=api-prod","cve":"CVE-2025-9260","affectedVersions":">=5.1.16,<=6.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/954e7509-3ebf-429a-8c65-9825ea190d53/fluentform","title":"FluentForm <= 4.3.25 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"954e7509-3ebf-429a-8c65-9825ea190d53"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/954e7509-3ebf-429a-8c65-9825ea190d53?source=api-prod","cve":"CVE-2023-24410","affectedVersions":"<=4.3.25","severity":"high"},{"advisoryId":"WPSECADV/WF/9e6a1af3-d53c-4e23-95d2-3b799bc10827/fluentform","title":"Contact Form Plugin by FluentForm <= 4.3.12 - CSV Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"9e6a1af3-d53c-4e23-95d2-3b799bc10827"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9e6a1af3-d53c-4e23-95d2-3b799bc10827?source=api-prod","cve":"CVE-2022-3463","affectedVersions":"<=4.3.12","severity":"high"},{"advisoryId":"WPSECADV/WF/be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 23:10:10","sources":[{"name":"Wordfence","remoteId":"be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7?source=api-prod","cve":"CVE-2024-6521","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/c2aee799-4e4c-4a41-8b76-e2ad576fe2e2/fluentform","title":"Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-05 18:10:08","sources":[{"name":"Wordfence","remoteId":"c2aee799-4e4c-4a41-8b76-e2ad576fe2e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c2aee799-4e4c-4a41-8b76-e2ad576fe2e2?source=api-prod","cve":"CVE-2025-13748","affectedVersions":"<=6.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca329b94-1d4c-439c-b45a-6b39ccf3d1eb/fluentform","title":"Fluent Forms <= 5.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca329b94-1d4c-439c-b45a-6b39ccf3d1eb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca329b94-1d4c-439c-b45a-6b39ccf3d1eb?source=api-prod","cve":"CVE-2024-9651","affectedVersions":"<=5.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e06fe8e4-e27a-4492-b175-3b0846e4cf10/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-21 19:39:05","sources":[{"name":"Wordfence","remoteId":"e06fe8e4-e27a-4492-b175-3b0846e4cf10"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e06fe8e4-e27a-4492-b175-3b0846e4cf10?source=api-prod","cve":"CVE-2024-13666","affectedVersions":"<=5.2.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/f31bd18e-57d4-4c87-8a7c-a168e7e70061/fluentform","title":"Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 19:17:45","sources":[{"name":"Wordfence","remoteId":"f31bd18e-57d4-4c87-8a7c-a168e7e70061"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f31bd18e-57d4-4c87-8a7c-a168e7e70061?source=api-prod","cve":"CVE-2025-3615","affectedVersions":"<=6.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f4050403-6b8c-4023-b170-39f3cb68583e/fluentform","title":"Fluent Forms <= 5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"f4050403-6b8c-4023-b170-39f3cb68583e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f4050403-6b8c-4023-b170-39f3cb68583e?source=api-prod","cve":"CVE-2023-6957","affectedVersions":"<=5.1.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/f7dbf179-7099-4dfb-8dad-780f996a7005/fluentform","title":"Fluent Forms <= 6.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 20:40:48","sources":[{"name":"Wordfence","remoteId":"f7dbf179-7099-4dfb-8dad-780f996a7005"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f7dbf179-7099-4dfb-8dad-780f996a7005?source=api-prod","cve":"CVE-2025-13722","affectedVersions":"<=6.1.7","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_666f726d2d6d616b6572811c9dc5_gen.json b/internal/data/assets/plugin_666f726d2d6d616b6572811c9dc5_gen.json index 88f6bf07..c9788b7e 100644 --- a/internal/data/assets/plugin_666f726d2d6d616b6572811c9dc5_gen.json +++ b/internal/data/assets/plugin_666f726d2d6d616b6572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0506f360-17c3-4cc8-9ac7-988c056c3caf/form-maker","title":"Form Maker <= 1.15.5 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"0506f360-17c3-4cc8-9ac7-988c056c3caf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0506f360-17c3-4cc8-9ac7-988c056c3caf?source=api-prod","cve":"CVE-2022-3300","affectedVersions":"<=1.15.5","severity":"high"},{"advisoryId":"WPSECADV/WF/05b434f7-6bce-4ad0-bd12-db5b01f14953/form-maker","title":"Form Maker by 10Web <= 1.15.18 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"05b434f7-6bce-4ad0-bd12-db5b01f14953"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/05b434f7-6bce-4ad0-bd12-db5b01f14953?source=api-prod","cve":"CVE-2023-45071","affectedVersions":"<=1.15.18","severity":"high"},{"advisoryId":"WPSECADV/WF/05d063e3-4863-4dd5-9219-6240b9b3f939/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.38 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"05d063e3-4863-4dd5-9219-6240b9b3f939"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/05d063e3-4863-4dd5-9219-6240b9b3f939?source=api-prod","cve":"CVE-2026-39502","affectedVersions":"<=1.15.38","severity":"high"},{"advisoryId":"WPSECADV/WF/0fb1a2c2-581d-47ed-a180-9f70fdf79066/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 - Reflected Cross-Site Scripting via add_query_arg Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-10 00:07:43","sources":[{"name":"Wordfence","remoteId":"0fb1a2c2-581d-47ed-a180-9f70fdf79066"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0fb1a2c2-581d-47ed-a180-9f70fdf79066?source=api-prod","cve":"CVE-2024-10265","affectedVersions":"<=1.15.30","severity":"medium"},{"advisoryId":"WPSECADV/WF/197449f5-9304-49df-9261-a354145fc00e/form-maker","title":"Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-13 13:52:02","sources":[{"name":"Wordfence","remoteId":"197449f5-9304-49df-9261-a354145fc00e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/197449f5-9304-49df-9261-a354145fc00e?source=api-prod","cve":"CVE-2026-4388","affectedVersions":"<=1.15.40","severity":"high"},{"advisoryId":"WPSECADV/WF/1b1db6b8-f005-488f-b2cc-667acc700b0a/form-maker","title":"Form Maker by 10Web <= 1.15.18 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"1b1db6b8-f005-488f-b2cc-667acc700b0a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b1db6b8-f005-488f-b2cc-667acc700b0a?source=api-prod","cve":"CVE-2023-45070","affectedVersions":"<=1.15.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/1c33c193-618d-4e36-bb36-350cac6e2948/form-maker","title":"Form Maker by 10Web <= 1.15.32 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c33c193-618d-4e36-bb36-350cac6e2948"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c33c193-618d-4e36-bb36-350cac6e2948?source=api-prod","cve":"CVE-2024-13605","affectedVersions":"<=1.15.32","severity":"medium"},{"advisoryId":"WPSECADV/WF/2b32cc12-c8d5-40b8-9510-42699beec581/form-maker","title":"Form Maker <= 1.15.27 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-25 23:14:51","sources":[{"name":"Wordfence","remoteId":"2b32cc12-c8d5-40b8-9510-42699beec581"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b32cc12-c8d5-40b8-9510-42699beec581?source=api-prod","cve":"CVE-2024-8633","affectedVersions":"<=1.15.27","severity":"medium"},{"advisoryId":"WPSECADV/WF/3c3091eb-a2e7-4fc2-9f5c-5d6d582bbb89/form-maker","title":"Form Maker <= 1.13.59 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"3c3091eb-a2e7-4fc2-9f5c-5d6d582bbb89"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3c3091eb-a2e7-4fc2-9f5c-5d6d582bbb89?source=api-prod","cve":"CVE-2021-24526","affectedVersions":"<=1.13.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/3c547a2b-98fb-4936-88a5-31e5c879a364/form-maker","title":"Form Maker <= 1.14.11 - Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-05-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"3c547a2b-98fb-4936-88a5-31e5c879a364"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3c547a2b-98fb-4936-88a5-31e5c879a364?source=api-prod","cve":"CVE-2022-1564","affectedVersions":"<=1.14.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/46525a06-f3a4-4c78-ba32-4b937e1dbac6/form-maker","title":"Form Maker <= 1.15.20 - Captcha Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"46525a06-f3a4-4c78-ba32-4b937e1dbac6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/46525a06-f3a4-4c78-ba32-4b937e1dbac6?source=api-prod","cve":"CVE-2023-48290","affectedVersions":"<1.15.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/46e64a82-4d3f-4887-9c03-3285a6ddefb7/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder < 1.15.38 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"46e64a82-4d3f-4887-9c03-3285a6ddefb7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/46e64a82-4d3f-4887-9c03-3285a6ddefb7?source=api-prod","cve":"CVE-2025-15441","affectedVersions":"<1.15.38","severity":"high"},{"advisoryId":"WPSECADV/WF/5652f9c3-3cc9-4541-8209-40117b4d25d9/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"5652f9c3-3cc9-4541-8209-40117b4d25d9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5652f9c3-3cc9-4541-8209-40117b4d25d9?source=api-prod","cve":"CVE-2024-2112","affectedVersions":"<=1.15.22","severity":"medium"},{"advisoryId":"WPSECADV/WF/59c1b745-7559-4b80-9118-152ee2340c47/form-maker","title":"Form Maker by 10Web <= 1.13.4 - Cross-Site Request Forgery to Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"59c1b745-7559-4b80-9118-152ee2340c47"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/59c1b745-7559-4b80-9118-152ee2340c47?source=api-prod","cve":"CVE-2019-11590","affectedVersions":"<=1.13.4","severity":"high"},{"advisoryId":"WPSECADV/WF/5e383b8a-27e5-4b35-8d11-6e4102255d44/form-maker","title":"Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-16 15:04:04","sources":[{"name":"Wordfence","remoteId":"5e383b8a-27e5-4b35-8d11-6e4102255d44"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5e383b8a-27e5-4b35-8d11-6e4102255d44?source=api-prod","cve":"CVE-2026-3330","affectedVersions":"<=1.15.40","severity":"medium"},{"advisoryId":"WPSECADV/WF/7317d716-39e0-40d6-92a8-e59bd8470e5d/form-maker","title":"Form Maker by 10Web <= 1.12.21 - CSV Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-04-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"7317d716-39e0-40d6-92a8-e59bd8470e5d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7317d716-39e0-40d6-92a8-e59bd8470e5d?source=api-prod","cve":"CVE-2018-10504","affectedVersions":"<1.12.22","severity":"high"},{"advisoryId":"WPSECADV/WF/7350bb9f-8c75-4292-9769-bccb3805292e/form-maker","title":"Form Maker by 10Web <= 1.15.29 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"7350bb9f-8c75-4292-9769-bccb3805292e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7350bb9f-8c75-4292-9769-bccb3805292e?source=api-prod","cve":"CVE-2024-10560","affectedVersions":"<=1.15.29","severity":"medium"},{"advisoryId":"WPSECADV/WF/7f0eac1e-4988-4b73-bf13-c959b0dc11e2/form-maker","title":"Form Maker <= 1.15.16 - Missing Authorization in check_score\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"7f0eac1e-4988-4b73-bf13-c959b0dc11e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7f0eac1e-4988-4b73-bf13-c959b0dc11e2?source=api-prod","affectedVersions":"<=1.15.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/8230d5f8-01d9-465a-8a43-e9852248bb3d/form-maker","title":"Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-02 18:12:37","sources":[{"name":"Wordfence","remoteId":"8230d5f8-01d9-465a-8a43-e9852248bb3d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8230d5f8-01d9-465a-8a43-e9852248bb3d?source=api-prod","cve":"CVE-2026-1065","affectedVersions":"<=1.15.35","severity":"high"},{"advisoryId":"WPSECADV/WF/8921ea7f-5e27-4f05-b338-1c16366a8c8e/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.23 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"8921ea7f-5e27-4f05-b338-1c16366a8c8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8921ea7f-5e27-4f05-b338-1c16366a8c8e?source=api-prod","cve":"CVE-2024-32534","affectedVersions":"<=1.15.23","severity":"medium"},{"advisoryId":"WPSECADV/WF/9347dafb-1789-4855-b09e-2a1ef5f7f2c1/form-maker","title":"Form Maker by 10Web <= 1.13.35 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-05-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"9347dafb-1789-4855-b09e-2a1ef5f7f2c1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9347dafb-1789-4855-b09e-2a1ef5f7f2c1?source=api-prod","affectedVersions":"<=1.13.35","severity":"high"},{"advisoryId":"WPSECADV/WF/93ff1634-d520-4895-8822-2dbfa7b5e030/form-maker","title":"Form Maker by 10Web <= 1.13.2 - Authenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-05-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"93ff1634-d520-4895-8822-2dbfa7b5e030"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/93ff1634-d520-4895-8822-2dbfa7b5e030?source=api-prod","cve":"CVE-2019-10866","affectedVersions":"<1.13.3","severity":"high"},{"advisoryId":"WPSECADV/WF/95737062-587a-447c-b448-06dc2d22dbdf/form-maker","title":"Form Maker by 10Web <= 1.15.32 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"95737062-587a-447c-b448-06dc2d22dbdf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/95737062-587a-447c-b448-06dc2d22dbdf?source=api-prod","cve":"CVE-2024-13053","affectedVersions":"<=1.15.32","severity":"medium"},{"advisoryId":"WPSECADV/WF/a0f877c3-cb51-4b82-ae7a-a30c90d593f7/form-maker","title":"Form Maker by 10Web <= 1.15.33 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"a0f877c3-cb51-4b82-ae7a-a30c90d593f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a0f877c3-cb51-4b82-ae7a-a30c90d593f7?source=api-prod","cve":"CVE-2025-48341","affectedVersions":"<=1.15.33","severity":"medium"},{"advisoryId":"WPSECADV/WF/aa19eb88-b47a-4438-accf-d98241b927af/form-maker","title":"Form Maker by 10Web <= 1.15.29 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"aa19eb88-b47a-4438-accf-d98241b927af"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa19eb88-b47a-4438-accf-d98241b927af?source=api-prod","cve":"CVE-2024-10558","affectedVersions":"<=1.15.29","severity":"medium"},{"advisoryId":"WPSECADV/WF/ad8311d4-b07d-4e74-ab14-69faa3e409c8/form-maker","title":"Form Maker by 10Web <= 1.15.26 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad8311d4-b07d-4e74-ab14-69faa3e409c8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad8311d4-b07d-4e74-ab14-69faa3e409c8?source=api-prod","cve":"CVE-2024-43220","affectedVersions":"<=1.15.26","severity":"medium"},{"advisoryId":"WPSECADV/WF/af1075a5-9efa-4b86-9798-6dbafcba4db5/form-maker","title":"Form Maker by 10Web <= 1.15.24 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"af1075a5-9efa-4b86-9798-6dbafcba4db5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af1075a5-9efa-4b86-9798-6dbafcba4db5?source=api-prod","cve":"CVE-2024-2258","affectedVersions":"<=1.15.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/afb5206a-9019-4de4-89b4-adffd11d1466/form-maker","title":"Form Maker by 10Web <= 1.15.30 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"afb5206a-9019-4de4-89b4-adffd11d1466"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/afb5206a-9019-4de4-89b4-adffd11d1466?source=api-prod","cve":"CVE-2024-10562","affectedVersions":"<=1.15.30","severity":"medium"},{"advisoryId":"WPSECADV/WF/c691d129-35db-4de8-a28e-5e77347e2280/form-maker","title":"Form Maker by 10Web <= 1.15.19 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"c691d129-35db-4de8-a28e-5e77347e2280"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c691d129-35db-4de8-a28e-5e77347e2280?source=api-prod","cve":"CVE-2023-4666","affectedVersions":"<1.15.20","severity":"critical"},{"advisoryId":"WPSECADV/WF/ca1316be-1978-46c1-8685-10a8d4c34bdb/form-maker","title":"Form Maker by 10Web <= 1.15.31 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca1316be-1978-46c1-8685-10a8d4c34bdb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca1316be-1978-46c1-8685-10a8d4c34bdb?source=api-prod","cve":"CVE-2024-10680","affectedVersions":"<=1.15.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/d55c832b-f558-4e8a-8301-33dd38d39ef1/form-maker","title":"Form-Maker (twb_form-maker) <= 1.15.21 - Cross-Site Request Forgery to Limited Code Execution via Execute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"d55c832b-f558-4e8a-8301-33dd38d39ef1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d55c832b-f558-4e8a-8301-33dd38d39ef1?source=api-prod","cve":"CVE-2024-0667","affectedVersions":"<=1.15.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/d713ff91-30ba-474d-87ca-39b15c77b30a/form-maker","title":"Form Maker by 10Web <= 1.15.24 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"d713ff91-30ba-474d-87ca-39b15c77b30a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d713ff91-30ba-474d-87ca-39b15c77b30a?source=api-prod","cve":"CVE-2024-34437","affectedVersions":"<=1.15.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/d99d4b9a-aa09-434d-91a8-7afaa0e8b5db/form-maker","title":"Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"d99d4b9a-aa09-434d-91a8-7afaa0e8b5db"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d99d4b9a-aa09-434d-91a8-7afaa0e8b5db?source=api-prod","cve":"CVE-2024-5020","affectedVersions":"<=1.15.27","severity":"medium"},{"advisoryId":"WPSECADV/WF/e0ec0027-2792-4069-b413-8fdd951f5fe7/form-maker","title":"Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-02 18:21:06","sources":[{"name":"Wordfence","remoteId":"e0ec0027-2792-4069-b413-8fdd951f5fe7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e0ec0027-2792-4069-b413-8fdd951f5fe7?source=api-prod","cve":"CVE-2026-1058","affectedVersions":"<=1.15.35","severity":"high"},{"advisoryId":"WPSECADV/WF/f2a59015-eb29-44fe-bc21-ba8832ac750b/form-maker","title":"Form Maker by 10Web < 1.13.40 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"f2a59015-eb29-44fe-bc21-ba8832ac750b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2a59015-eb29-44fe-bc21-ba8832ac750b?source=api-prod","affectedVersions":"<1.13.40","severity":"medium"},{"advisoryId":"WPSECADV/WF/fd683a80-2090-4f9b-8342-7cc76675067e/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.25 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd683a80-2090-4f9b-8342-7cc76675067e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd683a80-2090-4f9b-8342-7cc76675067e?source=api-prod","cve":"CVE-2024-6130","affectedVersions":"<=1.15.25","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0506f360-17c3-4cc8-9ac7-988c056c3caf/form-maker","title":"Form Maker <= 1.15.5 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"0506f360-17c3-4cc8-9ac7-988c056c3caf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0506f360-17c3-4cc8-9ac7-988c056c3caf?source=api-prod","cve":"CVE-2022-3300","affectedVersions":"<=1.15.5","severity":"high"},{"advisoryId":"WPSECADV/WF/05b434f7-6bce-4ad0-bd12-db5b01f14953/form-maker","title":"Form Maker by 10Web <= 1.15.18 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"05b434f7-6bce-4ad0-bd12-db5b01f14953"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/05b434f7-6bce-4ad0-bd12-db5b01f14953?source=api-prod","cve":"CVE-2023-45071","affectedVersions":"<=1.15.18","severity":"high"},{"advisoryId":"WPSECADV/WF/05d063e3-4863-4dd5-9219-6240b9b3f939/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.38 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"05d063e3-4863-4dd5-9219-6240b9b3f939"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/05d063e3-4863-4dd5-9219-6240b9b3f939?source=api-prod","cve":"CVE-2026-39502","affectedVersions":"<=1.15.38","severity":"high"},{"advisoryId":"WPSECADV/WF/0fb1a2c2-581d-47ed-a180-9f70fdf79066/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 - Reflected Cross-Site Scripting via add_query_arg Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-10 00:07:43","sources":[{"name":"Wordfence","remoteId":"0fb1a2c2-581d-47ed-a180-9f70fdf79066"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0fb1a2c2-581d-47ed-a180-9f70fdf79066?source=api-prod","cve":"CVE-2024-10265","affectedVersions":"<=1.15.30","severity":"medium"},{"advisoryId":"WPSECADV/WF/197449f5-9304-49df-9261-a354145fc00e/form-maker","title":"Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-13 13:52:02","sources":[{"name":"Wordfence","remoteId":"197449f5-9304-49df-9261-a354145fc00e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/197449f5-9304-49df-9261-a354145fc00e?source=api-prod","cve":"CVE-2026-4388","affectedVersions":"<=1.15.40","severity":"high"},{"advisoryId":"WPSECADV/WF/1b1db6b8-f005-488f-b2cc-667acc700b0a/form-maker","title":"Form Maker by 10Web <= 1.15.18 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"1b1db6b8-f005-488f-b2cc-667acc700b0a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b1db6b8-f005-488f-b2cc-667acc700b0a?source=api-prod","cve":"CVE-2023-45070","affectedVersions":"<=1.15.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/1c33c193-618d-4e36-bb36-350cac6e2948/form-maker","title":"Form Maker by 10Web <= 1.15.32 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c33c193-618d-4e36-bb36-350cac6e2948"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c33c193-618d-4e36-bb36-350cac6e2948?source=api-prod","cve":"CVE-2024-13605","affectedVersions":"<=1.15.32","severity":"medium"},{"advisoryId":"WPSECADV/WF/2b32cc12-c8d5-40b8-9510-42699beec581/form-maker","title":"Form Maker <= 1.15.27 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-25 23:14:51","sources":[{"name":"Wordfence","remoteId":"2b32cc12-c8d5-40b8-9510-42699beec581"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b32cc12-c8d5-40b8-9510-42699beec581?source=api-prod","cve":"CVE-2024-8633","affectedVersions":"<=1.15.27","severity":"medium"},{"advisoryId":"WPSECADV/WF/3c3091eb-a2e7-4fc2-9f5c-5d6d582bbb89/form-maker","title":"Form Maker <= 1.13.59 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"3c3091eb-a2e7-4fc2-9f5c-5d6d582bbb89"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3c3091eb-a2e7-4fc2-9f5c-5d6d582bbb89?source=api-prod","cve":"CVE-2021-24526","affectedVersions":"<=1.13.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/3c547a2b-98fb-4936-88a5-31e5c879a364/form-maker","title":"Form Maker <= 1.14.11 - Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-05-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"3c547a2b-98fb-4936-88a5-31e5c879a364"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3c547a2b-98fb-4936-88a5-31e5c879a364?source=api-prod","cve":"CVE-2022-1564","affectedVersions":"<=1.14.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/46525a06-f3a4-4c78-ba32-4b937e1dbac6/form-maker","title":"Form Maker <= 1.15.20 - Captcha Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"46525a06-f3a4-4c78-ba32-4b937e1dbac6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/46525a06-f3a4-4c78-ba32-4b937e1dbac6?source=api-prod","cve":"CVE-2023-48290","affectedVersions":"<1.15.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/46e64a82-4d3f-4887-9c03-3285a6ddefb7/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder < 1.15.38 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"46e64a82-4d3f-4887-9c03-3285a6ddefb7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/46e64a82-4d3f-4887-9c03-3285a6ddefb7?source=api-prod","cve":"CVE-2025-15441","affectedVersions":"<1.15.38","severity":"high"},{"advisoryId":"WPSECADV/WF/5652f9c3-3cc9-4541-8209-40117b4d25d9/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"5652f9c3-3cc9-4541-8209-40117b4d25d9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5652f9c3-3cc9-4541-8209-40117b4d25d9?source=api-prod","cve":"CVE-2024-2112","affectedVersions":"<=1.15.22","severity":"medium"},{"advisoryId":"WPSECADV/WF/59c1b745-7559-4b80-9118-152ee2340c47/form-maker","title":"Form Maker by 10Web <= 1.13.4 - Cross-Site Request Forgery to Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"59c1b745-7559-4b80-9118-152ee2340c47"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/59c1b745-7559-4b80-9118-152ee2340c47?source=api-prod","cve":"CVE-2019-11590","affectedVersions":"<=1.13.4","severity":"high"},{"advisoryId":"WPSECADV/WF/5e383b8a-27e5-4b35-8d11-6e4102255d44/form-maker","title":"Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-16 15:04:04","sources":[{"name":"Wordfence","remoteId":"5e383b8a-27e5-4b35-8d11-6e4102255d44"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5e383b8a-27e5-4b35-8d11-6e4102255d44?source=api-prod","cve":"CVE-2026-3330","affectedVersions":"<=1.15.40","severity":"medium"},{"advisoryId":"WPSECADV/WF/7317d716-39e0-40d6-92a8-e59bd8470e5d/form-maker","title":"Form Maker by 10Web <= 1.12.21 - CSV Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-04-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"7317d716-39e0-40d6-92a8-e59bd8470e5d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7317d716-39e0-40d6-92a8-e59bd8470e5d?source=api-prod","cve":"CVE-2018-10504","affectedVersions":"<1.12.22","severity":"high"},{"advisoryId":"WPSECADV/WF/7350bb9f-8c75-4292-9769-bccb3805292e/form-maker","title":"Form Maker by 10Web <= 1.15.29 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"7350bb9f-8c75-4292-9769-bccb3805292e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7350bb9f-8c75-4292-9769-bccb3805292e?source=api-prod","cve":"CVE-2024-10560","affectedVersions":"<=1.15.29","severity":"medium"},{"advisoryId":"WPSECADV/WF/7f0eac1e-4988-4b73-bf13-c959b0dc11e2/form-maker","title":"Form Maker <= 1.15.16 - Missing Authorization in check_score\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"7f0eac1e-4988-4b73-bf13-c959b0dc11e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7f0eac1e-4988-4b73-bf13-c959b0dc11e2?source=api-prod","affectedVersions":"<=1.15.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/8230d5f8-01d9-465a-8a43-e9852248bb3d/form-maker","title":"Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-02 18:12:37","sources":[{"name":"Wordfence","remoteId":"8230d5f8-01d9-465a-8a43-e9852248bb3d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8230d5f8-01d9-465a-8a43-e9852248bb3d?source=api-prod","cve":"CVE-2026-1065","affectedVersions":"<=1.15.35","severity":"high"},{"advisoryId":"WPSECADV/WF/8921ea7f-5e27-4f05-b338-1c16366a8c8e/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.23 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"8921ea7f-5e27-4f05-b338-1c16366a8c8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8921ea7f-5e27-4f05-b338-1c16366a8c8e?source=api-prod","cve":"CVE-2024-32534","affectedVersions":"<=1.15.23","severity":"medium"},{"advisoryId":"WPSECADV/WF/9347dafb-1789-4855-b09e-2a1ef5f7f2c1/form-maker","title":"Form Maker by 10Web <= 1.13.35 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-05-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"9347dafb-1789-4855-b09e-2a1ef5f7f2c1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9347dafb-1789-4855-b09e-2a1ef5f7f2c1?source=api-prod","affectedVersions":"<=1.13.35","severity":"high"},{"advisoryId":"WPSECADV/WF/93ff1634-d520-4895-8822-2dbfa7b5e030/form-maker","title":"Form Maker by 10Web <= 1.13.2 - Authenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-05-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"93ff1634-d520-4895-8822-2dbfa7b5e030"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/93ff1634-d520-4895-8822-2dbfa7b5e030?source=api-prod","cve":"CVE-2019-10866","affectedVersions":"<1.13.3","severity":"high"},{"advisoryId":"WPSECADV/WF/95737062-587a-447c-b448-06dc2d22dbdf/form-maker","title":"Form Maker by 10Web <= 1.15.32 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"95737062-587a-447c-b448-06dc2d22dbdf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/95737062-587a-447c-b448-06dc2d22dbdf?source=api-prod","cve":"CVE-2024-13053","affectedVersions":"<=1.15.32","severity":"medium"},{"advisoryId":"WPSECADV/WF/a0f877c3-cb51-4b82-ae7a-a30c90d593f7/form-maker","title":"Form Maker by 10Web <= 1.15.33 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"a0f877c3-cb51-4b82-ae7a-a30c90d593f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a0f877c3-cb51-4b82-ae7a-a30c90d593f7?source=api-prod","cve":"CVE-2025-48341","affectedVersions":"<=1.15.33","severity":"medium"},{"advisoryId":"WPSECADV/WF/aa19eb88-b47a-4438-accf-d98241b927af/form-maker","title":"Form Maker by 10Web <= 1.15.29 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"aa19eb88-b47a-4438-accf-d98241b927af"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa19eb88-b47a-4438-accf-d98241b927af?source=api-prod","cve":"CVE-2024-10558","affectedVersions":"<=1.15.29","severity":"medium"},{"advisoryId":"WPSECADV/WF/ad8311d4-b07d-4e74-ab14-69faa3e409c8/form-maker","title":"Form Maker by 10Web <= 1.15.26 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad8311d4-b07d-4e74-ab14-69faa3e409c8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad8311d4-b07d-4e74-ab14-69faa3e409c8?source=api-prod","cve":"CVE-2024-43220","affectedVersions":"<=1.15.26","severity":"medium"},{"advisoryId":"WPSECADV/WF/af1075a5-9efa-4b86-9798-6dbafcba4db5/form-maker","title":"Form Maker by 10Web <= 1.15.24 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"af1075a5-9efa-4b86-9798-6dbafcba4db5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af1075a5-9efa-4b86-9798-6dbafcba4db5?source=api-prod","cve":"CVE-2024-2258","affectedVersions":"<=1.15.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/afb5206a-9019-4de4-89b4-adffd11d1466/form-maker","title":"Form Maker by 10Web <= 1.15.30 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"afb5206a-9019-4de4-89b4-adffd11d1466"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/afb5206a-9019-4de4-89b4-adffd11d1466?source=api-prod","cve":"CVE-2024-10562","affectedVersions":"<=1.15.30","severity":"medium"},{"advisoryId":"WPSECADV/WF/c691d129-35db-4de8-a28e-5e77347e2280/form-maker","title":"Form Maker by 10Web <= 1.15.19 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"c691d129-35db-4de8-a28e-5e77347e2280"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c691d129-35db-4de8-a28e-5e77347e2280?source=api-prod","cve":"CVE-2023-4666","affectedVersions":"<1.15.20","severity":"critical"},{"advisoryId":"WPSECADV/WF/ca1316be-1978-46c1-8685-10a8d4c34bdb/form-maker","title":"Form Maker by 10Web <= 1.15.31 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca1316be-1978-46c1-8685-10a8d4c34bdb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca1316be-1978-46c1-8685-10a8d4c34bdb?source=api-prod","cve":"CVE-2024-10680","affectedVersions":"<=1.15.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/d55c832b-f558-4e8a-8301-33dd38d39ef1/form-maker","title":"Form-Maker (twb_form-maker) <= 1.15.21 - Cross-Site Request Forgery to Limited Code Execution via Execute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"d55c832b-f558-4e8a-8301-33dd38d39ef1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d55c832b-f558-4e8a-8301-33dd38d39ef1?source=api-prod","cve":"CVE-2024-0667","affectedVersions":"<=1.15.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/d713ff91-30ba-474d-87ca-39b15c77b30a/form-maker","title":"Form Maker by 10Web <= 1.15.24 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"d713ff91-30ba-474d-87ca-39b15c77b30a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d713ff91-30ba-474d-87ca-39b15c77b30a?source=api-prod","cve":"CVE-2024-34437","affectedVersions":"<=1.15.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/d99d4b9a-aa09-434d-91a8-7afaa0e8b5db/form-maker","title":"Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"d99d4b9a-aa09-434d-91a8-7afaa0e8b5db"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d99d4b9a-aa09-434d-91a8-7afaa0e8b5db?source=api-prod","cve":"CVE-2024-5020","affectedVersions":"<=1.15.27","severity":"medium"},{"advisoryId":"WPSECADV/WF/e0ec0027-2792-4069-b413-8fdd951f5fe7/form-maker","title":"Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-02 18:21:06","sources":[{"name":"Wordfence","remoteId":"e0ec0027-2792-4069-b413-8fdd951f5fe7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e0ec0027-2792-4069-b413-8fdd951f5fe7?source=api-prod","cve":"CVE-2026-1058","affectedVersions":"<=1.15.35","severity":"high"},{"advisoryId":"WPSECADV/WF/f2a59015-eb29-44fe-bc21-ba8832ac750b/form-maker","title":"Form Maker by 10Web < 1.13.40 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"f2a59015-eb29-44fe-bc21-ba8832ac750b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2a59015-eb29-44fe-bc21-ba8832ac750b?source=api-prod","affectedVersions":"<1.13.40","severity":"medium"},{"advisoryId":"WPSECADV/WF/f37cc880-d8a4-431a-9639-abf01163030a/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 18:43:52","sources":[{"name":"Wordfence","remoteId":"f37cc880-d8a4-431a-9639-abf01163030a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f37cc880-d8a4-431a-9639-abf01163030a?source=api-prod","cve":"CVE-2026-3359","affectedVersions":"<=1.15.42","severity":"high"},{"advisoryId":"WPSECADV/WF/fd683a80-2090-4f9b-8342-7cc76675067e/form-maker","title":"Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.25 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd683a80-2090-4f9b-8342-7cc76675067e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd683a80-2090-4f9b-8342-7cc76675067e?source=api-prod","cve":"CVE-2024-6130","affectedVersions":"<=1.15.25","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_666f726d696e61746f72811c9dc5_gen.json b/internal/data/assets/plugin_666f726d696e61746f72811c9dc5_gen.json index 312fc256..411deb25 100644 --- a/internal/data/assets/plugin_666f726d696e61746f72811c9dc5_gen.json +++ b/internal/data/assets/plugin_666f726d696e61746f72811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/00272fe2-52aa-4183-8b57-6b51ad57c657/forminator","title":"Forminator <= 1.24.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"00272fe2-52aa-4183-8b57-6b51ad57c657"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00272fe2-52aa-4183-8b57-6b51ad57c657?source=api-prod","cve":"CVE-2023-3134","affectedVersions":"<=1.24.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/0d04b822-a48a-485e-b9b5-f5a213307c71/forminator","title":"Forminator <= 1.29.1 - HubSpot Developer API Key Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d04b822-a48a-485e-b9b5-f5a213307c71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d04b822-a48a-485e-b9b5-f5a213307c71?source=api-prod","cve":"CVE-2024-7389","affectedVersions":"<=1.29.1","severity":"high"},{"advisoryId":"WPSECADV/WF/13cfa202-ab90-46c0-ab53-00995bfdcaa3/forminator","title":"Forminator <= 1.27.0 - Authenticated (Administrator+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"13cfa202-ab90-46c0-ab53-00995bfdcaa3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/13cfa202-ab90-46c0-ab53-00995bfdcaa3?source=api-prod","cve":"CVE-2023-6133","affectedVersions":"<=1.27.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/14043276-ba0a-4862-a1a7-00b4c372c5bc/forminator","title":"Forminator <= 1.39.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-26 16:21:30","sources":[{"name":"Wordfence","remoteId":"14043276-ba0a-4862-a1a7-00b4c372c5bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/14043276-ba0a-4862-a1a7-00b4c372c5bc?source=api-prod","cve":"CVE-2025-0469","affectedVersions":"=1.39.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/19439622-6396-4f10-ab71-aa243b6812fa/forminator","title":"Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.29.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"19439622-6396-4f10-ab71-aa243b6812fa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/19439622-6396-4f10-ab71-aa243b6812fa?source=api-prod","cve":"CVE-2024-3053","affectedVersions":"<=1.29.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/1a6fbb60-811a-4763-b301-694bc8d387e7/forminator","title":"Forminator <= 1.29.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"1a6fbb60-811a-4763-b301-694bc8d387e7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1a6fbb60-811a-4763-b301-694bc8d387e7?source=api-prod","cve":"CVE-2024-29777","affectedVersions":"<=1.29.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/224233bc-68f3-40e4-8182-4831ccce93fb/forminator","title":"Forminator <= 1.29.2 - Authenticated (Admin+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"224233bc-68f3-40e4-8182-4831ccce93fb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/224233bc-68f3-40e4-8182-4831ccce93fb?source=api-prod","cve":"CVE-2024-31077","affectedVersions":"<=1.29.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/2283b147-b904-4086-8cb1-6d8969ccbaf6/forminator","title":"Forminator <= 1.50.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"2283b147-b904-4086-8cb1-6d8969ccbaf6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2283b147-b904-4086-8cb1-6d8969ccbaf6?source=api-prod","cve":"CVE-2026-32409","affectedVersions":"<=1.50.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/23feb72c-7e6f-436b-b56e-dc6185302d31/forminator","title":"Forminator <= 1.29.0 - Unauthenticated Stored Cross-Site Scripting via File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"23feb72c-7e6f-436b-b56e-dc6185302d31"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/23feb72c-7e6f-436b-b56e-dc6185302d31?source=api-prod","cve":"CVE-2024-1794","affectedVersions":"<=1.29.0","severity":"high"},{"advisoryId":"WPSECADV/WF/286df83a-d723-4443-b265-f91cf5abb385/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.38.2 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"286df83a-d723-4443-b265-f91cf5abb385"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/286df83a-d723-4443-b265-f91cf5abb385?source=api-prod","cve":"CVE-2024-7052","affectedVersions":"<=1.38.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/2b28ddeb-44f5-4d19-b866-94fc2088ee6d/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.49.1 - Missing Authorization to Authenticated (Forminator User+) CSV Export\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 17:47:08","sources":[{"name":"Wordfence","remoteId":"2b28ddeb-44f5-4d19-b866-94fc2088ee6d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b28ddeb-44f5-4d19-b866-94fc2088ee6d?source=api-prod","cve":"CVE-2025-14782","affectedVersions":"<=1.49.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ef15cb1-b320-42d9-a2fd-afff2ec8a93b/forminator","title":"Forminator <= 1.22.1 - Missing Authorization on 'load_hcaptcha_preview' AJAX function\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"2ef15cb1-b320-42d9-a2fd-afff2ec8a93b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ef15cb1-b320-42d9-a2fd-afff2ec8a93b?source=api-prod","affectedVersions":"<=1.22.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/415bfddb-5223-439f-8a08-535f79631ff0/forminator","title":"Forminator <= 1.44.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id and data-size Parameters\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-04 21:58:40","sources":[{"name":"Wordfence","remoteId":"415bfddb-5223-439f-8a08-535f79631ff0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/415bfddb-5223-439f-8a08-535f79631ff0?source=api-prod","cve":"CVE-2025-5341","affectedVersions":"<=1.44.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/4ada2055-3c4a-4b6f-8803-2eac8ede5ec7/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.50.2 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-16 16:02:17","sources":[{"name":"Wordfence","remoteId":"4ada2055-3c4a-4b6f-8803-2eac8ede5ec7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ada2055-3c4a-4b6f-8803-2eac8ede5ec7?source=api-prod","cve":"CVE-2026-2002","affectedVersions":"<=1.50.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/5039d63b-377d-435a-be31-4ae81ea30dd3/forminator","title":"Forminator <= 1.42.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'limit'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 22:33:14","sources":[{"name":"Wordfence","remoteId":"5039d63b-377d-435a-be31-4ae81ea30dd3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5039d63b-377d-435a-be31-4ae81ea30dd3?source=api-prod","cve":"CVE-2025-3487","affectedVersions":"<=1.42.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/5f5a1eb3-3fda-49de-aefb-2205c9ca3520/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.45.0 - Authenticated (Administrator+) SQL Injection via `order_by` Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-17 16:22:47","sources":[{"name":"Wordfence","remoteId":"5f5a1eb3-3fda-49de-aefb-2205c9ca3520"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5f5a1eb3-3fda-49de-aefb-2205c9ca3520?source=api-prod","cve":"CVE-2025-7638","affectedVersions":"<=1.45.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/64e14944-db83-413f-82a3-cda594398c7e/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.34.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"64e14944-db83-413f-82a3-cda594398c7e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/64e14944-db83-413f-82a3-cda594398c7e?source=api-prod","cve":"CVE-2024-45625","affectedVersions":"<=1.34.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/6707aa4c-c652-42c0-bdb9-00be984e7271/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-01 17:04:22","sources":[{"name":"Wordfence","remoteId":"6707aa4c-c652-42c0-bdb9-00be984e7271"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6707aa4c-c652-42c0-bdb9-00be984e7271?source=api-prod","cve":"CVE-2025-6464","affectedVersions":"<=1.44.2","severity":"high"},{"advisoryId":"WPSECADV/WF/6dc9b4cb-d36b-4693-a7b9-1dad123b6639/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-01 16:22:05","sources":[{"name":"Wordfence","remoteId":"6dc9b4cb-d36b-4693-a7b9-1dad123b6639"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6dc9b4cb-d36b-4693-a7b9-1dad123b6639?source=api-prod","cve":"CVE-2025-6463","affectedVersions":"<=1.44.2","severity":"high"},{"advisoryId":"WPSECADV/WF/6f34b94f-ea72-4a42-abea-2f2eb565ffdd/forminator","title":"Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.27.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f34b94f-ea72-4a42-abea-2f2eb565ffdd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f34b94f-ea72-4a42-abea-2f2eb565ffdd?source=api-prod","cve":"CVE-2023-5119","affectedVersions":"<=1.26.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/718e54f5-f040-42d6-958d-255d905615d5/forminator","title":"Forminator <= 1.22.1 - Missing Authorization on 'load_recaptcha_preview' AJAX function\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"718e54f5-f040-42d6-958d-255d905615d5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/718e54f5-f040-42d6-958d-255d905615d5?source=api-prod","affectedVersions":"<=1.22.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/81e6e266-078a-4f4f-a335-c9d388f41ef2/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Custom Form Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"81e6e266-078a-4f4f-a335-c9d388f41ef2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/81e6e266-078a-4f4f-a335-c9d388f41ef2?source=api-prod","cve":"CVE-2024-9352","affectedVersions":"<=1.35.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8d89e3b7-d980-42bb-ab0c-d86ab174a69c/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Quiz Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"8d89e3b7-d980-42bb-ab0c-d86ab174a69c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8d89e3b7-d980-42bb-ab0c-d86ab174a69c?source=api-prod","cve":"CVE-2024-9351","affectedVersions":"<=1.35.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/97cbf2d7-2fdc-4c10-872d-add54687dd9b/forminator","title":"Forminator <= 1.15.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"97cbf2d7-2fdc-4c10-872d-add54687dd9b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/97cbf2d7-2fdc-4c10-872d-add54687dd9b?source=api-prod","cve":"CVE-2024-31857","affectedVersions":"<=1.15.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9cd87da6-1f4c-4a15-8ebb-6e0f8ef72513/forminator","title":"Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"9cd87da6-1f4c-4a15-8ebb-6e0f8ef72513"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9cd87da6-1f4c-4a15-8ebb-6e0f8ef72513?source=api-prod","cve":"CVE-2023-4596","affectedVersions":"<=1.24.6","severity":"critical"},{"advisoryId":"WPSECADV/WF/9d68ab8b-38c8-47aa-8b69-8cebe0a8d24e/forminator","title":"Forminator <= 1.15.2 - Admin+ Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"9d68ab8b-38c8-47aa-8b69-8cebe0a8d24e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9d68ab8b-38c8-47aa-8b69-8cebe0a8d24e?source=api-prod","cve":"CVE-2021-24700","affectedVersions":"<1.15.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/a40cb2da-dc13-4e20-9602-a4e6c2eade43/forminator","title":"Forminator <= 1.23.3 - Race Condition to Multiple Poll Voting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"a40cb2da-dc13-4e20-9602-a4e6c2eade43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a40cb2da-dc13-4e20-9602-a4e6c2eade43?source=api-prod","cve":"CVE-2023-2010","affectedVersions":"<=1.23.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/be1d9d2b-cbdf-4d62-85fe-2616eaf02848/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"be1d9d2b-cbdf-4d62-85fe-2616eaf02848"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be1d9d2b-cbdf-4d62-85fe-2616eaf02848?source=api-prod","cve":"CVE-2024-10402","affectedVersions":"<=1.35.1","severity":"high"},{"advisoryId":"WPSECADV/WF/c873c04e-516e-41ee-a295-b8c5235abc1b/forminator","title":"Forminator <= 1.42.0 - Order Replay Vulnerability\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 22:33:04","sources":[{"name":"Wordfence","remoteId":"c873c04e-516e-41ee-a295-b8c5235abc1b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c873c04e-516e-41ee-a295-b8c5235abc1b?source=api-prod","cve":"CVE-2025-3479","affectedVersions":"<=1.42.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/cdee0cd8-b83b-4436-aebe-533f5af03ef1/forminator","title":"Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.13.4 - Cross-Site Request Forgery Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"cdee0cd8-b83b-4436-aebe-533f5af03ef1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cdee0cd8-b83b-4436-aebe-533f5af03ef1?source=api-prod","cve":"CVE-2021-4417","affectedVersions":"<1.13.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/d0cb4434-94c5-42a9-bd86-869058dcbf67/forminator","title":"Forminator <= 1.22.1 - Missing Authorization on 'hubspot_support_request' AJAX function\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"d0cb4434-94c5-42a9-bd86-869058dcbf67"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d0cb4434-94c5-42a9-bd86-869058dcbf67?source=api-prod","affectedVersions":"<=1.22.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/e558100a-5866-4e7f-bae7-47a1f492ab27/forminator","title":"Forminator <= 1.14.11 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"e558100a-5866-4e7f-bae7-47a1f492ab27"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e558100a-5866-4e7f-bae7-47a1f492ab27?source=api-prod","cve":"CVE-2021-36821","affectedVersions":"<1.14.12","severity":"high"},{"advisoryId":"WPSECADV/WF/efe6c4aa-5e5d-4e3b-8a38-f85e163a9e00/forminator","title":"Forminator Plugin <= 1.5.4 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-02-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"efe6c4aa-5e5d-4e3b-8a38-f85e163a9e00"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/efe6c4aa-5e5d-4e3b-8a38-f85e163a9e00?source=api-prod","cve":"CVE-2019-9567","affectedVersions":"<1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/f5281d4b-c2cd-4972-b837-e101a8893c6e/forminator","title":"Forminator <= 1.38.2 - Reflected Cross-Site Scripting via Title Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-30 15:07:49","sources":[{"name":"Wordfence","remoteId":"f5281d4b-c2cd-4972-b837-e101a8893c6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5281d4b-c2cd-4972-b837-e101a8893c6e?source=api-prod","cve":"CVE-2025-0470","affectedVersions":"<=1.38.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f58d5464-b12d-4d01-985a-68854b0b2fdd/forminator","title":"Forminator <= 1.28.1 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"f58d5464-b12d-4d01-985a-68854b0b2fdd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f58d5464-b12d-4d01-985a-68854b0b2fdd?source=api-prod","cve":"CVE-2024-28890","affectedVersions":"<=1.28.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/f88286b9-16b2-42a9-b8c6-0a6fe6c136ef/forminator","title":"Forminator Plugin <= 1.5.3.1 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-02-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"f88286b9-16b2-42a9-b8c6-0a6fe6c136ef"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f88286b9-16b2-42a9-b8c6-0a6fe6c136ef?source=api-prod","cve":"CVE-2019-9568","affectedVersions":"<1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/fbed35ca-1630-46a4-8b1f-60cc7216f294/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.36.0 - Insecure Direct Object Reference to Submission Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"fbed35ca-1630-46a4-8b1f-60cc7216f294"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fbed35ca-1630-46a4-8b1f-60cc7216f294?source=api-prod","cve":"CVE-2024-9700","affectedVersions":"<=1.36.0","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/00272fe2-52aa-4183-8b57-6b51ad57c657/forminator","title":"Forminator <= 1.24.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"00272fe2-52aa-4183-8b57-6b51ad57c657"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00272fe2-52aa-4183-8b57-6b51ad57c657?source=api-prod","cve":"CVE-2023-3134","affectedVersions":"<=1.24.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/0d04b822-a48a-485e-b9b5-f5a213307c71/forminator","title":"Forminator <= 1.29.1 - HubSpot Developer API Key Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d04b822-a48a-485e-b9b5-f5a213307c71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d04b822-a48a-485e-b9b5-f5a213307c71?source=api-prod","cve":"CVE-2024-7389","affectedVersions":"<=1.29.1","severity":"high"},{"advisoryId":"WPSECADV/WF/13cfa202-ab90-46c0-ab53-00995bfdcaa3/forminator","title":"Forminator <= 1.27.0 - Authenticated (Administrator+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"13cfa202-ab90-46c0-ab53-00995bfdcaa3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/13cfa202-ab90-46c0-ab53-00995bfdcaa3?source=api-prod","cve":"CVE-2023-6133","affectedVersions":"<=1.27.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/14043276-ba0a-4862-a1a7-00b4c372c5bc/forminator","title":"Forminator <= 1.39.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-26 16:21:30","sources":[{"name":"Wordfence","remoteId":"14043276-ba0a-4862-a1a7-00b4c372c5bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/14043276-ba0a-4862-a1a7-00b4c372c5bc?source=api-prod","cve":"CVE-2025-0469","affectedVersions":"=1.39.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/19439622-6396-4f10-ab71-aa243b6812fa/forminator","title":"Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.29.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"19439622-6396-4f10-ab71-aa243b6812fa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/19439622-6396-4f10-ab71-aa243b6812fa?source=api-prod","cve":"CVE-2024-3053","affectedVersions":"<=1.29.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/1a6fbb60-811a-4763-b301-694bc8d387e7/forminator","title":"Forminator <= 1.29.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"1a6fbb60-811a-4763-b301-694bc8d387e7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1a6fbb60-811a-4763-b301-694bc8d387e7?source=api-prod","cve":"CVE-2024-29777","affectedVersions":"<=1.29.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/1afb94ab-b3ba-4598-8ff4-f9ffc6717371/forminator","title":"Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.52.0 - Missing Authorization to Unauthenticated Stripe PaymentIntent Reuse / Underpayment Bypass via 'paymentid' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 17:34:23","sources":[{"name":"Wordfence","remoteId":"1afb94ab-b3ba-4598-8ff4-f9ffc6717371"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1afb94ab-b3ba-4598-8ff4-f9ffc6717371?source=api-prod","cve":"CVE-2026-2729","affectedVersions":"<=1.52.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/224233bc-68f3-40e4-8182-4831ccce93fb/forminator","title":"Forminator <= 1.29.2 - Authenticated (Admin+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"224233bc-68f3-40e4-8182-4831ccce93fb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/224233bc-68f3-40e4-8182-4831ccce93fb?source=api-prod","cve":"CVE-2024-31077","affectedVersions":"<=1.29.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/2283b147-b904-4086-8cb1-6d8969ccbaf6/forminator","title":"Forminator <= 1.50.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"2283b147-b904-4086-8cb1-6d8969ccbaf6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2283b147-b904-4086-8cb1-6d8969ccbaf6?source=api-prod","cve":"CVE-2026-32409","affectedVersions":"<=1.50.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/23feb72c-7e6f-436b-b56e-dc6185302d31/forminator","title":"Forminator <= 1.29.0 - Unauthenticated Stored Cross-Site Scripting via File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"23feb72c-7e6f-436b-b56e-dc6185302d31"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/23feb72c-7e6f-436b-b56e-dc6185302d31?source=api-prod","cve":"CVE-2024-1794","affectedVersions":"<=1.29.0","severity":"high"},{"advisoryId":"WPSECADV/WF/286df83a-d723-4443-b265-f91cf5abb385/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.38.2 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"286df83a-d723-4443-b265-f91cf5abb385"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/286df83a-d723-4443-b265-f91cf5abb385?source=api-prod","cve":"CVE-2024-7052","affectedVersions":"<=1.38.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/2b28ddeb-44f5-4d19-b866-94fc2088ee6d/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.49.1 - Missing Authorization to Authenticated (Forminator User+) CSV Export\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 17:47:08","sources":[{"name":"Wordfence","remoteId":"2b28ddeb-44f5-4d19-b866-94fc2088ee6d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b28ddeb-44f5-4d19-b866-94fc2088ee6d?source=api-prod","cve":"CVE-2025-14782","affectedVersions":"<=1.49.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ef15cb1-b320-42d9-a2fd-afff2ec8a93b/forminator","title":"Forminator <= 1.22.1 - Missing Authorization on 'load_hcaptcha_preview' AJAX function\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"2ef15cb1-b320-42d9-a2fd-afff2ec8a93b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ef15cb1-b320-42d9-a2fd-afff2ec8a93b?source=api-prod","affectedVersions":"<=1.22.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/415bfddb-5223-439f-8a08-535f79631ff0/forminator","title":"Forminator <= 1.44.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id and data-size Parameters\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-04 21:58:40","sources":[{"name":"Wordfence","remoteId":"415bfddb-5223-439f-8a08-535f79631ff0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/415bfddb-5223-439f-8a08-535f79631ff0?source=api-prod","cve":"CVE-2025-5341","affectedVersions":"<=1.44.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/4ada2055-3c4a-4b6f-8803-2eac8ede5ec7/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.50.2 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-16 16:02:17","sources":[{"name":"Wordfence","remoteId":"4ada2055-3c4a-4b6f-8803-2eac8ede5ec7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ada2055-3c4a-4b6f-8803-2eac8ede5ec7?source=api-prod","cve":"CVE-2026-2002","affectedVersions":"<=1.50.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/5039d63b-377d-435a-be31-4ae81ea30dd3/forminator","title":"Forminator <= 1.42.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'limit'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 22:33:14","sources":[{"name":"Wordfence","remoteId":"5039d63b-377d-435a-be31-4ae81ea30dd3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5039d63b-377d-435a-be31-4ae81ea30dd3?source=api-prod","cve":"CVE-2025-3487","affectedVersions":"<=1.42.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/5f5a1eb3-3fda-49de-aefb-2205c9ca3520/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.45.0 - Authenticated (Administrator+) SQL Injection via `order_by` Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-17 16:22:47","sources":[{"name":"Wordfence","remoteId":"5f5a1eb3-3fda-49de-aefb-2205c9ca3520"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5f5a1eb3-3fda-49de-aefb-2205c9ca3520?source=api-prod","cve":"CVE-2025-7638","affectedVersions":"<=1.45.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/64e14944-db83-413f-82a3-cda594398c7e/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.34.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"64e14944-db83-413f-82a3-cda594398c7e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/64e14944-db83-413f-82a3-cda594398c7e?source=api-prod","cve":"CVE-2024-45625","affectedVersions":"<=1.34.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/6707aa4c-c652-42c0-bdb9-00be984e7271/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-01 17:04:22","sources":[{"name":"Wordfence","remoteId":"6707aa4c-c652-42c0-bdb9-00be984e7271"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6707aa4c-c652-42c0-bdb9-00be984e7271?source=api-prod","cve":"CVE-2025-6464","affectedVersions":"<=1.44.2","severity":"high"},{"advisoryId":"WPSECADV/WF/6dc9b4cb-d36b-4693-a7b9-1dad123b6639/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-01 16:22:05","sources":[{"name":"Wordfence","remoteId":"6dc9b4cb-d36b-4693-a7b9-1dad123b6639"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6dc9b4cb-d36b-4693-a7b9-1dad123b6639?source=api-prod","cve":"CVE-2025-6463","affectedVersions":"<=1.44.2","severity":"high"},{"advisoryId":"WPSECADV/WF/6f34b94f-ea72-4a42-abea-2f2eb565ffdd/forminator","title":"Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.27.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f34b94f-ea72-4a42-abea-2f2eb565ffdd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f34b94f-ea72-4a42-abea-2f2eb565ffdd?source=api-prod","cve":"CVE-2023-5119","affectedVersions":"<=1.26.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/718e54f5-f040-42d6-958d-255d905615d5/forminator","title":"Forminator <= 1.22.1 - Missing Authorization on 'load_recaptcha_preview' AJAX function\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"718e54f5-f040-42d6-958d-255d905615d5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/718e54f5-f040-42d6-958d-255d905615d5?source=api-prod","affectedVersions":"<=1.22.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/788422c4-e070-48aa-a85d-a5d5a25a6a1d/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.52.1 - Unauthenticated Arbitrary File Read via 'upload-1[file][file_path]'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 17:49:05","sources":[{"name":"Wordfence","remoteId":"788422c4-e070-48aa-a85d-a5d5a25a6a1d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/788422c4-e070-48aa-a85d-a5d5a25a6a1d?source=api-prod","cve":"CVE-2026-5192","affectedVersions":"<=1.52.1","severity":"high"},{"advisoryId":"WPSECADV/WF/81e6e266-078a-4f4f-a335-c9d388f41ef2/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Custom Form Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"81e6e266-078a-4f4f-a335-c9d388f41ef2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/81e6e266-078a-4f4f-a335-c9d388f41ef2?source=api-prod","cve":"CVE-2024-9352","affectedVersions":"<=1.35.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8d89e3b7-d980-42bb-ab0c-d86ab174a69c/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Quiz Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"8d89e3b7-d980-42bb-ab0c-d86ab174a69c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8d89e3b7-d980-42bb-ab0c-d86ab174a69c?source=api-prod","cve":"CVE-2024-9351","affectedVersions":"<=1.35.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/97cbf2d7-2fdc-4c10-872d-add54687dd9b/forminator","title":"Forminator <= 1.15.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"97cbf2d7-2fdc-4c10-872d-add54687dd9b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/97cbf2d7-2fdc-4c10-872d-add54687dd9b?source=api-prod","cve":"CVE-2024-31857","affectedVersions":"<=1.15.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9cd87da6-1f4c-4a15-8ebb-6e0f8ef72513/forminator","title":"Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"9cd87da6-1f4c-4a15-8ebb-6e0f8ef72513"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9cd87da6-1f4c-4a15-8ebb-6e0f8ef72513?source=api-prod","cve":"CVE-2023-4596","affectedVersions":"<=1.24.6","severity":"critical"},{"advisoryId":"WPSECADV/WF/9d68ab8b-38c8-47aa-8b69-8cebe0a8d24e/forminator","title":"Forminator <= 1.15.2 - Admin+ Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"9d68ab8b-38c8-47aa-8b69-8cebe0a8d24e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9d68ab8b-38c8-47aa-8b69-8cebe0a8d24e?source=api-prod","cve":"CVE-2021-24700","affectedVersions":"<1.15.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/a40cb2da-dc13-4e20-9602-a4e6c2eade43/forminator","title":"Forminator <= 1.23.3 - Race Condition to Multiple Poll Voting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"a40cb2da-dc13-4e20-9602-a4e6c2eade43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a40cb2da-dc13-4e20-9602-a4e6c2eade43?source=api-prod","cve":"CVE-2023-2010","affectedVersions":"<=1.23.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/be1d9d2b-cbdf-4d62-85fe-2616eaf02848/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"be1d9d2b-cbdf-4d62-85fe-2616eaf02848"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be1d9d2b-cbdf-4d62-85fe-2616eaf02848?source=api-prod","cve":"CVE-2024-10402","affectedVersions":"<=1.35.1","severity":"high"},{"advisoryId":"WPSECADV/WF/c873c04e-516e-41ee-a295-b8c5235abc1b/forminator","title":"Forminator <= 1.42.0 - Order Replay Vulnerability\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 22:33:04","sources":[{"name":"Wordfence","remoteId":"c873c04e-516e-41ee-a295-b8c5235abc1b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c873c04e-516e-41ee-a295-b8c5235abc1b?source=api-prod","cve":"CVE-2025-3479","affectedVersions":"<=1.42.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/cdee0cd8-b83b-4436-aebe-533f5af03ef1/forminator","title":"Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.13.4 - Cross-Site Request Forgery Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"cdee0cd8-b83b-4436-aebe-533f5af03ef1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cdee0cd8-b83b-4436-aebe-533f5af03ef1?source=api-prod","cve":"CVE-2021-4417","affectedVersions":"<1.13.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/d0cb4434-94c5-42a9-bd86-869058dcbf67/forminator","title":"Forminator <= 1.22.1 - Missing Authorization on 'hubspot_support_request' AJAX function\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"d0cb4434-94c5-42a9-bd86-869058dcbf67"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d0cb4434-94c5-42a9-bd86-869058dcbf67?source=api-prod","affectedVersions":"<=1.22.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/e558100a-5866-4e7f-bae7-47a1f492ab27/forminator","title":"Forminator <= 1.14.11 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"e558100a-5866-4e7f-bae7-47a1f492ab27"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e558100a-5866-4e7f-bae7-47a1f492ab27?source=api-prod","cve":"CVE-2021-36821","affectedVersions":"<1.14.12","severity":"high"},{"advisoryId":"WPSECADV/WF/efe6c4aa-5e5d-4e3b-8a38-f85e163a9e00/forminator","title":"Forminator Plugin <= 1.5.4 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-02-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"efe6c4aa-5e5d-4e3b-8a38-f85e163a9e00"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/efe6c4aa-5e5d-4e3b-8a38-f85e163a9e00?source=api-prod","cve":"CVE-2019-9567","affectedVersions":"<1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/f5281d4b-c2cd-4972-b837-e101a8893c6e/forminator","title":"Forminator <= 1.38.2 - Reflected Cross-Site Scripting via Title Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-30 15:07:49","sources":[{"name":"Wordfence","remoteId":"f5281d4b-c2cd-4972-b837-e101a8893c6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5281d4b-c2cd-4972-b837-e101a8893c6e?source=api-prod","cve":"CVE-2025-0470","affectedVersions":"<=1.38.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f58d5464-b12d-4d01-985a-68854b0b2fdd/forminator","title":"Forminator <= 1.28.1 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"f58d5464-b12d-4d01-985a-68854b0b2fdd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f58d5464-b12d-4d01-985a-68854b0b2fdd?source=api-prod","cve":"CVE-2024-28890","affectedVersions":"<=1.28.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/f88286b9-16b2-42a9-b8c6-0a6fe6c136ef/forminator","title":"Forminator Plugin <= 1.5.3.1 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-02-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"f88286b9-16b2-42a9-b8c6-0a6fe6c136ef"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f88286b9-16b2-42a9-b8c6-0a6fe6c136ef?source=api-prod","cve":"CVE-2019-9568","affectedVersions":"<1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/fbed35ca-1630-46a4-8b1f-60cc7216f294/forminator","title":"Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.36.0 - Insecure Direct Object Reference to Submission Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"fbed35ca-1630-46a4-8b1f-60cc7216f294"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fbed35ca-1630-46a4-8b1f-60cc7216f294?source=api-prod","cve":"CVE-2024-9700","affectedVersions":"<=1.36.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_667573696f6e2d6275696c646572811c9dc5_gen.json b/internal/data/assets/plugin_667573696f6e2d6275696c646572811c9dc5_gen.json index 51f9804d..1be0dcb5 100644 --- a/internal/data/assets/plugin_667573696f6e2d6275696c646572811c9dc5_gen.json +++ b/internal/data/assets/plugin_667573696f6e2d6275696c646572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/05220967-dd42-4cb9-9c2f-9c7ac3c0926b/fusion-builder","title":"Fusion Builder <= 3.11.1 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"05220967-dd42-4cb9-9c2f-9c7ac3c0926b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/05220967-dd42-4cb9-9c2f-9c7ac3c0926b?source=api-prod","cve":"CVE-2023-39311","affectedVersions":"<=3.11.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/149ef56e-b9a6-4d28-9c90-0e2fa917ada6/fusion-builder","title":"Avada (Fusion) Builder < 3.15.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"149ef56e-b9a6-4d28-9c90-0e2fa917ada6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/149ef56e-b9a6-4d28-9c90-0e2fa917ada6?source=api-prod","cve":"CVE-2026-32452","affectedVersions":"<3.15.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/2f881298-23f3-471c-b6f1-ebaf72d7180e/fusion-builder","title":"Avada (Fusion) Builder < 3.15.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"2f881298-23f3-471c-b6f1-ebaf72d7180e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2f881298-23f3-471c-b6f1-ebaf72d7180e?source=api-prod","cve":"CVE-2026-32451","affectedVersions":"<3.15.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/35b3a82a-4391-41b0-b434-691743c5ff4d/fusion-builder","title":"Fusion Builder <= 3.11.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"35b3a82a-4391-41b0-b434-691743c5ff4d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/35b3a82a-4391-41b0-b434-691743c5ff4d?source=api-prod","cve":"CVE-2023-39310","affectedVersions":"<=3.11.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/4181dcad-b5bd-46db-b47c-3cdee427123c/fusion-builder","title":"Avada Builder <= 3.11.12 - Authenticated (Contributor+) Protected Post Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"4181dcad-b5bd-46db-b47c-3cdee427123c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4181dcad-b5bd-46db-b47c-3cdee427123c?source=api-prod","cve":"CVE-2024-12335","affectedVersions":"<=3.11.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/7c23bd29-ba02-4c90-a631-5ce6294d7760/fusion-builder","title":"Avada | Website Builder For WordPress & eCommerce <= 3.11.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via fusion_button Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"7c23bd29-ba02-4c90-a631-5ce6294d7760"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c23bd29-ba02-4c90-a631-5ce6294d7760?source=api-prod","cve":"CVE-2024-5628","affectedVersions":"<=3.11.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/7c54588f-6436-406f-93cb-b08965586d11/fusion-builder","title":"Avada Builder <= 3.11.11 - Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widgets\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-22 08:24:14","sources":[{"name":"Wordfence","remoteId":"7c54588f-6436-406f-93cb-b08965586d11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c54588f-6436-406f-93cb-b08965586d11?source=api-prod","cve":"CVE-2024-12477","affectedVersions":"<=3.11.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/7c734aa9-ee9e-4605-a4b8-5075ce4b941f/fusion-builder","title":"Fusion Builder <= 3.11.1 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"7c734aa9-ee9e-4605-a4b8-5075ce4b941f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c734aa9-ee9e-4605-a4b8-5075ce4b941f?source=api-prod","cve":"CVE-2023-39309","affectedVersions":"<=3.11.1","severity":"high"},{"advisoryId":"WPSECADV/WF/94e373fb-b3f5-4c1b-9eaa-89747af4dc30/fusion-builder","title":"Avada Builder <= 3.11.14 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"94e373fb-b3f5-4c1b-9eaa-89747af4dc30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/94e373fb-b3f5-4c1b-9eaa-89747af4dc30?source=api-prod","cve":"CVE-2025-1665","affectedVersions":"<=3.11.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/94f6aab3-49a7-4837-a424-e40e483f3f68/fusion-builder","title":"Avada Builder <= 3.11.13 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"94f6aab3-49a7-4837-a424-e40e483f3f68"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/94f6aab3-49a7-4837-a424-e40e483f3f68?source=api-prod","cve":"CVE-2024-13345","affectedVersions":"<=3.11.13","severity":"high"},{"advisoryId":"WPSECADV/WF/9fe3d648-d6b3-4363-b449-bfc0f5b9c1ea/fusion-builder","title":"Fusion Builder <= 3.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"9fe3d648-d6b3-4363-b449-bfc0f5b9c1ea"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9fe3d648-d6b3-4363-b449-bfc0f5b9c1ea?source=api-prod","cve":"CVE-2025-49940","affectedVersions":"<=3.13.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/ad3de7e6-a080-4ce8-aa27-21e7f8fdb2c7/fusion-builder","title":"Fusion Builder <= 3.6.1 & Avada <= 7.6.1 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-04-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad3de7e6-a080-4ce8-aa27-21e7f8fdb2c7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad3de7e6-a080-4ce8-aa27-21e7f8fdb2c7?source=api-prod","cve":"CVE-2022-1386","affectedVersions":"<3.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/b173523a-e79d-4d2d-af67-5372576df220/fusion-builder","title":"Fusion Builder <= 3.11.1 - Reflected Cross-Site Scripting via User Register Element\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"b173523a-e79d-4d2d-af67-5372576df220"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b173523a-e79d-4d2d-af67-5372576df220?source=api-prod","cve":"CVE-2023-39306","affectedVersions":"<=3.11.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f0a21eaa-4e2a-4d07-8635-f0a8a5db660f/fusion-builder","title":"Avada (Fusion) Builder <= 3.12.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"f0a21eaa-4e2a-4d07-8635-f0a8a5db660f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f0a21eaa-4e2a-4d07-8635-f0a8a5db660f?source=api-prod","cve":"CVE-2025-6747","affectedVersions":"<=3.12.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f1f69f93-80e3-434d-98a6-fc8757b4e6d1/fusion-builder","title":"Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-14 12:23:58","sources":[{"name":"Wordfence","remoteId":"f1f69f93-80e3-434d-98a6-fc8757b4e6d1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f1f69f93-80e3-434d-98a6-fc8757b4e6d1?source=api-prod","cve":"CVE-2026-1541","affectedVersions":"<=3.15.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f946c5b9-a227-47bd-bae2-decbb5748436/fusion-builder","title":"Avada (Fusion) Builder < 3.15.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"f946c5b9-a227-47bd-bae2-decbb5748436"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f946c5b9-a227-47bd-bae2-decbb5748436?source=api-prod","cve":"CVE-2026-32542","affectedVersions":"<3.15.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/fdc57b06-bae9-49a3-84dd-f593705330e9/fusion-builder","title":"Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-14 12:25:28","sources":[{"name":"Wordfence","remoteId":"fdc57b06-bae9-49a3-84dd-f593705330e9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fdc57b06-bae9-49a3-84dd-f593705330e9?source=api-prod","cve":"CVE-2026-1509","affectedVersions":"<=3.15.1","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/05220967-dd42-4cb9-9c2f-9c7ac3c0926b/fusion-builder","title":"Fusion Builder <= 3.11.1 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"05220967-dd42-4cb9-9c2f-9c7ac3c0926b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/05220967-dd42-4cb9-9c2f-9c7ac3c0926b?source=api-prod","cve":"CVE-2023-39311","affectedVersions":"<=3.11.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/149ef56e-b9a6-4d28-9c90-0e2fa917ada6/fusion-builder","title":"Avada (Fusion) Builder < 3.15.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"149ef56e-b9a6-4d28-9c90-0e2fa917ada6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/149ef56e-b9a6-4d28-9c90-0e2fa917ada6?source=api-prod","cve":"CVE-2026-32452","affectedVersions":"<3.15.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/2f881298-23f3-471c-b6f1-ebaf72d7180e/fusion-builder","title":"Avada (Fusion) Builder < 3.15.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"2f881298-23f3-471c-b6f1-ebaf72d7180e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2f881298-23f3-471c-b6f1-ebaf72d7180e?source=api-prod","cve":"CVE-2026-32451","affectedVersions":"<3.15.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/35b3a82a-4391-41b0-b434-691743c5ff4d/fusion-builder","title":"Fusion Builder <= 3.11.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"35b3a82a-4391-41b0-b434-691743c5ff4d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/35b3a82a-4391-41b0-b434-691743c5ff4d?source=api-prod","cve":"CVE-2023-39310","affectedVersions":"<=3.11.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/4181dcad-b5bd-46db-b47c-3cdee427123c/fusion-builder","title":"Avada Builder <= 3.11.12 - Authenticated (Contributor+) Protected Post Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"4181dcad-b5bd-46db-b47c-3cdee427123c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4181dcad-b5bd-46db-b47c-3cdee427123c?source=api-prod","cve":"CVE-2024-12335","affectedVersions":"<=3.11.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/67f23705-ee04-40a7-a4d9-3bf654a2cb12/fusion-builder","title":"Avada (Fusion) Builder <= 3.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"67f23705-ee04-40a7-a4d9-3bf654a2cb12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/67f23705-ee04-40a7-a4d9-3bf654a2cb12?source=api-prod","cve":"CVE-2026-25472","affectedVersions":"<=3.14.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/7c23bd29-ba02-4c90-a631-5ce6294d7760/fusion-builder","title":"Avada | Website Builder For WordPress & eCommerce <= 3.11.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via fusion_button Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"7c23bd29-ba02-4c90-a631-5ce6294d7760"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c23bd29-ba02-4c90-a631-5ce6294d7760?source=api-prod","cve":"CVE-2024-5628","affectedVersions":"<=3.11.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/7c54588f-6436-406f-93cb-b08965586d11/fusion-builder","title":"Avada Builder <= 3.11.11 - Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widgets\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-22 08:24:14","sources":[{"name":"Wordfence","remoteId":"7c54588f-6436-406f-93cb-b08965586d11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c54588f-6436-406f-93cb-b08965586d11?source=api-prod","cve":"CVE-2024-12477","affectedVersions":"<=3.11.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/7c734aa9-ee9e-4605-a4b8-5075ce4b941f/fusion-builder","title":"Fusion Builder <= 3.11.1 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"7c734aa9-ee9e-4605-a4b8-5075ce4b941f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c734aa9-ee9e-4605-a4b8-5075ce4b941f?source=api-prod","cve":"CVE-2023-39309","affectedVersions":"<=3.11.1","severity":"high"},{"advisoryId":"WPSECADV/WF/94e373fb-b3f5-4c1b-9eaa-89747af4dc30/fusion-builder","title":"Avada Builder <= 3.11.14 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"94e373fb-b3f5-4c1b-9eaa-89747af4dc30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/94e373fb-b3f5-4c1b-9eaa-89747af4dc30?source=api-prod","cve":"CVE-2025-1665","affectedVersions":"<=3.11.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/94f6aab3-49a7-4837-a424-e40e483f3f68/fusion-builder","title":"Avada Builder <= 3.11.13 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"94f6aab3-49a7-4837-a424-e40e483f3f68"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/94f6aab3-49a7-4837-a424-e40e483f3f68?source=api-prod","cve":"CVE-2024-13345","affectedVersions":"<=3.11.13","severity":"high"},{"advisoryId":"WPSECADV/WF/9fe3d648-d6b3-4363-b449-bfc0f5b9c1ea/fusion-builder","title":"Fusion Builder <= 3.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"9fe3d648-d6b3-4363-b449-bfc0f5b9c1ea"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9fe3d648-d6b3-4363-b449-bfc0f5b9c1ea?source=api-prod","cve":"CVE-2025-49940","affectedVersions":"<=3.13.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/ad3de7e6-a080-4ce8-aa27-21e7f8fdb2c7/fusion-builder","title":"Fusion Builder <= 3.6.1 & Avada <= 7.6.1 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-04-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad3de7e6-a080-4ce8-aa27-21e7f8fdb2c7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad3de7e6-a080-4ce8-aa27-21e7f8fdb2c7?source=api-prod","cve":"CVE-2022-1386","affectedVersions":"<3.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/b173523a-e79d-4d2d-af67-5372576df220/fusion-builder","title":"Fusion Builder <= 3.11.1 - Reflected Cross-Site Scripting via User Register Element\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"b173523a-e79d-4d2d-af67-5372576df220"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b173523a-e79d-4d2d-af67-5372576df220?source=api-prod","cve":"CVE-2023-39306","affectedVersions":"<=3.11.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f0a21eaa-4e2a-4d07-8635-f0a8a5db660f/fusion-builder","title":"Avada (Fusion) Builder <= 3.12.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"f0a21eaa-4e2a-4d07-8635-f0a8a5db660f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f0a21eaa-4e2a-4d07-8635-f0a8a5db660f?source=api-prod","cve":"CVE-2025-6747","affectedVersions":"<=3.12.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f1f69f93-80e3-434d-98a6-fc8757b4e6d1/fusion-builder","title":"Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-14 12:23:58","sources":[{"name":"Wordfence","remoteId":"f1f69f93-80e3-434d-98a6-fc8757b4e6d1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f1f69f93-80e3-434d-98a6-fc8757b4e6d1?source=api-prod","cve":"CVE-2026-1541","affectedVersions":"<=3.15.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f946c5b9-a227-47bd-bae2-decbb5748436/fusion-builder","title":"Avada (Fusion) Builder < 3.15.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"f946c5b9-a227-47bd-bae2-decbb5748436"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f946c5b9-a227-47bd-bae2-decbb5748436?source=api-prod","cve":"CVE-2026-32542","affectedVersions":"<3.15.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/fdc57b06-bae9-49a3-84dd-f593705330e9/fusion-builder","title":"Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-14 12:25:28","sources":[{"name":"Wordfence","remoteId":"fdc57b06-bae9-49a3-84dd-f593705330e9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fdc57b06-bae9-49a3-84dd-f593705330e9?source=api-prod","cve":"CVE-2026-1509","affectedVersions":"<=3.15.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_67642d726174696e672d73797374656d811c9dc5_gen.json b/internal/data/assets/plugin_67642d726174696e672d73797374656d811c9dc5_gen.json index 327f4a5a..9f018fe4 100644 --- a/internal/data/assets/plugin_67642d726174696e672d73797374656d811c9dc5_gen.json +++ b/internal/data/assets/plugin_67642d726174696e672d73797374656d811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/10ac9e80-7aa9-4cc5-ad37-f15f8d12ed16/gd-rating-system","title":"GD Rating System < 2.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"10ac9e80-7aa9-4cc5-ad37-f15f8d12ed16"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/10ac9e80-7aa9-4cc5-ad37-f15f8d12ed16?source=api-prod","cve":"CVE-2017-18591","affectedVersions":"<2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/44210443-26f8-4626-aee2-4a19d87fdd43/gd-rating-system","title":"GD Rating System <= 2.3 - Directory Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"44210443-26f8-4626-aee2-4a19d87fdd43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/44210443-26f8-4626-aee2-4a19d87fdd43?source=api-prod","cve":"CVE-2018-5287","affectedVersions":"<2.3.1","severity":"high"},{"advisoryId":"WPSECADV/WF/47687614-bd79-44fd-bc82-eaa801c1387d/gd-rating-system","title":"GD Rating System <= 2.3 - Directory Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"47687614-bd79-44fd-bc82-eaa801c1387d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/47687614-bd79-44fd-bc82-eaa801c1387d?source=api-prod","cve":"CVE-2018-5291","affectedVersions":"<2.3.1","severity":"high"},{"advisoryId":"WPSECADV/WF/6351d3f7-2d10-4fcf-b7c1-88ce529cd9f4/gd-rating-system","title":"GD Rating System <= 2.3 - Directory Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"6351d3f7-2d10-4fcf-b7c1-88ce529cd9f4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6351d3f7-2d10-4fcf-b7c1-88ce529cd9f4?source=api-prod","cve":"CVE-2018-5290","affectedVersions":"<2.3.1","severity":"high"},{"advisoryId":"WPSECADV/WF/66cad18d-a433-47f1-9cb6-c619c8717a0d/gd-rating-system","title":"GD Rating System <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via extra_class Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-19 00:05:15","sources":[{"name":"Wordfence","remoteId":"66cad18d-a433-47f1-9cb6-c619c8717a0d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/66cad18d-a433-47f1-9cb6-c619c8717a0d?source=api-prod","cve":"CVE-2024-11198","affectedVersions":"<=3.6.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/b211f05e-fc6a-4aaf-b75e-b044243f9176/gd-rating-system","title":"GD Rating System <= 3.6 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"b211f05e-fc6a-4aaf-b75e-b044243f9176"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b211f05e-fc6a-4aaf-b75e-b044243f9176?source=api-prod","cve":"CVE-2024-38709","affectedVersions":"<=3.6","severity":"high"},{"advisoryId":"WPSECADV/WF/c0b3662d-e369-4978-aa7a-debbb3ee37e4/gd-rating-system","title":"GD Rating System <= 3.5.0 - Unauthenticated Stored Cross-Site Scripting via IP\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"c0b3662d-e369-4978-aa7a-debbb3ee37e4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c0b3662d-e369-4978-aa7a-debbb3ee37e4?source=api-prod","cve":"CVE-2024-25093","affectedVersions":"<=3.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c14f473f-ca49-4610-b5df-9eb0e064ece5/gd-rating-system","title":"GD Rating System <= 2.3 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"c14f473f-ca49-4610-b5df-9eb0e064ece5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c14f473f-ca49-4610-b5df-9eb0e064ece5?source=api-prod","cve":"CVE-2018-5292","affectedVersions":"<2.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8e768a4-09ac-4772-9e5d-b9f63bac208c/gd-rating-system","title":"GD Rating System <= 2.3 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"c8e768a4-09ac-4772-9e5d-b9f63bac208c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8e768a4-09ac-4772-9e5d-b9f63bac208c?source=api-prod","cve":"CVE-2018-5293","affectedVersions":"<2.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/ccf80f2d-3d2d-4fe6-a4c4-5a850cf5bdc8/gd-rating-system","title":"GD Rating System <= 2.3 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"ccf80f2d-3d2d-4fe6-a4c4-5a850cf5bdc8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ccf80f2d-3d2d-4fe6-a4c4-5a850cf5bdc8?source=api-prod","cve":"CVE-2018-5286","affectedVersions":"<2.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/d1a7e39a-5fd1-4bb3-9cd9-4bded794f8f0/gd-rating-system","title":"GD Rating System <= 2.3 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"d1a7e39a-5fd1-4bb3-9cd9-4bded794f8f0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d1a7e39a-5fd1-4bb3-9cd9-4bded794f8f0?source=api-prod","cve":"CVE-2018-5288","affectedVersions":"<2.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/e0d6c8dc-d32b-4ac8-8b0d-6d7ecbac86b5/gd-rating-system","title":"GD Rating System <= 2.3 - Directory Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"e0d6c8dc-d32b-4ac8-8b0d-6d7ecbac86b5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e0d6c8dc-d32b-4ac8-8b0d-6d7ecbac86b5?source=api-prod","cve":"CVE-2018-5289","affectedVersions":"<2.3.1","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/10ac9e80-7aa9-4cc5-ad37-f15f8d12ed16/gd-rating-system","title":"GD Rating System < 2.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"10ac9e80-7aa9-4cc5-ad37-f15f8d12ed16"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/10ac9e80-7aa9-4cc5-ad37-f15f8d12ed16?source=api-prod","cve":"CVE-2017-18591","affectedVersions":"<2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/44210443-26f8-4626-aee2-4a19d87fdd43/gd-rating-system","title":"GD Rating System <= 2.3 - Directory Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"44210443-26f8-4626-aee2-4a19d87fdd43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/44210443-26f8-4626-aee2-4a19d87fdd43?source=api-prod","cve":"CVE-2018-5287","affectedVersions":"<2.3.1","severity":"high"},{"advisoryId":"WPSECADV/WF/47687614-bd79-44fd-bc82-eaa801c1387d/gd-rating-system","title":"GD Rating System <= 2.3 - Directory Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"47687614-bd79-44fd-bc82-eaa801c1387d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/47687614-bd79-44fd-bc82-eaa801c1387d?source=api-prod","cve":"CVE-2018-5291","affectedVersions":"<2.3.1","severity":"high"},{"advisoryId":"WPSECADV/WF/6351d3f7-2d10-4fcf-b7c1-88ce529cd9f4/gd-rating-system","title":"GD Rating System <= 2.3 - Directory Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"6351d3f7-2d10-4fcf-b7c1-88ce529cd9f4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6351d3f7-2d10-4fcf-b7c1-88ce529cd9f4?source=api-prod","cve":"CVE-2018-5290","affectedVersions":"<2.3.1","severity":"high"},{"advisoryId":"WPSECADV/WF/66cad18d-a433-47f1-9cb6-c619c8717a0d/gd-rating-system","title":"GD Rating System <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via extra_class Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-19 00:05:15","sources":[{"name":"Wordfence","remoteId":"66cad18d-a433-47f1-9cb6-c619c8717a0d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/66cad18d-a433-47f1-9cb6-c619c8717a0d?source=api-prod","cve":"CVE-2024-11198","affectedVersions":"<=3.6.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/74c2c447-2ec5-4bba-a884-a366c5197dbb/gd-rating-system","title":"GD Rating System <= 3.6.2 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"74c2c447-2ec5-4bba-a884-a366c5197dbb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/74c2c447-2ec5-4bba-a884-a366c5197dbb?source=api-prod","cve":"CVE-2026-42639","affectedVersions":"<=3.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/b211f05e-fc6a-4aaf-b75e-b044243f9176/gd-rating-system","title":"GD Rating System <= 3.6 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"b211f05e-fc6a-4aaf-b75e-b044243f9176"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b211f05e-fc6a-4aaf-b75e-b044243f9176?source=api-prod","cve":"CVE-2024-38709","affectedVersions":"<=3.6","severity":"high"},{"advisoryId":"WPSECADV/WF/c0b3662d-e369-4978-aa7a-debbb3ee37e4/gd-rating-system","title":"GD Rating System <= 3.5.0 - Unauthenticated Stored Cross-Site Scripting via IP\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"c0b3662d-e369-4978-aa7a-debbb3ee37e4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c0b3662d-e369-4978-aa7a-debbb3ee37e4?source=api-prod","cve":"CVE-2024-25093","affectedVersions":"<=3.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c14f473f-ca49-4610-b5df-9eb0e064ece5/gd-rating-system","title":"GD Rating System <= 2.3 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"c14f473f-ca49-4610-b5df-9eb0e064ece5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c14f473f-ca49-4610-b5df-9eb0e064ece5?source=api-prod","cve":"CVE-2018-5292","affectedVersions":"<2.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8e768a4-09ac-4772-9e5d-b9f63bac208c/gd-rating-system","title":"GD Rating System <= 2.3 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"c8e768a4-09ac-4772-9e5d-b9f63bac208c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8e768a4-09ac-4772-9e5d-b9f63bac208c?source=api-prod","cve":"CVE-2018-5293","affectedVersions":"<2.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/ccf80f2d-3d2d-4fe6-a4c4-5a850cf5bdc8/gd-rating-system","title":"GD Rating System <= 2.3 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"ccf80f2d-3d2d-4fe6-a4c4-5a850cf5bdc8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ccf80f2d-3d2d-4fe6-a4c4-5a850cf5bdc8?source=api-prod","cve":"CVE-2018-5286","affectedVersions":"<2.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/d1a7e39a-5fd1-4bb3-9cd9-4bded794f8f0/gd-rating-system","title":"GD Rating System <= 2.3 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"d1a7e39a-5fd1-4bb3-9cd9-4bded794f8f0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d1a7e39a-5fd1-4bb3-9cd9-4bded794f8f0?source=api-prod","cve":"CVE-2018-5288","affectedVersions":"<2.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/e0d6c8dc-d32b-4ac8-8b0d-6d7ecbac86b5/gd-rating-system","title":"GD Rating System <= 2.3 - Directory Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"e0d6c8dc-d32b-4ac8-8b0d-6d7ecbac86b5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e0d6c8dc-d32b-4ac8-8b0d-6d7ecbac86b5?source=api-prod","cve":"CVE-2018-5289","affectedVersions":"<2.3.1","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6765656b792d626f74811c9dc5_gen.json b/internal/data/assets/plugin_6765656b792d626f74811c9dc5_gen.json index 10ae7f09..0d4b2b28 100644 --- a/internal/data/assets/plugin_6765656b792d626f74811c9dc5_gen.json +++ b/internal/data/assets/plugin_6765656b792d626f74811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/351a035a-9768-4efd-9887-e0905e129634/geeky-bot","title":"GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content <= 1.2.0 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"351a035a-9768-4efd-9887-e0905e129634"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/351a035a-9768-4efd-9887-e0905e129634?source=api-prod","cve":"CVE-2026-39519","affectedVersions":"<=1.2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/93495395-42cc-4787-be95-4691ff77d01b/geeky-bot","title":"GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content <= 1.2.2 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"93495395-42cc-4787-be95-4691ff77d01b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/93495395-42cc-4787-be95-4691ff77d01b?source=api-prod","cve":"CVE-2026-40772","affectedVersions":"<=1.2.2","severity":"high"},{"advisoryId":"WPSECADV/WF/b30e84db-c73f-4df2-9c88-c37a7e14c95b/geeky-bot","title":"GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation <= 1.1.8 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-13 17:20:05","sources":[{"name":"Wordfence","remoteId":"b30e84db-c73f-4df2-9c88-c37a7e14c95b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b30e84db-c73f-4df2-9c88-c37a7e14c95b?source=api-prod","cve":"CVE-2025-15266","affectedVersions":"<=1.1.8","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/351a035a-9768-4efd-9887-e0905e129634/geeky-bot","title":"GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content <= 1.2.0 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"351a035a-9768-4efd-9887-e0905e129634"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/351a035a-9768-4efd-9887-e0905e129634?source=api-prod","cve":"CVE-2026-39519","affectedVersions":"<=1.2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/4c716fd3-6297-4b3a-a796-65f68f2986cf/geeky-bot","title":"GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation <= 1.2.0 - Unauthenticated SQL Injection via 'attributekey'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 15:06:44","sources":[{"name":"Wordfence","remoteId":"4c716fd3-6297-4b3a-a796-65f68f2986cf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4c716fd3-6297-4b3a-a796-65f68f2986cf?source=api-prod","cve":"CVE-2026-3456","affectedVersions":"<=1.2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/93495395-42cc-4787-be95-4691ff77d01b/geeky-bot","title":"GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content <= 1.2.2 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"93495395-42cc-4787-be95-4691ff77d01b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/93495395-42cc-4787-be95-4691ff77d01b?source=api-prod","cve":"CVE-2026-40772","affectedVersions":"<=1.2.2","severity":"high"},{"advisoryId":"WPSECADV/WF/a1817c58-e807-4ef2-a382-28ca2fd5239e/geeky-bot","title":"GeekyBot <= 1.2.2 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation via 'geekybot_frontendajax' AJAX Action\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 15:26:29","sources":[{"name":"Wordfence","remoteId":"a1817c58-e807-4ef2-a382-28ca2fd5239e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a1817c58-e807-4ef2-a382-28ca2fd5239e?source=api-prod","cve":"CVE-2026-5294","affectedVersions":"<=1.2.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/b30e84db-c73f-4df2-9c88-c37a7e14c95b/geeky-bot","title":"GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation <= 1.1.8 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-13 17:20:05","sources":[{"name":"Wordfence","remoteId":"b30e84db-c73f-4df2-9c88-c37a7e14c95b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b30e84db-c73f-4df2-9c88-c37a7e14c95b?source=api-prod","cve":"CVE-2025-15266","affectedVersions":"<=1.1.8","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_67656e6572617465626c6f636b73811c9dc5_gen.json b/internal/data/assets/plugin_67656e6572617465626c6f636b73811c9dc5_gen.json index 6aaea091..8f491fc9 100644 --- a/internal/data/assets/plugin_67656e6572617465626c6f636b73811c9dc5_gen.json +++ b/internal/data/assets/plugin_67656e6572617465626c6f636b73811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/4f6f2a8c-ecd9-482c-a32e-0c3d7a7e4ec4/generateblocks","title":"GenerateBlocks <= 1.9.1 - Authenticated (Contributor+) Sensitive Information Exposure via 'get_image_description'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"4f6f2a8c-ecd9-482c-a32e-0c3d7a7e4ec4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4f6f2a8c-ecd9-482c-a32e-0c3d7a7e4ec4?source=api-prod","cve":"CVE-2024-13546","affectedVersions":"<=1.9.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/5f1ba1c7-de88-4070-a4ec-fbe4a0c30920/generateblocks","title":"GenerateBlocks <= 2.1.1 - Improper Authorization to Authenticated (Contributor+) Arbitrary Options Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"5f1ba1c7-de88-4070-a4ec-fbe4a0c30920"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5f1ba1c7-de88-4070-a4ec-fbe4a0c30920?source=api-prod","cve":"CVE-2025-11879","affectedVersions":"<=2.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/62f19301-2311-4989-a5f2-9f845b72dd54/generateblocks","title":"GenerateBlocks <= 1.8.2 - Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"62f19301-2311-4989-a5f2-9f845b72dd54"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62f19301-2311-4989-a5f2-9f845b72dd54?source=api-prod","cve":"CVE-2024-1452","affectedVersions":"<=1.8.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/6affdb56-39cc-4749-b7cb-b80b7666f028/generateblocks","title":"GenerateBlocks <= 2.1.2 - Authenticated (Contributor+) Information Exposure via Metadata\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-12 14:28:54","sources":[{"name":"Wordfence","remoteId":"6affdb56-39cc-4749-b7cb-b80b7666f028"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6affdb56-39cc-4749-b7cb-b80b7666f028?source=api-prod","cve":"CVE-2025-12512","affectedVersions":"<=2.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/ffd3ecc8-8b76-453f-b2e9-a9c70c58edbf/generateblocks","title":"GenerateBlocks <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"ffd3ecc8-8b76-453f-b2e9-a9c70c58edbf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ffd3ecc8-8b76-453f-b2e9-a9c70c58edbf?source=api-prod","cve":"CVE-2021-24751","affectedVersions":"<=1.3.5","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0297d524-e016-4f8d-920c-d58c62edb2a0/generateblocks","title":"GenerateBlocks <= 2.2.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via Dynamic Tag Replacements\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 17:58:25","sources":[{"name":"Wordfence","remoteId":"0297d524-e016-4f8d-920c-d58c62edb2a0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0297d524-e016-4f8d-920c-d58c62edb2a0?source=api-prod","cve":"CVE-2026-3454","affectedVersions":"<=2.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/4f6f2a8c-ecd9-482c-a32e-0c3d7a7e4ec4/generateblocks","title":"GenerateBlocks <= 1.9.1 - Authenticated (Contributor+) Sensitive Information Exposure via 'get_image_description'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"4f6f2a8c-ecd9-482c-a32e-0c3d7a7e4ec4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4f6f2a8c-ecd9-482c-a32e-0c3d7a7e4ec4?source=api-prod","cve":"CVE-2024-13546","affectedVersions":"<=1.9.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/5f1ba1c7-de88-4070-a4ec-fbe4a0c30920/generateblocks","title":"GenerateBlocks <= 2.1.1 - Improper Authorization to Authenticated (Contributor+) Arbitrary Options Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"5f1ba1c7-de88-4070-a4ec-fbe4a0c30920"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5f1ba1c7-de88-4070-a4ec-fbe4a0c30920?source=api-prod","cve":"CVE-2025-11879","affectedVersions":"<=2.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/62f19301-2311-4989-a5f2-9f845b72dd54/generateblocks","title":"GenerateBlocks <= 1.8.2 - Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"62f19301-2311-4989-a5f2-9f845b72dd54"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62f19301-2311-4989-a5f2-9f845b72dd54?source=api-prod","cve":"CVE-2024-1452","affectedVersions":"<=1.8.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/6affdb56-39cc-4749-b7cb-b80b7666f028/generateblocks","title":"GenerateBlocks <= 2.1.2 - Authenticated (Contributor+) Information Exposure via Metadata\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-12 14:28:54","sources":[{"name":"Wordfence","remoteId":"6affdb56-39cc-4749-b7cb-b80b7666f028"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6affdb56-39cc-4749-b7cb-b80b7666f028?source=api-prod","cve":"CVE-2025-12512","affectedVersions":"<=2.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/ffd3ecc8-8b76-453f-b2e9-a9c70c58edbf/generateblocks","title":"GenerateBlocks <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"ffd3ecc8-8b76-453f-b2e9-a9c70c58edbf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ffd3ecc8-8b76-453f-b2e9-a9c70c58edbf?source=api-prod","cve":"CVE-2021-24751","affectedVersions":"<=1.3.5","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_677574656e7665727365811c9dc5_gen.json b/internal/data/assets/plugin_677574656e7665727365811c9dc5_gen.json index 6067bec5..e409f6c7 100644 --- a/internal/data/assets/plugin_677574656e7665727365811c9dc5_gen.json +++ b/internal/data/assets/plugin_677574656e7665727365811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/3a152cbd-1452-483c-8780-afa8054c3686/gutenverse","title":"Gutenverse <= 1.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"3a152cbd-1452-483c-8780-afa8054c3686"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3a152cbd-1452-483c-8780-afa8054c3686?source=api-prod","cve":"CVE-2024-38785","affectedVersions":"<=1.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/4c4e1d2c-bb20-40b7-90a3-96df68d083b8/gutenverse","title":"Gutenverse <= 1.8.5 - Missing Authorization via 'data/update' API Endpoint\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"4c4e1d2c-bb20-40b7-90a3-96df68d083b8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4c4e1d2c-bb20-40b7-90a3-96df68d083b8?source=api-prod","cve":"CVE-2023-35875","affectedVersions":"<=1.8.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/690e7f00-d9db-4912-9438-7fcbcb026800/gutenverse","title":"Gutenverse <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via countdown Block\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-28 17:26:18","sources":[{"name":"Wordfence","remoteId":"690e7f00-d9db-4912-9438-7fcbcb026800"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/690e7f00-d9db-4912-9438-7fcbcb026800?source=api-prod","cve":"CVE-2025-2893","affectedVersions":"<=2.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/76cfe806-a8d9-4249-b2d0-eb3a314ca69a/gutenverse","title":"Gutenverse <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Fun Fact Blocks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-05 17:41:10","sources":[{"name":"Wordfence","remoteId":"76cfe806-a8d9-4249-b2d0-eb3a314ca69a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/76cfe806-a8d9-4249-b2d0-eb3a314ca69a?source=api-prod","cve":"CVE-2025-7727","affectedVersions":"<=3.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/8056af63-e81f-4321-991e-d201ad1095c4/gutenverse","title":"Gutenverse <= 1.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"8056af63-e81f-4321-991e-d201ad1095c4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8056af63-e81f-4321-991e-d201ad1095c4?source=api-prod","cve":"CVE-2024-3692","affectedVersions":"<=1.9.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/89100b33-0e27-4a04-9407-8505524e7e45/gutenverse","title":"Gutenverse <= 3.2.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"89100b33-0e27-4a04-9407-8505524e7e45"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/89100b33-0e27-4a04-9407-8505524e7e45?source=api-prod","cve":"CVE-2025-66065","affectedVersions":"<=3.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/950f7493-4ccb-4a8a-9cc2-23b9ba3a9cd0/gutenverse","title":"Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'imageLoad'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-03 13:45:17","sources":[{"name":"Wordfence","remoteId":"950f7493-4ccb-4a8a-9cc2-23b9ba3a9cd0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/950f7493-4ccb-4a8a-9cc2-23b9ba3a9cd0?source=api-prod","cve":"CVE-2026-2924","affectedVersions":"<=3.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/d8f40034-c868-4337-bf0a-385a961f9c35/gutenverse","title":"Gutenverse <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"d8f40034-c868-4337-bf0a-385a961f9c35"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d8f40034-c868-4337-bf0a-385a961f9c35?source=api-prod","cve":"CVE-2024-43920","affectedVersions":"<=1.9.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/3a152cbd-1452-483c-8780-afa8054c3686/gutenverse","title":"Gutenverse <= 1.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"3a152cbd-1452-483c-8780-afa8054c3686"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3a152cbd-1452-483c-8780-afa8054c3686?source=api-prod","cve":"CVE-2024-38785","affectedVersions":"<=1.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/4c4e1d2c-bb20-40b7-90a3-96df68d083b8/gutenverse","title":"Gutenverse <= 1.8.5 - Missing Authorization via 'data/update' API Endpoint\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"4c4e1d2c-bb20-40b7-90a3-96df68d083b8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4c4e1d2c-bb20-40b7-90a3-96df68d083b8?source=api-prod","cve":"CVE-2023-35875","affectedVersions":"<=1.8.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/690e7f00-d9db-4912-9438-7fcbcb026800/gutenverse","title":"Gutenverse <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via countdown Block\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-28 17:26:18","sources":[{"name":"Wordfence","remoteId":"690e7f00-d9db-4912-9438-7fcbcb026800"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/690e7f00-d9db-4912-9438-7fcbcb026800?source=api-prod","cve":"CVE-2025-2893","affectedVersions":"<=2.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/76cfe806-a8d9-4249-b2d0-eb3a314ca69a/gutenverse","title":"Gutenverse <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Fun Fact Blocks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-05 17:41:10","sources":[{"name":"Wordfence","remoteId":"76cfe806-a8d9-4249-b2d0-eb3a314ca69a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/76cfe806-a8d9-4249-b2d0-eb3a314ca69a?source=api-prod","cve":"CVE-2025-7727","affectedVersions":"<=3.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/8056af63-e81f-4321-991e-d201ad1095c4/gutenverse","title":"Gutenverse <= 1.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"8056af63-e81f-4321-991e-d201ad1095c4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8056af63-e81f-4321-991e-d201ad1095c4?source=api-prod","cve":"CVE-2024-3692","affectedVersions":"<=1.9.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/89100b33-0e27-4a04-9407-8505524e7e45/gutenverse","title":"Gutenverse <= 3.2.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"89100b33-0e27-4a04-9407-8505524e7e45"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/89100b33-0e27-4a04-9407-8505524e7e45?source=api-prod","cve":"CVE-2025-66065","affectedVersions":"<=3.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/950f7493-4ccb-4a8a-9cc2-23b9ba3a9cd0/gutenverse","title":"Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'imageLoad'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-03 13:45:17","sources":[{"name":"Wordfence","remoteId":"950f7493-4ccb-4a8a-9cc2-23b9ba3a9cd0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/950f7493-4ccb-4a8a-9cc2-23b9ba3a9cd0?source=api-prod","cve":"CVE-2026-2924","affectedVersions":"<=3.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/ac909a4b-d949-42eb-871a-963bc6242c12/gutenverse","title":"Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (Contributor+) Server-Side Request Forgery via 'imageUrl'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:51:49","sources":[{"name":"Wordfence","remoteId":"ac909a4b-d949-42eb-871a-963bc6242c12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ac909a4b-d949-42eb-871a-963bc6242c12?source=api-prod","cve":"CVE-2026-2948","affectedVersions":"<=3.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/cc540e5c-180f-4743-b1fb-608aa0e3ae79/gutenverse","title":"Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'separatorIconSVG'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:22:31","sources":[{"name":"Wordfence","remoteId":"cc540e5c-180f-4743-b1fb-608aa0e3ae79"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc540e5c-180f-4743-b1fb-608aa0e3ae79?source=api-prod","cve":"CVE-2026-2868","affectedVersions":"<=3.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/d8f40034-c868-4337-bf0a-385a961f9c35/gutenverse","title":"Gutenverse <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"d8f40034-c868-4337-bf0a-385a961f9c35"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d8f40034-c868-4337-bf0a-385a961f9c35?source=api-prod","cve":"CVE-2024-43920","affectedVersions":"<=1.9.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_68636170746368612d666f722d666f726d732d616e642d6d6f7265811c9dc5_gen.json b/internal/data/assets/plugin_68636170746368612d666f722d666f726d732d616e642d6d6f7265811c9dc5_gen.json index b74f0eb1..df8e1fd0 100644 --- a/internal/data/assets/plugin_68636170746368612d666f722d666f726d732d616e642d6d6f7265811c9dc5_gen.json +++ b/internal/data/assets/plugin_68636170746368612d666f722d666f726d732d616e642d6d6f7265811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/5ce70e87-6dee-4d4a-b2fc-93fd4d50957d/hcaptcha-for-forms-and-more","title":"hCaptcha for WordPress <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via cf7-hcaptcha Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"5ce70e87-6dee-4d4a-b2fc-93fd4d50957d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ce70e87-6dee-4d4a-b2fc-93fd4d50957d?source=api-prod","cve":"CVE-2024-4014","affectedVersions":"<=4.0.0","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/5ce70e87-6dee-4d4a-b2fc-93fd4d50957d/hcaptcha-for-forms-and-more","title":"hCaptcha for WordPress <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via cf7-hcaptcha Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"5ce70e87-6dee-4d4a-b2fc-93fd4d50957d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ce70e87-6dee-4d4a-b2fc-93fd4d50957d?source=api-prod","cve":"CVE-2024-4014","affectedVersions":"<=4.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/7235f5b9-43a6-4290-a6b6-f93ed8c7fa5d/hcaptcha-for-forms-and-more","title":"hCaptcha for WP <= 4.22.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"7235f5b9-43a6-4290-a6b6-f93ed8c7fa5d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7235f5b9-43a6-4290-a6b6-f93ed8c7fa5d?source=api-prod","cve":"CVE-2026-25315","affectedVersions":"<=4.22.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_697468656d65732d73796e63811c9dc5_gen.json b/internal/data/assets/plugin_697468656d65732d73796e63811c9dc5_gen.json index 89584a5d..b530f788 100644 --- a/internal/data/assets/plugin_697468656d65732d73796e63811c9dc5_gen.json +++ b/internal/data/assets/plugin_697468656d65732d73796e63811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0f9229f2-e7dd-43c9-9c15-9b76c13e895b/ithemes-sync","title":"iThemes Sync <= 2.1.13 - Cross-Site Request Forgery and Missing Authorization via 'hide_authenticate_notice'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"0f9229f2-e7dd-43c9-9c15-9b76c13e895b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f9229f2-e7dd-43c9-9c15-9b76c13e895b?source=api-prod","cve":"CVE-2023-40001","affectedVersions":"<2.1.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/55234307-9d51-4fe8-bc22-78d32a5fed11/ithemes-sync","title":"Solid Central <= 3.0.0 - Stored Cross-Site Scripting via packages\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"55234307-9d51-4fe8-bc22-78d32a5fed11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/55234307-9d51-4fe8-bc22-78d32a5fed11?source=api-prod","affectedVersions":"<3.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/6fb01045-d38f-469f-8aaf-ff8882132acc/ithemes-sync","title":"iThemes Sync <= 2.0.17 - Authentication Bypass\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-10-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"6fb01045-d38f-469f-8aaf-ff8882132acc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6fb01045-d38f-469f-8aaf-ff8882132acc?source=api-prod","affectedVersions":"<2.0.18","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0f9229f2-e7dd-43c9-9c15-9b76c13e895b/ithemes-sync","title":"iThemes Sync <= 2.1.13 - Cross-Site Request Forgery and Missing Authorization via 'hide_authenticate_notice'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"0f9229f2-e7dd-43c9-9c15-9b76c13e895b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f9229f2-e7dd-43c9-9c15-9b76c13e895b?source=api-prod","cve":"CVE-2023-40001","affectedVersions":"<2.1.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/55234307-9d51-4fe8-bc22-78d32a5fed11/ithemes-sync","title":"Solid Central <= 3.0.0 - Stored Cross-Site Scripting via packages\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"55234307-9d51-4fe8-bc22-78d32a5fed11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/55234307-9d51-4fe8-bc22-78d32a5fed11?source=api-prod","affectedVersions":"<3.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/6fb01045-d38f-469f-8aaf-ff8882132acc/ithemes-sync","title":"iThemes Sync <= 2.0.17 - Authentication Bypass\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-10-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"6fb01045-d38f-469f-8aaf-ff8882132acc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6fb01045-d38f-469f-8aaf-ff8882132acc?source=api-prod","affectedVersions":"<2.0.18","severity":"critical"},{"advisoryId":"WPSECADV/WF/aec4559a-4d96-49d3-8dc3-0210c78a798e/ithemes-sync","title":"Solid Central – Site Management, Backups, Security, and Reporting <= 3.2.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"aec4559a-4d96-49d3-8dc3-0210c78a798e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aec4559a-4d96-49d3-8dc3-0210c78a798e?source=api-prod","cve":"CVE-2026-27056","affectedVersions":"<=3.2.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6a65742d656e67696e65811c9dc5_gen.json b/internal/data/assets/plugin_6a65742d656e67696e65811c9dc5_gen.json index 83f59ce8..13d36581 100644 --- a/internal/data/assets/plugin_6a65742d656e67696e65811c9dc5_gen.json +++ b/internal/data/assets/plugin_6a65742d656e67696e65811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/099e8784-48d2-4be7-9549-b9dbe57fe637/jet-engine","title":"JetEngine <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"099e8784-48d2-4be7-9549-b9dbe57fe637"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/099e8784-48d2-4be7-9549-b9dbe57fe637?source=api-prod","cve":"CVE-2025-49938","affectedVersions":"<=3.7.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/0ef8f81e-b241-43c3-9045-610cdbc08be1/jet-engine","title":"JetEngine <= 3.6.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"0ef8f81e-b241-43c3-9045-610cdbc08be1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0ef8f81e-b241-43c3-9045-610cdbc08be1?source=api-prod","cve":"CVE-2025-26870","affectedVersions":"<=3.6.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/1c1e1c18-fecd-45a9-a515-11073c9f1aec/jet-engine","title":"JetEngine <= 3.7.0 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c1e1c18-fecd-45a9-a515-11073c9f1aec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c1e1c18-fecd-45a9-a515-11073c9f1aec?source=api-prod","cve":"CVE-2025-53196","affectedVersions":"<=3.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/1c85e5e0-d8ee-46d3-99b1-df6c6744f020/jet-engine","title":"Multiple Plugins by Crocoblock <= (Various Versions) - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c85e5e0-d8ee-46d3-99b1-df6c6744f020"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c85e5e0-d8ee-46d3-99b1-df6c6744f020?source=api-prod","cve":"CVE-2023-48762","affectedVersions":"<=3.2.5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/29a5701f-92f7-4a02-a990-b189a381cff5/jet-engine","title":"JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via '_cct_search' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-13 12:57:24","sources":[{"name":"Wordfence","remoteId":"29a5701f-92f7-4a02-a990-b189a381cff5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/29a5701f-92f7-4a02-a990-b189a381cff5?source=api-prod","cve":"CVE-2026-4352","affectedVersions":"<=3.8.6.1","severity":"high"},{"advisoryId":"WPSECADV/WF/3f2c97f4-0a6e-4693-a6c8-bd81ca76988c/jet-engine","title":"JetEngine <= 3.2.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"3f2c97f4-0a6e-4693-a6c8-bd81ca76988c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3f2c97f4-0a6e-4693-a6c8-bd81ca76988c?source=api-prod","cve":"CVE-2023-48758","affectedVersions":"<=3.2.4","severity":"high"},{"advisoryId":"WPSECADV/WF/40abaa5e-7dd5-4a4e-877c-0a56386f5ffe/jet-engine","title":"JetEngine <= 3.7.7 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"40abaa5e-7dd5-4a4e-877c-0a56386f5ffe"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/40abaa5e-7dd5-4a4e-877c-0a56386f5ffe?source=api-prod","cve":"CVE-2025-67923","affectedVersions":"<=3.7.7","severity":"high"},{"advisoryId":"WPSECADV/WF/594431b7-9bc7-4e86-bc20-311fdab657b6/jet-engine","title":"JetEngine <= 3.8.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"594431b7-9bc7-4e86-bc20-311fdab657b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/594431b7-9bc7-4e86-bc20-311fdab657b6?source=api-prod","cve":"CVE-2025-68495","affectedVersions":"<=3.8.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/84875591-2754-4415-9a77-8824fdfa89dd/jet-engine","title":"JetEngine <= 3.8.1.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"84875591-2754-4415-9a77-8824fdfa89dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/84875591-2754-4415-9a77-8824fdfa89dd?source=api-prod","cve":"CVE-2025-69333","affectedVersions":"<=3.8.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/893500ba-cc16-4429-bbe1-725aa65589c9/jet-engine","title":"Multiple Plugins by Crocoblock <= (Various Versions) - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"893500ba-cc16-4429-bbe1-725aa65589c9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/893500ba-cc16-4429-bbe1-725aa65589c9?source=api-prod","cve":"CVE-2023-48761","affectedVersions":"<=3.2.5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8ad473d5-f54b-4801-9ba3-54e4dddf26f7/jet-engine","title":"JetEngine <= 3.7.1 - Authenticated (Contributor+) Server-Side Template Injection to Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ad473d5-f54b-4801-9ba3-54e4dddf26f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ad473d5-f54b-4801-9ba3-54e4dddf26f7?source=api-prod","cve":"CVE-2025-53194","affectedVersions":"<=3.7.1","severity":"high"},{"advisoryId":"WPSECADV/WF/9a4f28bb-7669-483a-b93a-276b7a10826a/jet-engine","title":"JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"9a4f28bb-7669-483a-b93a-276b7a10826a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9a4f28bb-7669-483a-b93a-276b7a10826a?source=api-prod","cve":"CVE-2026-28134","affectedVersions":"<=3.7.2","severity":"high"},{"advisoryId":"WPSECADV/WF/ad66015d-7831-4590-9583-3abf7ca43c3b/jet-engine","title":"JetEngine <= 3.2.4 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad66015d-7831-4590-9583-3abf7ca43c3b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad66015d-7831-4590-9583-3abf7ca43c3b?source=api-prod","cve":"CVE-2023-48757","affectedVersions":"<=3.2.4","severity":"high"},{"advisoryId":"WPSECADV/WF/d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e/jet-engine","title":"Crocoblock JetEngine <= 3.1.3 - Authenticated(Author+) Arbitrary File Upload to Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e?source=api-prod","cve":"CVE-2023-1406","affectedVersions":"<=3.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/d938b867-a29a-460b-bfc2-1ba4490ee105/jet-engine","title":"JetEngine <= 3.7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"d938b867-a29a-460b-bfc2-1ba4490ee105"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d938b867-a29a-460b-bfc2-1ba4490ee105?source=api-prod","cve":"CVE-2025-54688","affectedVersions":"<=3.7.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f10cf49b-1b78-43c1-b0d1-c1dbb74d5696/jet-engine","title":"JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 16:17:43","sources":[{"name":"Wordfence","remoteId":"f10cf49b-1b78-43c1-b0d1-c1dbb74d5696"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f10cf49b-1b78-43c1-b0d1-c1dbb74d5696?source=api-prod","cve":"CVE-2026-4662","affectedVersions":"<=3.8.6.1","severity":"high"},{"advisoryId":"WPSECADV/WF/f27979a8-0e68-4a45-9e3e-3667d88361d8/jet-engine","title":"Jet Engine <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-17 18:34:33","sources":[{"name":"Wordfence","remoteId":"f27979a8-0e68-4a45-9e3e-3667d88361d8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f27979a8-0e68-4a45-9e3e-3667d88361d8?source=api-prod","cve":"CVE-2025-0369","affectedVersions":"<=3.6.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f920d63e-2101-4192-8916-be2d42929a54/jet-engine","title":"JetEngine <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"f920d63e-2101-4192-8916-be2d42929a54"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f920d63e-2101-4192-8916-be2d42929a54?source=api-prod","cve":"CVE-2025-53195","affectedVersions":"<=3.7.0","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/099e8784-48d2-4be7-9549-b9dbe57fe637/jet-engine","title":"JetEngine <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"099e8784-48d2-4be7-9549-b9dbe57fe637"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/099e8784-48d2-4be7-9549-b9dbe57fe637?source=api-prod","cve":"CVE-2025-49938","affectedVersions":"<=3.7.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/0ef8f81e-b241-43c3-9045-610cdbc08be1/jet-engine","title":"JetEngine <= 3.6.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"0ef8f81e-b241-43c3-9045-610cdbc08be1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0ef8f81e-b241-43c3-9045-610cdbc08be1?source=api-prod","cve":"CVE-2025-26870","affectedVersions":"<=3.6.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/1c1e1c18-fecd-45a9-a515-11073c9f1aec/jet-engine","title":"JetEngine <= 3.7.0 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c1e1c18-fecd-45a9-a515-11073c9f1aec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c1e1c18-fecd-45a9-a515-11073c9f1aec?source=api-prod","cve":"CVE-2025-53196","affectedVersions":"<=3.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/1c85e5e0-d8ee-46d3-99b1-df6c6744f020/jet-engine","title":"Multiple Plugins by Crocoblock <= (Various Versions) - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c85e5e0-d8ee-46d3-99b1-df6c6744f020"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c85e5e0-d8ee-46d3-99b1-df6c6744f020?source=api-prod","cve":"CVE-2023-48762","affectedVersions":"<=3.2.5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/29a5701f-92f7-4a02-a990-b189a381cff5/jet-engine","title":"JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via '_cct_search' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-13 12:57:24","sources":[{"name":"Wordfence","remoteId":"29a5701f-92f7-4a02-a990-b189a381cff5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/29a5701f-92f7-4a02-a990-b189a381cff5?source=api-prod","cve":"CVE-2026-4352","affectedVersions":"<=3.8.6.1","severity":"high"},{"advisoryId":"WPSECADV/WF/3f2c97f4-0a6e-4693-a6c8-bd81ca76988c/jet-engine","title":"JetEngine <= 3.2.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"3f2c97f4-0a6e-4693-a6c8-bd81ca76988c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3f2c97f4-0a6e-4693-a6c8-bd81ca76988c?source=api-prod","cve":"CVE-2023-48758","affectedVersions":"<=3.2.4","severity":"high"},{"advisoryId":"WPSECADV/WF/40abaa5e-7dd5-4a4e-877c-0a56386f5ffe/jet-engine","title":"JetEngine <= 3.7.7 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"40abaa5e-7dd5-4a4e-877c-0a56386f5ffe"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/40abaa5e-7dd5-4a4e-877c-0a56386f5ffe?source=api-prod","cve":"CVE-2025-67923","affectedVersions":"<=3.7.7","severity":"high"},{"advisoryId":"WPSECADV/WF/594431b7-9bc7-4e86-bc20-311fdab657b6/jet-engine","title":"JetEngine <= 3.8.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"594431b7-9bc7-4e86-bc20-311fdab657b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/594431b7-9bc7-4e86-bc20-311fdab657b6?source=api-prod","cve":"CVE-2025-68495","affectedVersions":"<=3.8.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/84875591-2754-4415-9a77-8824fdfa89dd/jet-engine","title":"JetEngine <= 3.8.1.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"84875591-2754-4415-9a77-8824fdfa89dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/84875591-2754-4415-9a77-8824fdfa89dd?source=api-prod","cve":"CVE-2025-69333","affectedVersions":"<=3.8.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/893500ba-cc16-4429-bbe1-725aa65589c9/jet-engine","title":"Multiple Plugins by Crocoblock <= (Various Versions) - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"893500ba-cc16-4429-bbe1-725aa65589c9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/893500ba-cc16-4429-bbe1-725aa65589c9?source=api-prod","cve":"CVE-2023-48761","affectedVersions":"<=3.2.5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8ad473d5-f54b-4801-9ba3-54e4dddf26f7/jet-engine","title":"JetEngine <= 3.7.1 - Authenticated (Contributor+) Server-Side Template Injection to Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ad473d5-f54b-4801-9ba3-54e4dddf26f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ad473d5-f54b-4801-9ba3-54e4dddf26f7?source=api-prod","cve":"CVE-2025-53194","affectedVersions":"<=3.7.1","severity":"high"},{"advisoryId":"WPSECADV/WF/9a4f28bb-7669-483a-b93a-276b7a10826a/jet-engine","title":"JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"9a4f28bb-7669-483a-b93a-276b7a10826a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9a4f28bb-7669-483a-b93a-276b7a10826a?source=api-prod","cve":"CVE-2026-28134","affectedVersions":"<=3.7.2","severity":"high"},{"advisoryId":"WPSECADV/WF/ad66015d-7831-4590-9583-3abf7ca43c3b/jet-engine","title":"JetEngine <= 3.2.4 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad66015d-7831-4590-9583-3abf7ca43c3b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad66015d-7831-4590-9583-3abf7ca43c3b?source=api-prod","cve":"CVE-2023-48757","affectedVersions":"<=3.2.4","severity":"high"},{"advisoryId":"WPSECADV/WF/d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e/jet-engine","title":"Crocoblock JetEngine <= 3.1.3 - Authenticated(Author+) Arbitrary File Upload to Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e?source=api-prod","cve":"CVE-2023-1406","affectedVersions":"<=3.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/d938b867-a29a-460b-bfc2-1ba4490ee105/jet-engine","title":"JetEngine <= 3.7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"d938b867-a29a-460b-bfc2-1ba4490ee105"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d938b867-a29a-460b-bfc2-1ba4490ee105?source=api-prod","cve":"CVE-2025-54688","affectedVersions":"<=3.7.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e37cabad-c41c-4fba-b01d-a5eb5c7d5254/jet-engine","title":"JetEngine <= 3.8.8.1 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"e37cabad-c41c-4fba-b01d-a5eb5c7d5254"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e37cabad-c41c-4fba-b01d-a5eb5c7d5254?source=api-prod","cve":"CVE-2026-42774","affectedVersions":"<=3.8.8.1","severity":"high"},{"advisoryId":"WPSECADV/WF/f10cf49b-1b78-43c1-b0d1-c1dbb74d5696/jet-engine","title":"JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 16:17:43","sources":[{"name":"Wordfence","remoteId":"f10cf49b-1b78-43c1-b0d1-c1dbb74d5696"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f10cf49b-1b78-43c1-b0d1-c1dbb74d5696?source=api-prod","cve":"CVE-2026-4662","affectedVersions":"<=3.8.6.1","severity":"high"},{"advisoryId":"WPSECADV/WF/f27979a8-0e68-4a45-9e3e-3667d88361d8/jet-engine","title":"Jet Engine <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-17 18:34:33","sources":[{"name":"Wordfence","remoteId":"f27979a8-0e68-4a45-9e3e-3667d88361d8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f27979a8-0e68-4a45-9e3e-3667d88361d8?source=api-prod","cve":"CVE-2025-0369","affectedVersions":"<=3.6.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f920d63e-2101-4192-8916-be2d42929a54/jet-engine","title":"JetEngine <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"f920d63e-2101-4192-8916-be2d42929a54"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f920d63e-2101-4192-8916-be2d42929a54?source=api-prod","cve":"CVE-2025-53195","affectedVersions":"<=3.7.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6a6f6f6d73706f72742d73706f7274732d6c65616775652d726573756c74732d6d616e6167656d656e74811c9dc5_gen.json b/internal/data/assets/plugin_6a6f6f6d73706f72742d73706f7274732d6c65616775652d726573756c74732d6d616e6167656d656e74811c9dc5_gen.json index 89faec2d..99a40971 100644 --- a/internal/data/assets/plugin_6a6f6f6d73706f72742d73706f7274732d6c65616775652d726573756c74732d6d616e6167656d656e74811c9dc5_gen.json +++ b/internal/data/assets/plugin_6a6f6f6d73706f72742d73706f7274732d6c65616775652d726573756c74732d6d616e6167656d656e74811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/31ca2de5-d63c-4ff8-9963-b96213d17cd0/joomsport-sports-league-results-management","title":"JoomSport – for Sports: Team & League, Football, Hockey & more < 3.4 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-07-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"31ca2de5-d63c-4ff8-9963-b96213d17cd0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/31ca2de5-d63c-4ff8-9963-b96213d17cd0?source=api-prod","cve":"CVE-2019-14348","affectedVersions":"<3.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/3f202cc3-ab74-4abb-9eed-b4caf9fccb71/joomsport-sports-league-results-management","title":"JoomSport <= 5.2.7 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"3f202cc3-ab74-4abb-9eed-b4caf9fccb71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3f202cc3-ab74-4abb-9eed-b4caf9fccb71?source=api-prod","cve":"CVE-2022-4050","affectedVersions":"<=5.2.7","severity":"critical"},{"advisoryId":"WPSECADV/WF/4f3900c7-2acb-4031-9854-b0b13e172e1f/joomsport-sports-league-results-management","title":"JoomSport <= 5.7.3 - Unauthenticated Directory Traversal to Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-02 22:17:24","sources":[{"name":"Wordfence","remoteId":"4f3900c7-2acb-4031-9854-b0b13e172e1f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4f3900c7-2acb-4031-9854-b0b13e172e1f?source=api-prod","cve":"CVE-2025-7721","affectedVersions":"<=5.7.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/9b6cf4ab-9e4d-4fd7-9e9e-c678ccc4d810/joomsport-sports-league-results-management","title":"JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 - Authentciated (Admin+) SQL Injection via orderby\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"9b6cf4ab-9e4d-4fd7-9e9e-c678ccc4d810"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9b6cf4ab-9e4d-4fd7-9e9e-c678ccc4d810?source=api-prod","cve":"CVE-2022-2717","affectedVersions":"<=5.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/9eee9bec-609a-468b-8b44-ac4af409df93/joomsport-sports-league-results-management","title":"JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 - Authenticated (Admin+) SQL Injection via orderby\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"9eee9bec-609a-468b-8b44-ac4af409df93"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9eee9bec-609a-468b-8b44-ac4af409df93?source=api-prod","cve":"CVE-2022-2718","affectedVersions":"<=5.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/b4503e2c-0d0d-45de-a597-baace44a98a7/joomsport-sports-league-results-management","title":"JoomSport <= 5.6.17 - Reflected Cross-Site Scripting via page\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"b4503e2c-0d0d-45de-a597-baace44a98a7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b4503e2c-0d0d-45de-a597-baace44a98a7?source=api-prod","cve":"CVE-2024-12633","affectedVersions":"<=5.6.17","severity":"high"},{"advisoryId":"WPSECADV/WF/b96273e8-29a8-4802-8c83-1ce5ab9600b6/joomsport-sports-league-results-management","title":"JoomSport <= 5.3.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"b96273e8-29a8-4802-8c83-1ce5ab9600b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b96273e8-29a8-4802-8c83-1ce5ab9600b6?source=api-prod","cve":"CVE-2024-43355","affectedVersions":"<=5.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca7e7419-5e1f-42f3-8dad-78d536b36888/joomsport-sports-league-results-management","title":"JoomSport <= 5.6.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca7e7419-5e1f-42f3-8dad-78d536b36888"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca7e7419-5e1f-42f3-8dad-78d536b36888?source=api-prod","cve":"CVE-2024-44031","affectedVersions":"<=5.6.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/d5400ec0-383b-4ac5-9b38-44533519e44d/joomsport-sports-league-results-management","title":"JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.1.7 - Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-06-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"d5400ec0-383b-4ac5-9b38-44533519e44d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d5400ec0-383b-4ac5-9b38-44533519e44d?source=api-prod","cve":"CVE-2021-24384","affectedVersions":"<5.1.8","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/31ca2de5-d63c-4ff8-9963-b96213d17cd0/joomsport-sports-league-results-management","title":"JoomSport – for Sports: Team & League, Football, Hockey & more < 3.4 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-07-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"31ca2de5-d63c-4ff8-9963-b96213d17cd0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/31ca2de5-d63c-4ff8-9963-b96213d17cd0?source=api-prod","cve":"CVE-2019-14348","affectedVersions":"<3.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/3f202cc3-ab74-4abb-9eed-b4caf9fccb71/joomsport-sports-league-results-management","title":"JoomSport <= 5.2.7 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"3f202cc3-ab74-4abb-9eed-b4caf9fccb71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3f202cc3-ab74-4abb-9eed-b4caf9fccb71?source=api-prod","cve":"CVE-2022-4050","affectedVersions":"<=5.2.7","severity":"critical"},{"advisoryId":"WPSECADV/WF/4f3900c7-2acb-4031-9854-b0b13e172e1f/joomsport-sports-league-results-management","title":"JoomSport <= 5.7.3 - Unauthenticated Directory Traversal to Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-02 22:17:24","sources":[{"name":"Wordfence","remoteId":"4f3900c7-2acb-4031-9854-b0b13e172e1f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4f3900c7-2acb-4031-9854-b0b13e172e1f?source=api-prod","cve":"CVE-2025-7721","affectedVersions":"<=5.7.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/9b6cf4ab-9e4d-4fd7-9e9e-c678ccc4d810/joomsport-sports-league-results-management","title":"JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 - Authentciated (Admin+) SQL Injection via orderby\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"9b6cf4ab-9e4d-4fd7-9e9e-c678ccc4d810"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9b6cf4ab-9e4d-4fd7-9e9e-c678ccc4d810?source=api-prod","cve":"CVE-2022-2717","affectedVersions":"<=5.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/9eee9bec-609a-468b-8b44-ac4af409df93/joomsport-sports-league-results-management","title":"JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.2.5 - Authenticated (Admin+) SQL Injection via orderby\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"9eee9bec-609a-468b-8b44-ac4af409df93"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9eee9bec-609a-468b-8b44-ac4af409df93?source=api-prod","cve":"CVE-2022-2718","affectedVersions":"<=5.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/b4503e2c-0d0d-45de-a597-baace44a98a7/joomsport-sports-league-results-management","title":"JoomSport <= 5.6.17 - Reflected Cross-Site Scripting via page\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"b4503e2c-0d0d-45de-a597-baace44a98a7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b4503e2c-0d0d-45de-a597-baace44a98a7?source=api-prod","cve":"CVE-2024-12633","affectedVersions":"<=5.6.17","severity":"high"},{"advisoryId":"WPSECADV/WF/b96273e8-29a8-4802-8c83-1ce5ab9600b6/joomsport-sports-league-results-management","title":"JoomSport <= 5.3.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"b96273e8-29a8-4802-8c83-1ce5ab9600b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b96273e8-29a8-4802-8c83-1ce5ab9600b6?source=api-prod","cve":"CVE-2024-43355","affectedVersions":"<=5.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c2b9c6ab-28b4-49c7-9dc2-32bca81300f8/joomsport-sports-league-results-management","title":"JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.7.7 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"c2b9c6ab-28b4-49c7-9dc2-32bca81300f8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c2b9c6ab-28b4-49c7-9dc2-32bca81300f8?source=api-prod","cve":"CVE-2026-42647","affectedVersions":"<=5.7.7","severity":"high"},{"advisoryId":"WPSECADV/WF/ca7e7419-5e1f-42f3-8dad-78d536b36888/joomsport-sports-league-results-management","title":"JoomSport <= 5.6.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca7e7419-5e1f-42f3-8dad-78d536b36888"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca7e7419-5e1f-42f3-8dad-78d536b36888?source=api-prod","cve":"CVE-2024-44031","affectedVersions":"<=5.6.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/d5400ec0-383b-4ac5-9b38-44533519e44d/joomsport-sports-league-results-management","title":"JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.1.7 - Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-06-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"d5400ec0-383b-4ac5-9b38-44533519e44d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d5400ec0-383b-4ac5-9b38-44533519e44d?source=api-prod","cve":"CVE-2021-24384","affectedVersions":"<5.1.8","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6c656164636f6e6e6563746f72811c9dc5_gen.json b/internal/data/assets/plugin_6c656164636f6e6e6563746f72811c9dc5_gen.json index 02552114..f17fd6b8 100644 --- a/internal/data/assets/plugin_6c656164636f6e6e6563746f72811c9dc5_gen.json +++ b/internal/data/assets/plugin_6c656164636f6e6e6563746f72811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/21552524-9f3f-4ef1-b8bc-9eb6ebfaac12/leadconnector","title":"LeadConnector < 3.0.22 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"21552524-9f3f-4ef1-b8bc-9eb6ebfaac12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/21552524-9f3f-4ef1-b8bc-9eb6ebfaac12?source=api-prod","cve":"CVE-2026-1890","affectedVersions":"<3.0.22","severity":"medium"},{"advisoryId":"WPSECADV/WF/797ec6dc-bced-48d0-b39f-4ad640b697fe/leadconnector","title":"LeadConnector <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"797ec6dc-bced-48d0-b39f-4ad640b697fe"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/797ec6dc-bced-48d0-b39f-4ad640b697fe?source=api-prod","cve":"CVE-2025-30893","affectedVersions":"<=3.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/79e786ce-a3eb-40df-8dad-4c9c75243bec/leadconnector","title":"LeadConnector <= 1.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"79e786ce-a3eb-40df-8dad-4c9c75243bec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/79e786ce-a3eb-40df-8dad-4c9c75243bec?source=api-prod","cve":"CVE-2024-1371","affectedVersions":"<=1.7","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/21552524-9f3f-4ef1-b8bc-9eb6ebfaac12/leadconnector","title":"LeadConnector < 3.0.22 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"21552524-9f3f-4ef1-b8bc-9eb6ebfaac12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/21552524-9f3f-4ef1-b8bc-9eb6ebfaac12?source=api-prod","cve":"CVE-2026-1890","affectedVersions":"<3.0.22","severity":"medium"},{"advisoryId":"WPSECADV/WF/797ec6dc-bced-48d0-b39f-4ad640b697fe/leadconnector","title":"LeadConnector <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"797ec6dc-bced-48d0-b39f-4ad640b697fe"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/797ec6dc-bced-48d0-b39f-4ad640b697fe?source=api-prod","cve":"CVE-2025-30893","affectedVersions":"<=3.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/79e786ce-a3eb-40df-8dad-4c9c75243bec/leadconnector","title":"LeadConnector <= 1.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"79e786ce-a3eb-40df-8dad-4c9c75243bec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/79e786ce-a3eb-40df-8dad-4c9c75243bec?source=api-prod","cve":"CVE-2024-1371","affectedVersions":"<=1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/e165b9ea-b7e1-43c8-8105-121e51c35a9a/leadconnector","title":"LeadConnector <= 3.0.21 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"e165b9ea-b7e1-43c8-8105-121e51c35a9a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e165b9ea-b7e1-43c8-8105-121e51c35a9a?source=api-prod","cve":"CVE-2026-25441","affectedVersions":"<=3.0.21","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6c696e6b2d77686973706572811c9dc5_gen.json b/internal/data/assets/plugin_6c696e6b2d77686973706572811c9dc5_gen.json index 7f42912b..c50d4856 100644 --- a/internal/data/assets/plugin_6c696e6b2d77686973706572811c9dc5_gen.json +++ b/internal/data/assets/plugin_6c696e6b2d77686973706572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/061eb5a2-2112-4379-8d10-1493a843c5f7/link-whisper","title":"Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"061eb5a2-2112-4379-8d10-1493a843c5f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/061eb5a2-2112-4379-8d10-1493a843c5f7?source=api-prod","cve":"CVE-2025-67927","affectedVersions":"<=0.8.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/1cb488d7-8b9d-440d-a04b-834639845eb4/link-whisper","title":"Link Whisper Free <= 0.8.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"1cb488d7-8b9d-440d-a04b-834639845eb4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1cb488d7-8b9d-440d-a04b-834639845eb4?source=api-prod","cve":"CVE-2025-62970","affectedVersions":"<=0.8.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/29b09367-6a27-4024-a71c-233aaee6c310/link-whisper","title":"Link Whisper Free <= 0.6.3 - Missing Authorization via init()\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"29b09367-6a27-4024-a71c-233aaee6c310"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/29b09367-6a27-4024-a71c-233aaee6c310?source=api-prod","cve":"CVE-2023-32506","affectedVersions":"<=0.6.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2a4289b1-ca9f-4045-a00f-50eba713b52f/link-whisper","title":"Link Whisper Free < 0.9.1 - Missing Authorization to Unauthenticated Settings Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"2a4289b1-ca9f-4045-a00f-50eba713b52f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2a4289b1-ca9f-4045-a00f-50eba713b52f?source=api-prod","cve":"CVE-2026-1900","affectedVersions":"<0.9.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/7d567665-543c-4a6b-bb07-9388fea09ee9/link-whisper","title":"Link Whisper Free <= 0.6.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"7d567665-543c-4a6b-bb07-9388fea09ee9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7d567665-543c-4a6b-bb07-9388fea09ee9?source=api-prod","cve":"CVE-2024-27992","affectedVersions":"<=0.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/7d5dd7cd-f96a-48df-a553-be5e59d8290f/link-whisper","title":"Link Whisper Free <= 0.7.1 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"7d5dd7cd-f96a-48df-a553-be5e59d8290f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7d5dd7cd-f96a-48df-a553-be5e59d8290f?source=api-prod","cve":"CVE-2024-2693","affectedVersions":"<=0.7.1","severity":"high"},{"advisoryId":"WPSECADV/WF/7e0cbef8-223a-44c0-a07f-28de2670da99/link-whisper","title":"Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-05 14:52:44","sources":[{"name":"Wordfence","remoteId":"7e0cbef8-223a-44c0-a07f-28de2670da99"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7e0cbef8-223a-44c0-a07f-28de2670da99?source=api-prod","cve":"CVE-2025-11263","affectedVersions":"<=0.8.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/8155585e-c29c-484c-ab2e-371b5723539e/link-whisper","title":"Link Whisper Free <= 0.6.9\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"8155585e-c29c-484c-ab2e-371b5723539e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8155585e-c29c-484c-ab2e-371b5723539e?source=api-prod","cve":"CVE-2024-31934","affectedVersions":"<=0.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/ad2b053b-12c0-42fa-b3da-31c824f04848/link-whisper","title":"Link Whisper Free <= 0.7.8 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad2b053b-12c0-42fa-b3da-31c824f04848"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad2b053b-12c0-42fa-b3da-31c824f04848?source=api-prod","cve":"CVE-2025-22306","affectedVersions":"<=0.7.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/c5e26a56-bba0-4204-bcb7-c5ec123a9b2d/link-whisper","title":"Link Whisper Free <= 0.6.5 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"c5e26a56-bba0-4204-bcb7-c5ec123a9b2d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c5e26a56-bba0-4204-bcb7-c5ec123a9b2d?source=api-prod","cve":"CVE-2023-47852","affectedVersions":"<=0.6.5","severity":"high"},{"advisoryId":"WPSECADV/WF/d47f7f24-2938-4af6-93b8-1aefb41bbae2/link-whisper","title":"Link Whisper Free <= 0.9.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"d47f7f24-2938-4af6-93b8-1aefb41bbae2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d47f7f24-2938-4af6-93b8-1aefb41bbae2?source=api-prod","cve":"CVE-2026-22357","affectedVersions":"<=0.9.0","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/061eb5a2-2112-4379-8d10-1493a843c5f7/link-whisper","title":"Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"061eb5a2-2112-4379-8d10-1493a843c5f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/061eb5a2-2112-4379-8d10-1493a843c5f7?source=api-prod","cve":"CVE-2025-67927","affectedVersions":"<=0.8.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/1cb488d7-8b9d-440d-a04b-834639845eb4/link-whisper","title":"Link Whisper Free <= 0.8.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"1cb488d7-8b9d-440d-a04b-834639845eb4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1cb488d7-8b9d-440d-a04b-834639845eb4?source=api-prod","cve":"CVE-2025-62970","affectedVersions":"<=0.8.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/29b09367-6a27-4024-a71c-233aaee6c310/link-whisper","title":"Link Whisper Free <= 0.6.3 - Missing Authorization via init()\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"29b09367-6a27-4024-a71c-233aaee6c310"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/29b09367-6a27-4024-a71c-233aaee6c310?source=api-prod","cve":"CVE-2023-32506","affectedVersions":"<=0.6.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2a4289b1-ca9f-4045-a00f-50eba713b52f/link-whisper","title":"Link Whisper Free < 0.9.1 - Missing Authorization to Unauthenticated Settings Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"2a4289b1-ca9f-4045-a00f-50eba713b52f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2a4289b1-ca9f-4045-a00f-50eba713b52f?source=api-prod","cve":"CVE-2026-1900","affectedVersions":"<0.9.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/7d567665-543c-4a6b-bb07-9388fea09ee9/link-whisper","title":"Link Whisper Free <= 0.6.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"7d567665-543c-4a6b-bb07-9388fea09ee9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7d567665-543c-4a6b-bb07-9388fea09ee9?source=api-prod","cve":"CVE-2024-27992","affectedVersions":"<=0.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/7d5dd7cd-f96a-48df-a553-be5e59d8290f/link-whisper","title":"Link Whisper Free <= 0.7.1 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"7d5dd7cd-f96a-48df-a553-be5e59d8290f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7d5dd7cd-f96a-48df-a553-be5e59d8290f?source=api-prod","cve":"CVE-2024-2693","affectedVersions":"<=0.7.1","severity":"high"},{"advisoryId":"WPSECADV/WF/7e0cbef8-223a-44c0-a07f-28de2670da99/link-whisper","title":"Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-05 14:52:44","sources":[{"name":"Wordfence","remoteId":"7e0cbef8-223a-44c0-a07f-28de2670da99"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7e0cbef8-223a-44c0-a07f-28de2670da99?source=api-prod","cve":"CVE-2025-11263","affectedVersions":"<=0.8.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/8155585e-c29c-484c-ab2e-371b5723539e/link-whisper","title":"Link Whisper Free <= 0.6.9\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"8155585e-c29c-484c-ab2e-371b5723539e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8155585e-c29c-484c-ab2e-371b5723539e?source=api-prod","cve":"CVE-2024-31934","affectedVersions":"<=0.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/ad2b053b-12c0-42fa-b3da-31c824f04848/link-whisper","title":"Link Whisper Free <= 0.7.8 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad2b053b-12c0-42fa-b3da-31c824f04848"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad2b053b-12c0-42fa-b3da-31c824f04848?source=api-prod","cve":"CVE-2025-22306","affectedVersions":"<=0.7.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/c5e26a56-bba0-4204-bcb7-c5ec123a9b2d/link-whisper","title":"Link Whisper Free <= 0.6.5 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"c5e26a56-bba0-4204-bcb7-c5ec123a9b2d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c5e26a56-bba0-4204-bcb7-c5ec123a9b2d?source=api-prod","cve":"CVE-2023-47852","affectedVersions":"<=0.6.5","severity":"high"},{"advisoryId":"WPSECADV/WF/d47f7f24-2938-4af6-93b8-1aefb41bbae2/link-whisper","title":"Link Whisper Free <= 0.9.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"d47f7f24-2938-4af6-93b8-1aefb41bbae2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d47f7f24-2938-4af6-93b8-1aefb41bbae2?source=api-prod","cve":"CVE-2026-22357","affectedVersions":"<=0.9.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6c6f636f2d7472616e736c617465811c9dc5_gen.json b/internal/data/assets/plugin_6c6f636f2d7472616e736c617465811c9dc5_gen.json index 0f8d273d..7da127c0 100644 --- a/internal/data/assets/plugin_6c6f636f2d7472616e736c617465811c9dc5_gen.json +++ b/internal/data/assets/plugin_6c6f636f2d7472616e736c617465811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/457865ca-cbf8-42ee-928d-2c894d9d62de/loco-translate","title":"Loco Translate <= 2.5.3 - Authenticated PHP Code Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"457865ca-cbf8-42ee-928d-2c894d9d62de"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/457865ca-cbf8-42ee-928d-2c894d9d62de?source=api-prod","cve":"CVE-2021-24721","affectedVersions":"<2.5.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/4d3b1a76-febc-4037-b31e-5987f8a23e92/loco-translate","title":"Loco Translate <= 2.6.0 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d3b1a76-febc-4037-b31e-5987f8a23e92"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d3b1a76-febc-4037-b31e-5987f8a23e92?source=api-prod","cve":"CVE-2022-0765","affectedVersions":"<2.6.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/6b83527a-aedd-4cc5-9416-1cbdfc2b8850/loco-translate","title":"Loco Translate <= 2.6.9 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"6b83527a-aedd-4cc5-9416-1cbdfc2b8850"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6b83527a-aedd-4cc5-9416-1cbdfc2b8850?source=api-prod","cve":"CVE-2024-37236","affectedVersions":"<=2.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/faa6c744-7586-47ee-b2ce-af972ee8b4f7/loco-translate","title":"Loco Translate <= 2.8.2 - Reflected Cross-Site Scripting via 'update_href' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-30 15:35:09","sources":[{"name":"Wordfence","remoteId":"faa6c744-7586-47ee-b2ce-af972ee8b4f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/faa6c744-7586-47ee-b2ce-af972ee8b4f7?source=api-prod","cve":"CVE-2026-4146","affectedVersions":"<=2.8.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/457865ca-cbf8-42ee-928d-2c894d9d62de/loco-translate","title":"Loco Translate <= 2.5.3 - Authenticated PHP Code Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"457865ca-cbf8-42ee-928d-2c894d9d62de"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/457865ca-cbf8-42ee-928d-2c894d9d62de?source=api-prod","cve":"CVE-2021-24721","affectedVersions":"<2.5.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/4d3b1a76-febc-4037-b31e-5987f8a23e92/loco-translate","title":"Loco Translate <= 2.6.0 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d3b1a76-febc-4037-b31e-5987f8a23e92"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d3b1a76-febc-4037-b31e-5987f8a23e92?source=api-prod","cve":"CVE-2022-0765","affectedVersions":"<2.6.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/6b83527a-aedd-4cc5-9416-1cbdfc2b8850/loco-translate","title":"Loco Translate <= 2.6.9 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"6b83527a-aedd-4cc5-9416-1cbdfc2b8850"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6b83527a-aedd-4cc5-9416-1cbdfc2b8850?source=api-prod","cve":"CVE-2024-37236","affectedVersions":"<=2.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/f9ff3058-a08c-40ed-b756-81e703b2277a/loco-translate","title":"Loco Translate <= 2.8.2 - Authenticated (Translator+) Path Traversal to Limited File Read via 'ref' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 13:32:17","sources":[{"name":"Wordfence","remoteId":"f9ff3058-a08c-40ed-b756-81e703b2277a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f9ff3058-a08c-40ed-b756-81e703b2277a?source=api-prod","cve":"CVE-2026-1921","affectedVersions":"<=2.8.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/faa6c744-7586-47ee-b2ce-af972ee8b4f7/loco-translate","title":"Loco Translate <= 2.8.2 - Reflected Cross-Site Scripting via 'update_href' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-30 15:35:09","sources":[{"name":"Wordfence","remoteId":"faa6c744-7586-47ee-b2ce-af972ee8b4f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/faa6c744-7586-47ee-b2ce-af972ee8b4f7?source=api-prod","cve":"CVE-2026-4146","affectedVersions":"<=2.8.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6c6f67696e2d776974682d73616c6573666f726365811c9dc5_gen.json b/internal/data/assets/plugin_6c6f67696e2d776974682d73616c6573666f726365811c9dc5_gen.json new file mode 100644 index 00000000..2e9beaba --- /dev/null +++ b/internal/data/assets/plugin_6c6f67696e2d776974682d73616c6573666f726365811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/be2ba063-140e-4c92-a57d-79f366631b3d/login-with-salesforce","title":"Login with Salesforce <= 1.0.2 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"be2ba063-140e-4c92-a57d-79f366631b3d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be2ba063-140e-4c92-a57d-79f366631b3d?source=api-prod","cve":"CVE-2026-2418","affectedVersions":"<=1.0.2","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6d656e746f72696e67811c9dc5_gen.json b/internal/data/assets/plugin_6d656e746f72696e67811c9dc5_gen.json new file mode 100644 index 00000000..9b31f20b --- /dev/null +++ b/internal/data/assets/plugin_6d656e746f72696e67811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/7192fb4c-0434-4e11-a2a7-c205b8d6b68e/mentoring","title":"Mentoring <= 1.2.8 - Unauthenticated Privilege Escalation in mentoring_process_registration\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 13:32:59","sources":[{"name":"Wordfence","remoteId":"7192fb4c-0434-4e11-a2a7-c205b8d6b68e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7192fb4c-0434-4e11-a2a7-c205b8d6b68e?source=api-prod","cve":"CVE-2025-13618","affectedVersions":"<=1.2.8","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6e696e6a612d7461626c6573811c9dc5_gen.json b/internal/data/assets/plugin_6e696e6a612d7461626c6573811c9dc5_gen.json index 44bde7d2..2e174761 100644 --- a/internal/data/assets/plugin_6e696e6a612d7461626c6573811c9dc5_gen.json +++ b/internal/data/assets/plugin_6e696e6a612d7461626c6573811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/02480559-be5c-4d23-9e62-bb76fafb4f42/ninja-tables","title":"Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"02480559-be5c-4d23-9e62-bb76fafb4f42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/02480559-be5c-4d23-9e62-bb76fafb4f42?source=api-prod","cve":"CVE-2025-2940","affectedVersions":"<=5.0.18","severity":"high"},{"advisoryId":"WPSECADV/WF/338158b5-bbda-4cd8-b4ea-97a3926a0989/ninja-tables","title":"Ninja Tables <= 4.3.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"338158b5-bbda-4cd8-b4ea-97a3926a0989"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/338158b5-bbda-4cd8-b4ea-97a3926a0989?source=api-prod","cve":"CVE-2022-47136","affectedVersions":"<=4.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/35219b1e-f716-4be8-926c-62a7c462d2eb/ninja-tables","title":"Ninja Tables <= 5.2.3 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"35219b1e-f716-4be8-926c-62a7c462d2eb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/35219b1e-f716-4be8-926c-62a7c462d2eb?source=api-prod","cve":"CVE-2025-67519","affectedVersions":"<=5.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/404fab1b-45e9-470a-a0ae-73c01386d95e/ninja-tables","title":"Ninja Tables – Easiest Data Table Builder <= 5.0.9 - Authenticated (Admin+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"404fab1b-45e9-470a-a0ae-73c01386d95e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/404fab1b-45e9-470a-a0ae-73c01386d95e?source=api-prod","cve":"CVE-2024-35635","affectedVersions":"<=5.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/49bd0848-afc0-4aa2-86a4-1b697206b925/ninja-tables","title":"Ninja Tables – Easy Data Table <= 5.0.16 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"49bd0848-afc0-4aa2-86a4-1b697206b925"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/49bd0848-afc0-4aa2-86a4-1b697206b925?source=api-prod","cve":"CVE-2024-12772","affectedVersions":"<=5.0.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/64338fc4-e8c9-4fa5-bb77-861fb5142286/ninja-tables","title":"Ninja Tables <= 4.1.7 - Admin+ Stored Cross-Site Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"64338fc4-e8c9-4fa5-bb77-861fb5142286"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/64338fc4-e8c9-4fa5-bb77-861fb5142286?source=api-prod","cve":"CVE-2021-24900","affectedVersions":"<=4.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/8b9e69f0-7b21-4cc5-924c-1556764cbb0d/ninja-tables","title":"Ninja Tables <= 5.2.4 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"8b9e69f0-7b21-4cc5-924c-1556764cbb0d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8b9e69f0-7b21-4cc5-924c-1556764cbb0d?source=api-prod","cve":"CVE-2025-69351","affectedVersions":"<=5.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/8e38553d-5dba-4c84-95f7-43420245c770/ninja-tables","title":"Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated PHP Object Injection to Limited Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e38553d-5dba-4c84-95f7-43420245c770"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e38553d-5dba-4c84-95f7-43420245c770?source=api-prod","cve":"CVE-2025-2939","affectedVersions":"<=5.0.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/b1eb6896-2de3-4d4d-9b5f-253aaffd193b/ninja-tables","title":"Ninja Tables – Easiest Data Table Builder <= 5.0.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-26 18:30:02","sources":[{"name":"Wordfence","remoteId":"b1eb6896-2de3-4d4d-9b5f-253aaffd193b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b1eb6896-2de3-4d4d-9b5f-253aaffd193b?source=api-prod","cve":"CVE-2024-7304","affectedVersions":"<=5.0.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/c86e5cfd-f450-48d6-819e-5345fc0fdfc8/ninja-tables","title":"Ninja Tables <= 5.0.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"c86e5cfd-f450-48d6-819e-5345fc0fdfc8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c86e5cfd-f450-48d6-819e-5345fc0fdfc8?source=api-prod","cve":"CVE-2024-23504","affectedVersions":"<=5.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/fc296c70-358e-4908-be49-5ffae83aca9b/ninja-tables","title":"Ninja Tables <= 4.3.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"fc296c70-358e-4908-be49-5ffae83aca9b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fc296c70-358e-4908-be49-5ffae83aca9b?source=api-prod","cve":"CVE-2022-47137","affectedVersions":"<=4.3.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/02480559-be5c-4d23-9e62-bb76fafb4f42/ninja-tables","title":"Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"02480559-be5c-4d23-9e62-bb76fafb4f42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/02480559-be5c-4d23-9e62-bb76fafb4f42?source=api-prod","cve":"CVE-2025-2940","affectedVersions":"<=5.0.18","severity":"high"},{"advisoryId":"WPSECADV/WF/338158b5-bbda-4cd8-b4ea-97a3926a0989/ninja-tables","title":"Ninja Tables <= 4.3.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"338158b5-bbda-4cd8-b4ea-97a3926a0989"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/338158b5-bbda-4cd8-b4ea-97a3926a0989?source=api-prod","cve":"CVE-2022-47136","affectedVersions":"<=4.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/35219b1e-f716-4be8-926c-62a7c462d2eb/ninja-tables","title":"Ninja Tables <= 5.2.3 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"35219b1e-f716-4be8-926c-62a7c462d2eb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/35219b1e-f716-4be8-926c-62a7c462d2eb?source=api-prod","cve":"CVE-2025-67519","affectedVersions":"<=5.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/404fab1b-45e9-470a-a0ae-73c01386d95e/ninja-tables","title":"Ninja Tables – Easiest Data Table Builder <= 5.0.9 - Authenticated (Admin+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"404fab1b-45e9-470a-a0ae-73c01386d95e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/404fab1b-45e9-470a-a0ae-73c01386d95e?source=api-prod","cve":"CVE-2024-35635","affectedVersions":"<=5.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/49bd0848-afc0-4aa2-86a4-1b697206b925/ninja-tables","title":"Ninja Tables – Easy Data Table <= 5.0.16 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"49bd0848-afc0-4aa2-86a4-1b697206b925"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/49bd0848-afc0-4aa2-86a4-1b697206b925?source=api-prod","cve":"CVE-2024-12772","affectedVersions":"<=5.0.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/64338fc4-e8c9-4fa5-bb77-861fb5142286/ninja-tables","title":"Ninja Tables <= 4.1.7 - Admin+ Stored Cross-Site Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"64338fc4-e8c9-4fa5-bb77-861fb5142286"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/64338fc4-e8c9-4fa5-bb77-861fb5142286?source=api-prod","cve":"CVE-2021-24900","affectedVersions":"<=4.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/8b9e69f0-7b21-4cc5-924c-1556764cbb0d/ninja-tables","title":"Ninja Tables <= 5.2.4 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"8b9e69f0-7b21-4cc5-924c-1556764cbb0d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8b9e69f0-7b21-4cc5-924c-1556764cbb0d?source=api-prod","cve":"CVE-2025-69351","affectedVersions":"<=5.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/8e38553d-5dba-4c84-95f7-43420245c770/ninja-tables","title":"Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated PHP Object Injection to Limited Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e38553d-5dba-4c84-95f7-43420245c770"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e38553d-5dba-4c84-95f7-43420245c770?source=api-prod","cve":"CVE-2025-2939","affectedVersions":"<=5.0.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/b1eb6896-2de3-4d4d-9b5f-253aaffd193b/ninja-tables","title":"Ninja Tables – Easiest Data Table Builder <= 5.0.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-26 18:30:02","sources":[{"name":"Wordfence","remoteId":"b1eb6896-2de3-4d4d-9b5f-253aaffd193b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b1eb6896-2de3-4d4d-9b5f-253aaffd193b?source=api-prod","cve":"CVE-2024-7304","affectedVersions":"<=5.0.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/baee1bba-c531-4a6a-8e4d-5c44e3d7e84f/ninja-tables","title":"Ninja Tables – Easy Data Table Builder <= 5.2.5 - Authenticated (Contributor+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"baee1bba-c531-4a6a-8e4d-5c44e3d7e84f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/baee1bba-c531-4a6a-8e4d-5c44e3d7e84f?source=api-prod","cve":"CVE-2026-25008","affectedVersions":"<=5.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/c86e5cfd-f450-48d6-819e-5345fc0fdfc8/ninja-tables","title":"Ninja Tables <= 5.0.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"c86e5cfd-f450-48d6-819e-5345fc0fdfc8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c86e5cfd-f450-48d6-819e-5345fc0fdfc8?source=api-prod","cve":"CVE-2024-23504","affectedVersions":"<=5.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/fc296c70-358e-4908-be49-5ffae83aca9b/ninja-tables","title":"Ninja Tables <= 4.3.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"fc296c70-358e-4908-be49-5ffae83aca9b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fc296c70-358e-4908-be49-5ffae83aca9b?source=api-prod","cve":"CVE-2022-47137","affectedVersions":"<=4.3.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6e6d656469612d757365722d66696c652d75706c6f61646572811c9dc5_gen.json b/internal/data/assets/plugin_6e6d656469612d757365722d66696c652d75706c6f61646572811c9dc5_gen.json index f48bab1b..5ccb8144 100644 --- a/internal/data/assets/plugin_6e6d656469612d757365722d66696c652d75706c6f61646572811c9dc5_gen.json +++ b/internal/data/assets/plugin_6e6d656469612d757365722d66696c652d75706c6f61646572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/28a7b2c9-5d8d-4b49-a47c-473e3288b563/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"28a7b2c9-5d8d-4b49-a47c-473e3288b563"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/28a7b2c9-5d8d-4b49-a47c-473e3288b563?source=api-prod","cve":"CVE-2021-4344","affectedVersions":"<18.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2c1e6298-f243-49a5-b1b7-52bd6a6c8858/nmedia-user-file-uploader","title":"Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"2c1e6298-f243-49a5-b1b7-52bd6a6c8858"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2c1e6298-f243-49a5-b1b7-52bd6a6c8858?source=api-prod","cve":"CVE-2016-15042","affectedVersions":"<4.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/361e2d5c-4355-4e71-91aa-2c1bc6b6fb78/nmedia-user-file-uploader","title":"Frontend File Manager Plugin <= 21.2 - Cross-Site Request Forgery to File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"361e2d5c-4355-4e71-91aa-2c1bc6b6fb78"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/361e2d5c-4355-4e71-91aa-2c1bc6b6fb78?source=api-prod","cve":"CVE-2022-3126","affectedVersions":"<=21.2","severity":"high"},{"advisoryId":"WPSECADV/WF/49150180-9de0-4318-b21b-779daaeb7a52/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Unauthenticated HTML Injection leading to Spam Emails\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"49150180-9de0-4318-b21b-779daaeb7a52"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/49150180-9de0-4318-b21b-779daaeb7a52?source=api-prod","cve":"CVE-2021-4350","affectedVersions":"<18.3","severity":"high"},{"advisoryId":"WPSECADV/WF/4cbc0dd4-4dea-4890-95d0-9531a669b95d/nmedia-user-file-uploader","title":"Frontend File Manager <= 23.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"4cbc0dd4-4dea-4890-95d0-9531a669b95d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4cbc0dd4-4dea-4890-95d0-9531a669b95d?source=api-prod","cve":"CVE-2026-0829","affectedVersions":"<=23.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/5539aa79-66ad-43fa-967c-2bec877061e0/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Unauthenticated Post Meta Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"5539aa79-66ad-43fa-967c-2bec877061e0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5539aa79-66ad-43fa-967c-2bec877061e0?source=api-prod","cve":"CVE-2021-4351","affectedVersions":"<18.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/59b63a01-fd8b-4742-a52f-c0a7b59e9e04/nmedia-user-file-uploader","title":"Frontend File Manager <= 21.3 - Cross-Site Request Forgery to Plugin Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"59b63a01-fd8b-4742-a52f-c0a7b59e9e04"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/59b63a01-fd8b-4742-a52f-c0a7b59e9e04?source=api-prod","affectedVersions":"<=21.3","severity":"high"},{"advisoryId":"WPSECADV/WF/628eef73-1725-4290-bb30-07792d1d5b6c/nmedia-user-file-uploader","title":"Frontend File Manager <= 21.2 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"628eef73-1725-4290-bb30-07792d1d5b6c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/628eef73-1725-4290-bb30-07792d1d5b6c?source=api-prod","cve":"CVE-2022-3125","affectedVersions":"<=21.2","severity":"high"},{"advisoryId":"WPSECADV/WF/79e2011c-5e4d-4d02-831f-6b4dcfcaa51e/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Unauthenticated Arbitrary File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"79e2011c-5e4d-4d02-831f-6b4dcfcaa51e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/79e2011c-5e4d-4d02-831f-6b4dcfcaa51e?source=api-prod","cve":"CVE-2021-4356","affectedVersions":"<18.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/84c61d00-20c1-4176-a74d-ea6ff6220f26/nmedia-user-file-uploader","title":"Frontend File Manager Plugin <= 18.2 - Unauthenticated Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"84c61d00-20c1-4176-a74d-ea6ff6220f26"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/84c61d00-20c1-4176-a74d-ea6ff6220f26?source=api-prod","cve":"CVE-2021-4359","affectedVersions":"<18.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/8a11c169-a232-49a9-80be-40d45d0c6dc0/nmedia-user-file-uploader","title":"Frontend File Manager Plugin < 3.6 - Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"8a11c169-a232-49a9-80be-40d45d0c6dc0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8a11c169-a232-49a9-80be-40d45d0c6dc0?source=api-prod","cve":"CVE-2014-5324","affectedVersions":"<3.6","severity":"high"},{"advisoryId":"WPSECADV/WF/8ff66981-68ed-489a-b53f-4a1029e7590e/nmedia-user-file-uploader","title":"Frontend File Manager <= 23.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ff66981-68ed-489a-b53f-4a1029e7590e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ff66981-68ed-489a-b53f-4a1029e7590e?source=api-prod","cve":"CVE-2025-57921","affectedVersions":"<=23.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9615ef3f-e1e3-4791-a5a5-19260fee6354/nmedia-user-file-uploader","title":"Frontend File Manager <= 23.4 - Authenticated (Subscriber+) Arbitrary File Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"9615ef3f-e1e3-4791-a5a5-19260fee6354"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9615ef3f-e1e3-4791-a5a5-19260fee6354?source=api-prod","cve":"CVE-2025-14804","affectedVersions":"<=23.4","severity":"high"},{"advisoryId":"WPSECADV/WF/a9c82154-d390-44ba-a54a-89f4bb69cdce/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"a9c82154-d390-44ba-a54a-89f4bb69cdce"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a9c82154-d390-44ba-a54a-89f4bb69cdce?source=api-prod","cve":"CVE-2021-4365","affectedVersions":"<18.3","severity":"high"},{"advisoryId":"WPSECADV/WF/aa8d5feb-2ae9-44b8-90b5-9fc67226855a/nmedia-user-file-uploader","title":"Frontend File Manager Plugin <= 23.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary File Renaming\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-24 19:15:11","sources":[{"name":"Wordfence","remoteId":"aa8d5feb-2ae9-44b8-90b5-9fc67226855a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa8d5feb-2ae9-44b8-90b5-9fc67226855a?source=api-prod","cve":"CVE-2025-13382","affectedVersions":"<=23.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/abf422ce-fa03-4bed-a4ec-b31d36de7633/nmedia-user-file-uploader","title":"Frontend File Manager <= 21.5 - Missing Authorization to Unauthenticated Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"abf422ce-fa03-4bed-a4ec-b31d36de7633"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/abf422ce-fa03-4bed-a4ec-b31d36de7633?source=api-prod","cve":"CVE-2023-7306","affectedVersions":"<=21.5","severity":"high"},{"advisoryId":"WPSECADV/WF/adb1d8b0-b1d6-40df-b591-f1062ee744fb/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Authenticated Settings Change leading to Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"adb1d8b0-b1d6-40df-b591-f1062ee744fb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/adb1d8b0-b1d6-40df-b591-f1062ee744fb?source=api-prod","cve":"CVE-2021-4368","affectedVersions":"<18.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/b59b5c41-6173-485e-869d-4165dc18e2bd/nmedia-user-file-uploader","title":"Frontend File Manager Plugin <= 22.5 - Authenticated (Editor+) Directory Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"b59b5c41-6173-485e-869d-4165dc18e2bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b59b5c41-6173-485e-869d-4165dc18e2bd?source=api-prod","cve":"CVE-2023-5105","affectedVersions":"<=22.5","severity":"critical"},{"advisoryId":"WPSECADV/WF/bbade634-cd81-41c0-8976-f5cb251da3f2/nmedia-user-file-uploader","title":"Frontend File Manager <= 22.7 - Sensitive Information Exposure via user uploads\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"bbade634-cd81-41c0-8976-f5cb251da3f2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bbade634-cd81-41c0-8976-f5cb251da3f2?source=api-prod","cve":"CVE-2024-25903","affectedVersions":"<=22.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/c434e6b8-0dd5-4ffe-93b1-1af614c08f85/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Unauthenticated Content Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"c434e6b8-0dd5-4ffe-93b1-1af614c08f85"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c434e6b8-0dd5-4ffe-93b1-1af614c08f85?source=api-prod","cve":"CVE-2021-4369","affectedVersions":"<18.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/c56e5250-7cbd-41f4-9b8c-79a644830708/nmedia-user-file-uploader","title":"Frontend File Manager <= 21.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"c56e5250-7cbd-41f4-9b8c-79a644830708"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c56e5250-7cbd-41f4-9b8c-79a644830708?source=api-prod","cve":"CVE-2022-3124","affectedVersions":"<=21.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/d6de5295-cb13-4e53-bcb2-3fc6c95b849a/nmedia-user-file-uploader","title":"Frontend File Manager <= 23.2 - Missing Authorization to Authenticated (Subscriber+) Content Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"d6de5295-cb13-4e53-bcb2-3fc6c95b849a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d6de5295-cb13-4e53-bcb2-3fc6c95b849a?source=api-prod","cve":"CVE-2025-27358","affectedVersions":"<=23.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e739e7d3-756a-4c93-9ca7-f7b9f9657033/nmedia-user-file-uploader","title":"Frontend File Manager Plugin <= 23.5 - Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-27 21:50:20","sources":[{"name":"Wordfence","remoteId":"e739e7d3-756a-4c93-9ca7-f7b9f9657033"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e739e7d3-756a-4c93-9ca7-f7b9f9657033?source=api-prod","cve":"CVE-2026-1280","affectedVersions":"<=23.5","severity":"high"},{"advisoryId":"WPSECADV/WF/f2ed5e51-8783-4b7f-9177-c116bf0fad44/nmedia-user-file-uploader","title":"Frontend File Manager <= 3.7 - Arbitrary File Upload\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-06-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"f2ed5e51-8783-4b7f-9177-c116bf0fad44"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2ed5e51-8783-4b7f-9177-c116bf0fad44?source=api-prod","affectedVersions":"<=3.7","severity":"critical"},{"advisoryId":"WPSECADV/WF/f8f372cb-739f-44e2-9074-e91b8c903837/nmedia-user-file-uploader","title":"Frontend File Manager <= 23.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"f8f372cb-739f-44e2-9074-e91b8c903837"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f8f372cb-739f-44e2-9074-e91b8c903837?source=api-prod","cve":"CVE-2025-64265","affectedVersions":"<=23.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/28a7b2c9-5d8d-4b49-a47c-473e3288b563/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"28a7b2c9-5d8d-4b49-a47c-473e3288b563"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/28a7b2c9-5d8d-4b49-a47c-473e3288b563?source=api-prod","cve":"CVE-2021-4344","affectedVersions":"<18.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2c1e6298-f243-49a5-b1b7-52bd6a6c8858/nmedia-user-file-uploader","title":"Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"2c1e6298-f243-49a5-b1b7-52bd6a6c8858"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2c1e6298-f243-49a5-b1b7-52bd6a6c8858?source=api-prod","cve":"CVE-2016-15042","affectedVersions":"<4.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/361e2d5c-4355-4e71-91aa-2c1bc6b6fb78/nmedia-user-file-uploader","title":"Frontend File Manager Plugin <= 21.2 - Cross-Site Request Forgery to File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"361e2d5c-4355-4e71-91aa-2c1bc6b6fb78"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/361e2d5c-4355-4e71-91aa-2c1bc6b6fb78?source=api-prod","cve":"CVE-2022-3126","affectedVersions":"<=21.2","severity":"high"},{"advisoryId":"WPSECADV/WF/49150180-9de0-4318-b21b-779daaeb7a52/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Unauthenticated HTML Injection leading to Spam Emails\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"49150180-9de0-4318-b21b-779daaeb7a52"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/49150180-9de0-4318-b21b-779daaeb7a52?source=api-prod","cve":"CVE-2021-4350","affectedVersions":"<18.3","severity":"high"},{"advisoryId":"WPSECADV/WF/4cbc0dd4-4dea-4890-95d0-9531a669b95d/nmedia-user-file-uploader","title":"Frontend File Manager <= 23.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"4cbc0dd4-4dea-4890-95d0-9531a669b95d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4cbc0dd4-4dea-4890-95d0-9531a669b95d?source=api-prod","cve":"CVE-2026-0829","affectedVersions":"<=23.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/5539aa79-66ad-43fa-967c-2bec877061e0/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Unauthenticated Post Meta Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"5539aa79-66ad-43fa-967c-2bec877061e0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5539aa79-66ad-43fa-967c-2bec877061e0?source=api-prod","cve":"CVE-2021-4351","affectedVersions":"<18.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/59b63a01-fd8b-4742-a52f-c0a7b59e9e04/nmedia-user-file-uploader","title":"Frontend File Manager <= 21.3 - Cross-Site Request Forgery to Plugin Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"59b63a01-fd8b-4742-a52f-c0a7b59e9e04"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/59b63a01-fd8b-4742-a52f-c0a7b59e9e04?source=api-prod","affectedVersions":"<=21.3","severity":"high"},{"advisoryId":"WPSECADV/WF/628eef73-1725-4290-bb30-07792d1d5b6c/nmedia-user-file-uploader","title":"Frontend File Manager <= 21.2 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"628eef73-1725-4290-bb30-07792d1d5b6c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/628eef73-1725-4290-bb30-07792d1d5b6c?source=api-prod","cve":"CVE-2022-3125","affectedVersions":"<=21.2","severity":"high"},{"advisoryId":"WPSECADV/WF/79e2011c-5e4d-4d02-831f-6b4dcfcaa51e/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Unauthenticated Arbitrary File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"79e2011c-5e4d-4d02-831f-6b4dcfcaa51e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/79e2011c-5e4d-4d02-831f-6b4dcfcaa51e?source=api-prod","cve":"CVE-2021-4356","affectedVersions":"<18.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/84c61d00-20c1-4176-a74d-ea6ff6220f26/nmedia-user-file-uploader","title":"Frontend File Manager Plugin <= 18.2 - Unauthenticated Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"84c61d00-20c1-4176-a74d-ea6ff6220f26"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/84c61d00-20c1-4176-a74d-ea6ff6220f26?source=api-prod","cve":"CVE-2021-4359","affectedVersions":"<18.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/8a11c169-a232-49a9-80be-40d45d0c6dc0/nmedia-user-file-uploader","title":"Frontend File Manager Plugin < 3.6 - Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"8a11c169-a232-49a9-80be-40d45d0c6dc0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8a11c169-a232-49a9-80be-40d45d0c6dc0?source=api-prod","cve":"CVE-2014-5324","affectedVersions":"<3.6","severity":"high"},{"advisoryId":"WPSECADV/WF/8a64d68b-8a0d-451b-ae2e-3cc583b4ed5a/nmedia-user-file-uploader","title":"Frontend File Manager Plugin <= 23.5 - Unauthenticated Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"8a64d68b-8a0d-451b-ae2e-3cc583b4ed5a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8a64d68b-8a0d-451b-ae2e-3cc583b4ed5a?source=api-prod","cve":"CVE-2026-25005","affectedVersions":"<=23.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/8ff66981-68ed-489a-b53f-4a1029e7590e/nmedia-user-file-uploader","title":"Frontend File Manager <= 23.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ff66981-68ed-489a-b53f-4a1029e7590e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ff66981-68ed-489a-b53f-4a1029e7590e?source=api-prod","cve":"CVE-2025-57921","affectedVersions":"<=23.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9615ef3f-e1e3-4791-a5a5-19260fee6354/nmedia-user-file-uploader","title":"Frontend File Manager <= 23.4 - Authenticated (Subscriber+) Arbitrary File Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"9615ef3f-e1e3-4791-a5a5-19260fee6354"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9615ef3f-e1e3-4791-a5a5-19260fee6354?source=api-prod","cve":"CVE-2025-14804","affectedVersions":"<=23.4","severity":"high"},{"advisoryId":"WPSECADV/WF/a9c82154-d390-44ba-a54a-89f4bb69cdce/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"a9c82154-d390-44ba-a54a-89f4bb69cdce"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a9c82154-d390-44ba-a54a-89f4bb69cdce?source=api-prod","cve":"CVE-2021-4365","affectedVersions":"<18.3","severity":"high"},{"advisoryId":"WPSECADV/WF/aa8d5feb-2ae9-44b8-90b5-9fc67226855a/nmedia-user-file-uploader","title":"Frontend File Manager Plugin <= 23.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary File Renaming\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-24 19:15:11","sources":[{"name":"Wordfence","remoteId":"aa8d5feb-2ae9-44b8-90b5-9fc67226855a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa8d5feb-2ae9-44b8-90b5-9fc67226855a?source=api-prod","cve":"CVE-2025-13382","affectedVersions":"<=23.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/abf422ce-fa03-4bed-a4ec-b31d36de7633/nmedia-user-file-uploader","title":"Frontend File Manager <= 21.5 - Missing Authorization to Unauthenticated Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"abf422ce-fa03-4bed-a4ec-b31d36de7633"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/abf422ce-fa03-4bed-a4ec-b31d36de7633?source=api-prod","cve":"CVE-2023-7306","affectedVersions":"<=21.5","severity":"high"},{"advisoryId":"WPSECADV/WF/adb1d8b0-b1d6-40df-b591-f1062ee744fb/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Authenticated Settings Change leading to Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"adb1d8b0-b1d6-40df-b591-f1062ee744fb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/adb1d8b0-b1d6-40df-b591-f1062ee744fb?source=api-prod","cve":"CVE-2021-4368","affectedVersions":"<18.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/b59b5c41-6173-485e-869d-4165dc18e2bd/nmedia-user-file-uploader","title":"Frontend File Manager Plugin <= 22.5 - Authenticated (Editor+) Directory Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"b59b5c41-6173-485e-869d-4165dc18e2bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b59b5c41-6173-485e-869d-4165dc18e2bd?source=api-prod","cve":"CVE-2023-5105","affectedVersions":"<=22.5","severity":"critical"},{"advisoryId":"WPSECADV/WF/bbade634-cd81-41c0-8976-f5cb251da3f2/nmedia-user-file-uploader","title":"Frontend File Manager <= 22.7 - Sensitive Information Exposure via user uploads\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"bbade634-cd81-41c0-8976-f5cb251da3f2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bbade634-cd81-41c0-8976-f5cb251da3f2?source=api-prod","cve":"CVE-2024-25903","affectedVersions":"<=22.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/c434e6b8-0dd5-4ffe-93b1-1af614c08f85/nmedia-user-file-uploader","title":"Frontend File Manager <= 18.2 - Unauthenticated Content Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"c434e6b8-0dd5-4ffe-93b1-1af614c08f85"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c434e6b8-0dd5-4ffe-93b1-1af614c08f85?source=api-prod","cve":"CVE-2021-4369","affectedVersions":"<18.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/c56e5250-7cbd-41f4-9b8c-79a644830708/nmedia-user-file-uploader","title":"Frontend File Manager <= 21.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"c56e5250-7cbd-41f4-9b8c-79a644830708"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c56e5250-7cbd-41f4-9b8c-79a644830708?source=api-prod","cve":"CVE-2022-3124","affectedVersions":"<=21.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/d6de5295-cb13-4e53-bcb2-3fc6c95b849a/nmedia-user-file-uploader","title":"Frontend File Manager <= 23.2 - Missing Authorization to Authenticated (Subscriber+) Content Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"d6de5295-cb13-4e53-bcb2-3fc6c95b849a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d6de5295-cb13-4e53-bcb2-3fc6c95b849a?source=api-prod","cve":"CVE-2025-27358","affectedVersions":"<=23.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e739e7d3-756a-4c93-9ca7-f7b9f9657033/nmedia-user-file-uploader","title":"Frontend File Manager Plugin <= 23.5 - Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-27 21:50:20","sources":[{"name":"Wordfence","remoteId":"e739e7d3-756a-4c93-9ca7-f7b9f9657033"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e739e7d3-756a-4c93-9ca7-f7b9f9657033?source=api-prod","cve":"CVE-2026-1280","affectedVersions":"<=23.5","severity":"high"},{"advisoryId":"WPSECADV/WF/f2ed5e51-8783-4b7f-9177-c116bf0fad44/nmedia-user-file-uploader","title":"Frontend File Manager <= 3.7 - Arbitrary File Upload\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-06-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"f2ed5e51-8783-4b7f-9177-c116bf0fad44"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2ed5e51-8783-4b7f-9177-c116bf0fad44?source=api-prod","affectedVersions":"<=3.7","severity":"critical"},{"advisoryId":"WPSECADV/WF/f8f372cb-739f-44e2-9074-e91b8c903837/nmedia-user-file-uploader","title":"Frontend File Manager <= 23.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"f8f372cb-739f-44e2-9074-e91b8c903837"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f8f372cb-739f-44e2-9074-e91b8c903837?source=api-prod","cve":"CVE-2025-64265","affectedVersions":"<=23.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6e6f74696669636174696f6e78811c9dc5_gen.json b/internal/data/assets/plugin_6e6f74696669636174696f6e78811c9dc5_gen.json index 5c9d5a71..06dcb889 100644 --- a/internal/data/assets/plugin_6e6f74696669636174696f6e78811c9dc5_gen.json +++ b/internal/data/assets/plugin_6e6f74696669636174696f6e78811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/338edb1d-101a-4b6e-ac25-b59bd3e17f8b/notificationx","title":"NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar <= 2.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"338edb1d-101a-4b6e-ac25-b59bd3e17f8b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/338edb1d-101a-4b6e-ac25-b59bd3e17f8b?source=api-prod","cve":"CVE-2024-11727","affectedVersions":"<=2.9.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/36dec90a-fead-48f5-a88b-dfbc6d8bffb4/notificationx","title":"NotificationX <= 2.3.11 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"36dec90a-fead-48f5-a88b-dfbc6d8bffb4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/36dec90a-fead-48f5-a88b-dfbc6d8bffb4?source=api-prod","affectedVersions":"<=2.3.11","severity":"high"},{"advisoryId":"WPSECADV/WF/3ebe7680-a76d-4178-a729-f0d79d861912/notificationx","title":"NotificationX <= 1.8.2 - Cross-Site Request Forgery Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-09-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"3ebe7680-a76d-4178-a729-f0d79d861912"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3ebe7680-a76d-4178-a729-f0d79d861912?source=api-prod","cve":"CVE-2020-36744","affectedVersions":"<1.8.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/589f5456-1d72-4eac-bd9b-2bedf4109daa/notificationx","title":"NotificationX <= 2.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"589f5456-1d72-4eac-bd9b-2bedf4109daa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/589f5456-1d72-4eac-bd9b-2bedf4109daa?source=api-prod","cve":"CVE-2025-22683","affectedVersions":"<=2.9.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/9ca12315-380b-4251-b637-4e9d29df35e0/notificationx","title":"NotificationX <= 3.2.0 - Unauthenticated DOM-Based Cross-Site Scripting via 'nx-preview'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-20 01:49:23","sources":[{"name":"Wordfence","remoteId":"9ca12315-380b-4251-b637-4e9d29df35e0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9ca12315-380b-4251-b637-4e9d29df35e0?source=api-prod","cve":"CVE-2025-15380","affectedVersions":"<=3.2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/e110ea99-e2fa-4558-bcf3-942a35af0b91/notificationx","title":"NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"e110ea99-e2fa-4558-bcf3-942a35af0b91"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e110ea99-e2fa-4558-bcf3-942a35af0b91?source=api-prod","cve":"CVE-2024-1698","affectedVersions":"<=2.8.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/e3cd843b-ab38-45c4-a661-78d4e6db5201/notificationx","title":"NotificationX <= 3.1.11 - Missing Authorization to Authenticated (Contributor+) Analytics Reset\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-20 01:50:24","sources":[{"name":"Wordfence","remoteId":"e3cd843b-ab38-45c4-a661-78d4e6db5201"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e3cd843b-ab38-45c4-a661-78d4e6db5201?source=api-prod","cve":"CVE-2026-0554","affectedVersions":"<=3.1.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/ec2eec5a-7767-4215-b77d-5cfd2d148f73/notificationx","title":"NotificationX <= 2.3.8 - Blind SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"ec2eec5a-7767-4215-b77d-5cfd2d148f73"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ec2eec5a-7767-4215-b77d-5cfd2d148f73?source=api-prod","cve":"CVE-2022-0349","affectedVersions":"<=2.3.8","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/338edb1d-101a-4b6e-ac25-b59bd3e17f8b/notificationx","title":"NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar <= 2.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"338edb1d-101a-4b6e-ac25-b59bd3e17f8b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/338edb1d-101a-4b6e-ac25-b59bd3e17f8b?source=api-prod","cve":"CVE-2024-11727","affectedVersions":"<=2.9.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/36dec90a-fead-48f5-a88b-dfbc6d8bffb4/notificationx","title":"NotificationX <= 2.3.11 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"36dec90a-fead-48f5-a88b-dfbc6d8bffb4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/36dec90a-fead-48f5-a88b-dfbc6d8bffb4?source=api-prod","affectedVersions":"<=2.3.11","severity":"high"},{"advisoryId":"WPSECADV/WF/3ebe7680-a76d-4178-a729-f0d79d861912/notificationx","title":"NotificationX <= 1.8.2 - Cross-Site Request Forgery Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-09-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"3ebe7680-a76d-4178-a729-f0d79d861912"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3ebe7680-a76d-4178-a729-f0d79d861912?source=api-prod","cve":"CVE-2020-36744","affectedVersions":"<1.8.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/589f5456-1d72-4eac-bd9b-2bedf4109daa/notificationx","title":"NotificationX <= 2.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"589f5456-1d72-4eac-bd9b-2bedf4109daa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/589f5456-1d72-4eac-bd9b-2bedf4109daa?source=api-prod","cve":"CVE-2025-22683","affectedVersions":"<=2.9.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/9ca12315-380b-4251-b637-4e9d29df35e0/notificationx","title":"NotificationX <= 3.2.0 - Unauthenticated DOM-Based Cross-Site Scripting via 'nx-preview'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-20 01:49:23","sources":[{"name":"Wordfence","remoteId":"9ca12315-380b-4251-b637-4e9d29df35e0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9ca12315-380b-4251-b637-4e9d29df35e0?source=api-prod","cve":"CVE-2025-15380","affectedVersions":"<=3.2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/c09318f1-04b2-44e5-a184-c07942ae5778/notificationx","title":"NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar <= 3.2.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"c09318f1-04b2-44e5-a184-c07942ae5778"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c09318f1-04b2-44e5-a184-c07942ae5778?source=api-prod","cve":"CVE-2026-27042","affectedVersions":"<=3.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/e110ea99-e2fa-4558-bcf3-942a35af0b91/notificationx","title":"NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"e110ea99-e2fa-4558-bcf3-942a35af0b91"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e110ea99-e2fa-4558-bcf3-942a35af0b91?source=api-prod","cve":"CVE-2024-1698","affectedVersions":"<=2.8.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/e3cd843b-ab38-45c4-a661-78d4e6db5201/notificationx","title":"NotificationX <= 3.1.11 - Missing Authorization to Authenticated (Contributor+) Analytics Reset\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-20 01:50:24","sources":[{"name":"Wordfence","remoteId":"e3cd843b-ab38-45c4-a661-78d4e6db5201"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e3cd843b-ab38-45c4-a661-78d4e6db5201?source=api-prod","cve":"CVE-2026-0554","affectedVersions":"<=3.1.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/ec2eec5a-7767-4215-b77d-5cfd2d148f73/notificationx","title":"NotificationX <= 2.3.8 - Blind SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"ec2eec5a-7767-4215-b77d-5cfd2d148f73"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ec2eec5a-7767-4215-b77d-5cfd2d148f73?source=api-prod","cve":"CVE-2022-0349","affectedVersions":"<=2.3.8","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6f6666696369616c2d6d61696c65726c6974652d7369676e2d75702d666f726d73811c9dc5_gen.json b/internal/data/assets/plugin_6f6666696369616c2d6d61696c65726c6974652d7369676e2d75702d666f726d73811c9dc5_gen.json index 37e6b948..96ea571d 100644 --- a/internal/data/assets/plugin_6f6666696369616c2d6d61696c65726c6974652d7369676e2d75702d666f726d73811c9dc5_gen.json +++ b/internal/data/assets/plugin_6f6666696369616c2d6d61696c65726c6974652d7369676e2d75702d666f726d73811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/156b955d-e978-4ff5-ab56-35af257b3199/official-mailerlite-sign-up-forms","title":"MailerLite – Signup forms (official) <= 1.5.7 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"156b955d-e978-4ff5-ab56-35af257b3199"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/156b955d-e978-4ff5-ab56-35af257b3199?source=api-prod","cve":"CVE-2022-33201","affectedVersions":"<=1.5.7","severity":"high"},{"advisoryId":"WPSECADV/WF/4e383235-8f61-46f2-bd54-cc41e3ec189e/official-mailerlite-sign-up-forms","title":"MailerLite - Signup forms <= 1.5.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-05-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"4e383235-8f61-46f2-bd54-cc41e3ec189e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4e383235-8f61-46f2-bd54-cc41e3ec189e?source=api-prod","cve":"CVE-2022-1604","affectedVersions":"<=1.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/7f34f4a6-9092-4e67-8a1e-7c60edde0b2a/official-mailerlite-sign-up-forms","title":"MailerLite – Signup forms (official) 1.5.0 - 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"7f34f4a6-9092-4e67-8a1e-7c60edde0b2a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7f34f4a6-9092-4e67-8a1e-7c60edde0b2a?source=api-prod","cve":"CVE-2024-1386","affectedVersions":">=1.5.0,<=1.7.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/8c37cc28-fde0-45c6-b49c-d6dfb296c4a5/official-mailerlite-sign-up-forms","title":"MailerLite – Signup forms (official) <= 1.7.16 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-11 21:04:21","sources":[{"name":"Wordfence","remoteId":"8c37cc28-fde0-45c6-b49c-d6dfb296c4a5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c37cc28-fde0-45c6-b49c-d6dfb296c4a5?source=api-prod","cve":"CVE-2025-13993","affectedVersions":"<=1.7.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/a03b4c19-85fa-47ad-b9ae-b466f8e5ca96/official-mailerlite-sign-up-forms","title":"MailerLite – Signup forms (official) <= 1.7.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"a03b4c19-85fa-47ad-b9ae-b466f8e5ca96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a03b4c19-85fa-47ad-b9ae-b466f8e5ca96?source=api-prod","cve":"CVE-2024-2797","affectedVersions":"<=1.7.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/ec9cd4a8-286e-43d7-8cb6-6cc363800e20/official-mailerlite-sign-up-forms","title":"MailerLite Signup Forms < 1.4.4 - Unauthenticated SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"ec9cd4a8-286e-43d7-8cb6-6cc363800e20"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ec9cd4a8-286e-43d7-8cb6-6cc363800e20?source=api-prod","affectedVersions":"<1.4.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/f3b79fab-208f-4354-89ea-508290dcd851/official-mailerlite-sign-up-forms","title":"MailerLite – Signup forms <= 1.4.4 - Cross-Site Request Forgery\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"f3b79fab-208f-4354-89ea-508290dcd851"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f3b79fab-208f-4354-89ea-508290dcd851?source=api-prod","affectedVersions":"<1.4.5","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/156b955d-e978-4ff5-ab56-35af257b3199/official-mailerlite-sign-up-forms","title":"MailerLite – Signup forms (official) <= 1.5.7 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"156b955d-e978-4ff5-ab56-35af257b3199"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/156b955d-e978-4ff5-ab56-35af257b3199?source=api-prod","cve":"CVE-2022-33201","affectedVersions":"<=1.5.7","severity":"high"},{"advisoryId":"WPSECADV/WF/4e383235-8f61-46f2-bd54-cc41e3ec189e/official-mailerlite-sign-up-forms","title":"MailerLite - Signup forms <= 1.5.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-05-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"4e383235-8f61-46f2-bd54-cc41e3ec189e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4e383235-8f61-46f2-bd54-cc41e3ec189e?source=api-prod","cve":"CVE-2022-1604","affectedVersions":"<=1.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/7f34f4a6-9092-4e67-8a1e-7c60edde0b2a/official-mailerlite-sign-up-forms","title":"MailerLite – Signup forms (official) 1.5.0 - 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"7f34f4a6-9092-4e67-8a1e-7c60edde0b2a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7f34f4a6-9092-4e67-8a1e-7c60edde0b2a?source=api-prod","cve":"CVE-2024-1386","affectedVersions":">=1.5.0,<=1.7.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/8c37cc28-fde0-45c6-b49c-d6dfb296c4a5/official-mailerlite-sign-up-forms","title":"MailerLite – Signup forms (official) <= 1.7.16 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-11 21:04:21","sources":[{"name":"Wordfence","remoteId":"8c37cc28-fde0-45c6-b49c-d6dfb296c4a5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c37cc28-fde0-45c6-b49c-d6dfb296c4a5?source=api-prod","cve":"CVE-2025-13993","affectedVersions":"<=1.7.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/a03b4c19-85fa-47ad-b9ae-b466f8e5ca96/official-mailerlite-sign-up-forms","title":"MailerLite – Signup forms (official) <= 1.7.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"a03b4c19-85fa-47ad-b9ae-b466f8e5ca96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a03b4c19-85fa-47ad-b9ae-b466f8e5ca96?source=api-prod","cve":"CVE-2024-2797","affectedVersions":"<=1.7.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/ec9cd4a8-286e-43d7-8cb6-6cc363800e20/official-mailerlite-sign-up-forms","title":"MailerLite Signup Forms < 1.4.4 - Unauthenticated SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"ec9cd4a8-286e-43d7-8cb6-6cc363800e20"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ec9cd4a8-286e-43d7-8cb6-6cc363800e20?source=api-prod","affectedVersions":"<1.4.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/f3b79fab-208f-4354-89ea-508290dcd851/official-mailerlite-sign-up-forms","title":"MailerLite – Signup forms <= 1.4.4 - Cross-Site Request Forgery\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"f3b79fab-208f-4354-89ea-508290dcd851"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f3b79fab-208f-4354-89ea-508290dcd851?source=api-prod","affectedVersions":"<1.4.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/fc7e68e7-6792-419d-800b-f1bc340f23fb/official-mailerlite-sign-up-forms","title":"MailerLite – Signup forms (official) <= 1.7.18 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"fc7e68e7-6792-419d-800b-f1bc340f23fb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fc7e68e7-6792-419d-800b-f1bc340f23fb?source=api-prod","cve":"CVE-2026-25420","affectedVersions":"<=1.7.18","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6f736d811c9dc5_gen.json b/internal/data/assets/plugin_6f736d811c9dc5_gen.json index edd8656c..29c5eed2 100644 --- a/internal/data/assets/plugin_6f736d811c9dc5_gen.json +++ b/internal/data/assets/plugin_6f736d811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/123c2958-3335-4212-8ed0-b2a56a5272f3/osm","title":"OSM - OpenStreetMap <= 6.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"123c2958-3335-4212-8ed0-b2a56a5272f3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/123c2958-3335-4212-8ed0-b2a56a5272f3?source=api-prod","cve":"CVE-2022-30544","affectedVersions":"<=6.0","severity":"high"},{"advisoryId":"WPSECADV/WF/5648fc33-3284-4f71-bc2b-6e72237b2ca1/osm","title":"OSM – OpenStreetMap <= 6.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"5648fc33-3284-4f71-bc2b-6e72237b2ca1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5648fc33-3284-4f71-bc2b-6e72237b2ca1?source=api-prod","cve":"CVE-2024-52355","affectedVersions":"<=6.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/65dffde9-2a50-41fe-bc21-3d0915068887/osm","title":"OSM <= 6.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker_name' Shortcode Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"65dffde9-2a50-41fe-bc21-3d0915068887"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/65dffde9-2a50-41fe-bc21-3d0915068887?source=api-prod","cve":"CVE-2026-4429","affectedVersions":"<=6.1.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/6dac6353-9e70-482d-b54b-ffde661b212c/osm","title":"OSM - OpenStreetMap <= 6.0.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via 'osm_map' Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"6dac6353-9e70-482d-b54b-ffde661b212c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6dac6353-9e70-482d-b54b-ffde661b212c?source=api-prod","cve":"CVE-2022-4676","affectedVersions":"<=6.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/839ecd06-9c74-4ddc-b455-26ec3e627889/osm","title":"OSM <= 6.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via osm_map and osm_map_v3 Shortcodes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-26 18:40:16","sources":[{"name":"Wordfence","remoteId":"839ecd06-9c74-4ddc-b455-26ec3e627889"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/839ecd06-9c74-4ddc-b455-26ec3e627889?source=api-prod","cve":"CVE-2024-8991","affectedVersions":"<=6.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/845cea77-ea74-4459-817b-cfbdb877b75a/osm","title":"OSM – OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-08 20:10:10","sources":[{"name":"Wordfence","remoteId":"845cea77-ea74-4459-817b-cfbdb877b75a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/845cea77-ea74-4459-817b-cfbdb877b75a?source=api-prod","cve":"CVE-2024-3603","affectedVersions":"<=6.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8eebc67-e590-4d7f-8925-e5e5090cedf0/osm","title":"OSM – OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-08 20:10:52","sources":[{"name":"Wordfence","remoteId":"c8eebc67-e590-4d7f-8925-e5e5090cedf0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8eebc67-e590-4d7f-8925-e5e5090cedf0?source=api-prod","cve":"CVE-2024-3604","affectedVersions":"<=6.0.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/e0f787cd-af81-4ba4-8ee1-5e01f06a00b0/osm","title":"OSM – OpenStreetMap <= 6.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"e0f787cd-af81-4ba4-8ee1-5e01f06a00b0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e0f787cd-af81-4ba4-8ee1-5e01f06a00b0?source=api-prod","cve":"CVE-2025-31557","affectedVersions":"<=6.1.13","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/123c2958-3335-4212-8ed0-b2a56a5272f3/osm","title":"OSM - OpenStreetMap <= 6.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"123c2958-3335-4212-8ed0-b2a56a5272f3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/123c2958-3335-4212-8ed0-b2a56a5272f3?source=api-prod","cve":"CVE-2022-30544","affectedVersions":"<=6.0","severity":"high"},{"advisoryId":"WPSECADV/WF/5648fc33-3284-4f71-bc2b-6e72237b2ca1/osm","title":"OSM – OpenStreetMap <= 6.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"5648fc33-3284-4f71-bc2b-6e72237b2ca1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5648fc33-3284-4f71-bc2b-6e72237b2ca1?source=api-prod","cve":"CVE-2024-52355","affectedVersions":"<=6.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/65dffde9-2a50-41fe-bc21-3d0915068887/osm","title":"OSM <= 6.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker_name' Shortcode Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"65dffde9-2a50-41fe-bc21-3d0915068887"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/65dffde9-2a50-41fe-bc21-3d0915068887?source=api-prod","cve":"CVE-2026-4429","affectedVersions":"<=6.1.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/6dac6353-9e70-482d-b54b-ffde661b212c/osm","title":"OSM - OpenStreetMap <= 6.0.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via 'osm_map' Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"6dac6353-9e70-482d-b54b-ffde661b212c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6dac6353-9e70-482d-b54b-ffde661b212c?source=api-prod","cve":"CVE-2022-4676","affectedVersions":"<=6.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/839ecd06-9c74-4ddc-b455-26ec3e627889/osm","title":"OSM <= 6.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via osm_map and osm_map_v3 Shortcodes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-26 18:40:16","sources":[{"name":"Wordfence","remoteId":"839ecd06-9c74-4ddc-b455-26ec3e627889"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/839ecd06-9c74-4ddc-b455-26ec3e627889?source=api-prod","cve":"CVE-2024-8991","affectedVersions":"<=6.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/845cea77-ea74-4459-817b-cfbdb877b75a/osm","title":"OSM – OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-08 20:10:10","sources":[{"name":"Wordfence","remoteId":"845cea77-ea74-4459-817b-cfbdb877b75a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/845cea77-ea74-4459-817b-cfbdb877b75a?source=api-prod","cve":"CVE-2024-3603","affectedVersions":"<=6.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8eebc67-e590-4d7f-8925-e5e5090cedf0/osm","title":"OSM – OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-08 20:10:52","sources":[{"name":"Wordfence","remoteId":"c8eebc67-e590-4d7f-8925-e5e5090cedf0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8eebc67-e590-4d7f-8925-e5e5090cedf0?source=api-prod","cve":"CVE-2024-3604","affectedVersions":"<=6.0.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/d3af34f4-72c5-43a4-9ca1-0729455298c5/osm","title":"OSM – OpenStreetMap <= 6.1.12 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"d3af34f4-72c5-43a4-9ca1-0729455298c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d3af34f4-72c5-43a4-9ca1-0729455298c5?source=api-prod","cve":"CVE-2026-25323","affectedVersions":"<=6.1.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/e0f787cd-af81-4ba4-8ee1-5e01f06a00b0/osm","title":"OSM – OpenStreetMap <= 6.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"e0f787cd-af81-4ba4-8ee1-5e01f06a00b0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e0f787cd-af81-4ba4-8ee1-5e01f06a00b0?source=api-prod","cve":"CVE-2025-31557","affectedVersions":"<=6.1.13","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7064662d67656e657261746f722d6164646f6e2d666f722d656c656d656e746f722d706167652d6275696c646572811c9dc5_gen.json b/internal/data/assets/plugin_7064662d67656e657261746f722d6164646f6e2d666f722d656c656d656e746f722d706167652d6275696c646572811c9dc5_gen.json index 12e0c0d3..49c348f0 100644 --- a/internal/data/assets/plugin_7064662d67656e657261746f722d6164646f6e2d666f722d656c656d656e746f722d706167652d6275696c646572811c9dc5_gen.json +++ b/internal/data/assets/plugin_7064662d67656e657261746f722d6164646f6e2d666f722d656c656d656e746f722d706167652d6275696c646572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/36daf2af-1db3-4b35-8849-480212660b2f/pdf-generator-addon-for-elementor-page-builder","title":"PDF Generator Addon for Elementor Page Builder <= 2.0.0 - Unauthenticated Arbitrary File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-15 15:00:29","sources":[{"name":"Wordfence","remoteId":"36daf2af-1db3-4b35-8849-480212660b2f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/36daf2af-1db3-4b35-8849-480212660b2f?source=api-prod","cve":"CVE-2024-9935","affectedVersions":"<=2.0.0","severity":"high"},{"advisoryId":"WPSECADV/WF/8f444df8-a7ed-4ab0-bf68-8b18ba5e90c0/pdf-generator-addon-for-elementor-page-builder","title":"PDF Generator Addon for Elementor Page Builder <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"8f444df8-a7ed-4ab0-bf68-8b18ba5e90c0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8f444df8-a7ed-4ab0-bf68-8b18ba5e90c0?source=api-prod","cve":"CVE-2025-31850","affectedVersions":"<=2.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e047123d-fffb-4fe4-9746-98251c8c2419/pdf-generator-addon-for-elementor-page-builder","title":"PDF Generator Addon for Elementor Page Builder <= 1.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"e047123d-fffb-4fe4-9746-98251c8c2419"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e047123d-fffb-4fe4-9746-98251c8c2419?source=api-prod","cve":"CVE-2024-50449","affectedVersions":"<=1.7.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/36daf2af-1db3-4b35-8849-480212660b2f/pdf-generator-addon-for-elementor-page-builder","title":"PDF Generator Addon for Elementor Page Builder <= 2.0.0 - Unauthenticated Arbitrary File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-15 15:00:29","sources":[{"name":"Wordfence","remoteId":"36daf2af-1db3-4b35-8849-480212660b2f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/36daf2af-1db3-4b35-8849-480212660b2f?source=api-prod","cve":"CVE-2024-9935","affectedVersions":"<=2.0.0","severity":"high"},{"advisoryId":"WPSECADV/WF/6847da95-a157-403a-8d54-d6794da94739/pdf-generator-addon-for-elementor-page-builder","title":"PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Unauthenticated Path Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"6847da95-a157-403a-8d54-d6794da94739"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6847da95-a157-403a-8d54-d6794da94739?source=api-prod","cve":"CVE-2025-24569","affectedVersions":"<=1.7.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/8f444df8-a7ed-4ab0-bf68-8b18ba5e90c0/pdf-generator-addon-for-elementor-page-builder","title":"PDF Generator Addon for Elementor Page Builder <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"8f444df8-a7ed-4ab0-bf68-8b18ba5e90c0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8f444df8-a7ed-4ab0-bf68-8b18ba5e90c0?source=api-prod","cve":"CVE-2025-31850","affectedVersions":"<=2.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e047123d-fffb-4fe4-9746-98251c8c2419/pdf-generator-addon-for-elementor-page-builder","title":"PDF Generator Addon for Elementor Page Builder <= 1.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"e047123d-fffb-4fe4-9746-98251c8c2419"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e047123d-fffb-4fe4-9746-98251c8c2419?source=api-prod","cve":"CVE-2024-50449","affectedVersions":"<=1.7.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_70656e63692d6169811c9dc5_gen.json b/internal/data/assets/plugin_70656e63692d6169811c9dc5_gen.json new file mode 100644 index 00000000..7527b9ee --- /dev/null +++ b/internal/data/assets/plugin_70656e63692d6169811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/85ff1468-2cbf-4c25-9fc6-9ee419dcaea8/penci-ai","title":"Penci AI SmartContent Creator <= 2.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"85ff1468-2cbf-4c25-9fc6-9ee419dcaea8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/85ff1468-2cbf-4c25-9fc6-9ee419dcaea8?source=api-prod","cve":"CVE-2026-27055","affectedVersions":"<=2.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_706f6c6c2d7770811c9dc5_gen.json b/internal/data/assets/plugin_706f6c6c2d7770811c9dc5_gen.json index 7b653bbd..23e4f838 100644 --- a/internal/data/assets/plugin_706f6c6c2d7770811c9dc5_gen.json +++ b/internal/data/assets/plugin_706f6c6c2d7770811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/1e2dab05-97ce-4f53-8069-2577c5c25b16/poll-wp","title":"TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.6 - Authenticated (Administrator+) SQL Injection via 's' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-14 11:33:59","sources":[{"name":"Wordfence","remoteId":"1e2dab05-97ce-4f53-8069-2577c5c25b16"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1e2dab05-97ce-4f53-8069-2577c5c25b16?source=api-prod","cve":"CVE-2025-3470","affectedVersions":"<=2.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/2b732bce-29a5-4b1f-99a2-b3153c0e82ed/poll-wp","title":"TS Poll <= 2.5.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"2b732bce-29a5-4b1f-99a2-b3153c0e82ed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b732bce-29a5-4b1f-99a2-b3153c0e82ed?source=api-prod","cve":"CVE-2025-68588","affectedVersions":"<=2.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/3d7b73f4-e52f-40bd-9865-de994cd8d610/poll-wp","title":"TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.3.9 - Authenticated (Admin+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"3d7b73f4-e52f-40bd-9865-de994cd8d610"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3d7b73f4-e52f-40bd-9865-de994cd8d610?source=api-prod","cve":"CVE-2024-8625","affectedVersions":"<=2.3.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/b78eb275-bede-44f0-bf72-6931c37d78bf/poll-wp","title":"TS Poll – Best Poll Plugin for WordPress <1.3.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-04-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"b78eb275-bede-44f0-bf72-6931c37d78bf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b78eb275-bede-44f0-bf72-6931c37d78bf?source=api-prod","cve":"CVE-2020-11673","affectedVersions":"<1.3.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/d16363d6-ca4b-4de0-abae-a7b07803e2e3/poll-wp","title":"TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.0 - Authenticated (Administrator+) SQL Injection via orderby Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"d16363d6-ca4b-4de0-abae-a7b07803e2e3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d16363d6-ca4b-4de0-abae-a7b07803e2e3?source=api-prod","cve":"CVE-2024-9022","affectedVersions":"<=2.4.0","severity":"high"},{"advisoryId":"WPSECADV/WF/df3b5124-1151-4402-b30f-038470c7a951/poll-wp","title":"TS Poll – Best Poll Plugin for WordPress <= 1.5.8 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-08-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"df3b5124-1151-4402-b30f-038470c7a951"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/df3b5124-1151-4402-b30f-038470c7a951?source=api-prod","affectedVersions":"<=1.5.8","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/1e2dab05-97ce-4f53-8069-2577c5c25b16/poll-wp","title":"TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.6 - Authenticated (Administrator+) SQL Injection via 's' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-14 11:33:59","sources":[{"name":"Wordfence","remoteId":"1e2dab05-97ce-4f53-8069-2577c5c25b16"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1e2dab05-97ce-4f53-8069-2577c5c25b16?source=api-prod","cve":"CVE-2025-3470","affectedVersions":"<=2.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/2b732bce-29a5-4b1f-99a2-b3153c0e82ed/poll-wp","title":"TS Poll <= 2.5.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"2b732bce-29a5-4b1f-99a2-b3153c0e82ed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b732bce-29a5-4b1f-99a2-b3153c0e82ed?source=api-prod","cve":"CVE-2025-68588","affectedVersions":"<=2.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/3d7b73f4-e52f-40bd-9865-de994cd8d610/poll-wp","title":"TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.3.9 - Authenticated (Admin+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"3d7b73f4-e52f-40bd-9865-de994cd8d610"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3d7b73f4-e52f-40bd-9865-de994cd8d610?source=api-prod","cve":"CVE-2024-8625","affectedVersions":"<=2.3.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/b78eb275-bede-44f0-bf72-6931c37d78bf/poll-wp","title":"TS Poll – Best Poll Plugin for WordPress <1.3.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-04-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"b78eb275-bede-44f0-bf72-6931c37d78bf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b78eb275-bede-44f0-bf72-6931c37d78bf?source=api-prod","cve":"CVE-2020-11673","affectedVersions":"<1.3.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/d16363d6-ca4b-4de0-abae-a7b07803e2e3/poll-wp","title":"TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.0 - Authenticated (Administrator+) SQL Injection via orderby Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"d16363d6-ca4b-4de0-abae-a7b07803e2e3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d16363d6-ca4b-4de0-abae-a7b07803e2e3?source=api-prod","cve":"CVE-2024-9022","affectedVersions":"<=2.4.0","severity":"high"},{"advisoryId":"WPSECADV/WF/d8b47395-6d04-4ecc-9ae5-081aabe30d31/poll-wp","title":"TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.5.5 - Authenticated (Editor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"d8b47395-6d04-4ecc-9ae5-081aabe30d31"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d8b47395-6d04-4ecc-9ae5-081aabe30d31?source=api-prod","cve":"CVE-2026-25428","affectedVersions":"<=2.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/df3b5124-1151-4402-b30f-038470c7a951/poll-wp","title":"TS Poll – Best Poll Plugin for WordPress <= 1.5.8 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-08-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"df3b5124-1151-4402-b30f-038470c7a951"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/df3b5124-1151-4402-b30f-038470c7a951?source=api-prod","affectedVersions":"<=1.5.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_706f7075702d6275696c6465722d626c6f636b811c9dc5_gen.json b/internal/data/assets/plugin_706f7075702d6275696c6465722d626c6f636b811c9dc5_gen.json index ca2d5579..1d247eca 100644 --- a/internal/data/assets/plugin_706f7075702d6275696c6465722d626c6f636b811c9dc5_gen.json +++ b/internal/data/assets/plugin_706f7075702d6275696c6465722d626c6f636b811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/48f5a44d-d01f-4c41-98da-7c1f6c65c254/popup-builder-block","title":"Popupkit <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Subscriber Data Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-05 16:05:07","sources":[{"name":"Wordfence","remoteId":"48f5a44d-d01f-4c41-98da-7c1f6c65c254"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/48f5a44d-d01f-4c41-98da-7c1f6c65c254?source=api-prod","cve":"CVE-2025-14441","affectedVersions":"<=2.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/5f4767b5-5dd6-4a2a-b44a-5297432286b1/popup-builder-block","title":"Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.4 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5f4767b5-5dd6-4a2a-b44a-5297432286b1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5f4767b5-5dd6-4a2a-b44a-5297432286b1?source=api-prod","cve":"CVE-2025-10861","affectedVersions":"<=2.1.4","severity":"high"},{"advisoryId":"WPSECADV/WF/93e0a1a1-fba6-4209-b679-e66d77870be2/popup-builder-block","title":"Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.3 - Unauthenticated SQL Injection via 'id'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"93e0a1a1-fba6-4209-b679-e66d77870be2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/93e0a1a1-fba6-4209-b679-e66d77870be2?source=api-prod","cve":"CVE-2025-10862","affectedVersions":"<=2.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/9db1dfde-0cba-41b2-ab7a-a1640e5fd96b/popup-builder-block","title":"Popup builder with Gamification <= 2.2.0 - Unauthenticated SQL Injection via Multiple REST API Endpoints\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-04 11:20:00","sources":[{"name":"Wordfence","remoteId":"9db1dfde-0cba-41b2-ab7a-a1640e5fd96b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9db1dfde-0cba-41b2-ab7a-a1640e5fd96b?source=api-prod","cve":"CVE-2025-13192","affectedVersions":"<=2.2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/af287dc4-a82a-4ccf-8878-6f9591fa5d33/popup-builder-block","title":"PopupKit <= 2.2.1 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"af287dc4-a82a-4ccf-8878-6f9591fa5d33"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af287dc4-a82a-4ccf-8878-6f9591fa5d33?source=api-prod","cve":"CVE-2025-69026","affectedVersions":"<=2.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/c13bb699-f065-4065-9ea5-bb86d24e09ab/popup-builder-block","title":"PopupKit <= 2.2.0 - Missing Authorization to Sensitive Information Disclosure and Data Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-09 20:31:47","sources":[{"name":"Wordfence","remoteId":"c13bb699-f065-4065-9ea5-bb86d24e09ab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c13bb699-f065-4065-9ea5-bb86d24e09ab?source=api-prod","cve":"CVE-2025-14895","affectedVersions":"<=2.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c7f041a7-f5cc-463c-97b0-d4ecb3edb77a/popup-builder-block","title":"PopupKit <= 2.1.5 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"c7f041a7-f5cc-463c-97b0-d4ecb3edb77a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c7f041a7-f5cc-463c-97b0-d4ecb3edb77a?source=api-prod","cve":"CVE-2025-14314","affectedVersions":"<=2.1.5","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/48f5a44d-d01f-4c41-98da-7c1f6c65c254/popup-builder-block","title":"Popupkit <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Subscriber Data Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-05 16:05:07","sources":[{"name":"Wordfence","remoteId":"48f5a44d-d01f-4c41-98da-7c1f6c65c254"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/48f5a44d-d01f-4c41-98da-7c1f6c65c254?source=api-prod","cve":"CVE-2025-14441","affectedVersions":"<=2.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/5f4767b5-5dd6-4a2a-b44a-5297432286b1/popup-builder-block","title":"Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.4 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5f4767b5-5dd6-4a2a-b44a-5297432286b1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5f4767b5-5dd6-4a2a-b44a-5297432286b1?source=api-prod","cve":"CVE-2025-10861","affectedVersions":"<=2.1.4","severity":"high"},{"advisoryId":"WPSECADV/WF/93e0a1a1-fba6-4209-b679-e66d77870be2/popup-builder-block","title":"Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.3 - Unauthenticated SQL Injection via 'id'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"93e0a1a1-fba6-4209-b679-e66d77870be2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/93e0a1a1-fba6-4209-b679-e66d77870be2?source=api-prod","cve":"CVE-2025-10862","affectedVersions":"<=2.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/9db1dfde-0cba-41b2-ab7a-a1640e5fd96b/popup-builder-block","title":"Popup builder with Gamification <= 2.2.0 - Unauthenticated SQL Injection via Multiple REST API Endpoints\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-04 11:20:00","sources":[{"name":"Wordfence","remoteId":"9db1dfde-0cba-41b2-ab7a-a1640e5fd96b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9db1dfde-0cba-41b2-ab7a-a1640e5fd96b?source=api-prod","cve":"CVE-2025-13192","affectedVersions":"<=2.2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/af287dc4-a82a-4ccf-8878-6f9591fa5d33/popup-builder-block","title":"PopupKit <= 2.1.5 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"af287dc4-a82a-4ccf-8878-6f9591fa5d33"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af287dc4-a82a-4ccf-8878-6f9591fa5d33?source=api-prod","cve":"CVE-2025-69026","affectedVersions":"<=2.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/c13bb699-f065-4065-9ea5-bb86d24e09ab/popup-builder-block","title":"PopupKit <= 2.2.0 - Missing Authorization to Sensitive Information Disclosure and Data Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-09 20:31:47","sources":[{"name":"Wordfence","remoteId":"c13bb699-f065-4065-9ea5-bb86d24e09ab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c13bb699-f065-4065-9ea5-bb86d24e09ab?source=api-prod","cve":"CVE-2025-14895","affectedVersions":"<=2.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c7f041a7-f5cc-463c-97b0-d4ecb3edb77a/popup-builder-block","title":"PopupKit <= 2.1.5 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"c7f041a7-f5cc-463c-97b0-d4ecb3edb77a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c7f041a7-f5cc-463c-97b0-d4ecb3edb77a?source=api-prod","cve":"CVE-2025-14314","affectedVersions":"<=2.1.5","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_706f73742d657870697261746f72811c9dc5_gen.json b/internal/data/assets/plugin_706f73742d657870697261746f72811c9dc5_gen.json index d0987bf4..ea543a9b 100644 --- a/internal/data/assets/plugin_706f73742d657870697261746f72811c9dc5_gen.json +++ b/internal/data/assets/plugin_706f73742d657870697261746f72811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/06ac994a-1f49-4c7f-ba76-054deaf25c51/post-expirator","title":"Post Expirator <= 4.9.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"06ac994a-1f49-4c7f-ba76-054deaf25c51"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/06ac994a-1f49-4c7f-ba76-054deaf25c51?source=api-prod","cve":"CVE-2025-69361","affectedVersions":"<=4.9.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2f67da8c-da60-4c77-a8b8-7dfc027662e9/post-expirator","title":"Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories <= 4.9.2 - Missing Authorization to Authenticated (Contributor+) Authors' Emails Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 22:49:04","sources":[{"name":"Wordfence","remoteId":"2f67da8c-da60-4c77-a8b8-7dfc027662e9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2f67da8c-da60-4c77-a8b8-7dfc027662e9?source=api-prod","cve":"CVE-2025-13741","affectedVersions":"<=4.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/51ca3ed9-6c3e-44c6-b746-8415e27abed0/post-expirator","title":"Post Expirator <= 4.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"51ca3ed9-6c3e-44c6-b746-8415e27abed0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/51ca3ed9-6c3e-44c6-b746-8415e27abed0?source=api-prod","cve":"CVE-2026-39482","affectedVersions":"<=4.9.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/8198d81a-40c0-49c1-8c38-f5ef6fb911ad/post-expirator","title":"Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories <= 4.9.3 - Missing Authorization to Authenticated (Contributor+) Workflow Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 17:41:07","sources":[{"name":"Wordfence","remoteId":"8198d81a-40c0-49c1-8c38-f5ef6fb911ad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8198d81a-40c0-49c1-8c38-f5ef6fb911ad?source=api-prod","cve":"CVE-2025-14718","affectedVersions":"<=4.9.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/82ea0ebc-08aa-4ef5-b6b1-c7c13715ef6d/post-expirator","title":"Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories <= 4.9.1 - Authenticated (Author+) Missing Authorization to Post/Page Status Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-20 19:53:09","sources":[{"name":"Wordfence","remoteId":"82ea0ebc-08aa-4ef5-b6b1-c7c13715ef6d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/82ea0ebc-08aa-4ef5-b6b1-c7c13715ef6d?source=api-prod","cve":"CVE-2025-13149","affectedVersions":"<=4.9.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f0576cde-8d32-4f06-899a-a9ebff99d8ba/post-expirator","title":"Post Expirator <= 2.5.1 - Contributor+ Arbitrary Post Schedule Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"f0576cde-8d32-4f06-899a-a9ebff99d8ba"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f0576cde-8d32-4f06-899a-a9ebff99d8ba?source=api-prod","cve":"CVE-2021-24783","affectedVersions":"<=2.5.1","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/06ac994a-1f49-4c7f-ba76-054deaf25c51/post-expirator","title":"Post Expirator <= 4.9.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"06ac994a-1f49-4c7f-ba76-054deaf25c51"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/06ac994a-1f49-4c7f-ba76-054deaf25c51?source=api-prod","cve":"CVE-2025-69361","affectedVersions":"<=4.9.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2f67da8c-da60-4c77-a8b8-7dfc027662e9/post-expirator","title":"Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories <= 4.9.2 - Missing Authorization to Authenticated (Contributor+) Authors' Emails Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 22:49:04","sources":[{"name":"Wordfence","remoteId":"2f67da8c-da60-4c77-a8b8-7dfc027662e9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2f67da8c-da60-4c77-a8b8-7dfc027662e9?source=api-prod","cve":"CVE-2025-13741","affectedVersions":"<=4.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/51ca3ed9-6c3e-44c6-b746-8415e27abed0/post-expirator","title":"Post Expirator <= 4.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"51ca3ed9-6c3e-44c6-b746-8415e27abed0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/51ca3ed9-6c3e-44c6-b746-8415e27abed0?source=api-prod","cve":"CVE-2026-39482","affectedVersions":"<=4.9.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/8198d81a-40c0-49c1-8c38-f5ef6fb911ad/post-expirator","title":"Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories <= 4.9.3 - Missing Authorization to Authenticated (Contributor+) Workflow Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 17:41:07","sources":[{"name":"Wordfence","remoteId":"8198d81a-40c0-49c1-8c38-f5ef6fb911ad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8198d81a-40c0-49c1-8c38-f5ef6fb911ad?source=api-prod","cve":"CVE-2025-14718","affectedVersions":"<=4.9.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/82ea0ebc-08aa-4ef5-b6b1-c7c13715ef6d/post-expirator","title":"Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories <= 4.9.1 - Authenticated (Author+) Missing Authorization to Post/Page Status Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-20 19:53:09","sources":[{"name":"Wordfence","remoteId":"82ea0ebc-08aa-4ef5-b6b1-c7c13715ef6d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/82ea0ebc-08aa-4ef5-b6b1-c7c13715ef6d?source=api-prod","cve":"CVE-2025-13149","affectedVersions":"<=4.9.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/9acf80aa-8354-4430-9836-18fa17854521/post-expirator","title":"Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories <= 4.10.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'wrapper' Shortcode Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:02:32","sources":[{"name":"Wordfence","remoteId":"9acf80aa-8354-4430-9836-18fa17854521"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9acf80aa-8354-4430-9836-18fa17854521?source=api-prod","cve":"CVE-2026-5247","affectedVersions":"<=4.10.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/f0576cde-8d32-4f06-899a-a9ebff99d8ba/post-expirator","title":"Post Expirator <= 2.5.1 - Contributor+ Arbitrary Post Schedule Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"f0576cde-8d32-4f06-899a-a9ebff99d8ba"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f0576cde-8d32-4f06-899a-a9ebff99d8ba?source=api-prod","cve":"CVE-2021-24783","affectedVersions":"<=2.5.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_706f7374732d7461626c652d66696c74657261626c65811c9dc5_gen.json b/internal/data/assets/plugin_706f7374732d7461626c652d66696c74657261626c65811c9dc5_gen.json index eb15d8c7..46818435 100644 --- a/internal/data/assets/plugin_706f7374732d7461626c652d66696c74657261626c65811c9dc5_gen.json +++ b/internal/data/assets/plugin_706f7374732d7461626c652d66696c74657261626c65811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0a69e4e0-0872-4604-98ae-6a0502e7e965/posts-table-filterable","title":"TableOn <= 1.0.4.2 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"0a69e4e0-0872-4604-98ae-6a0502e7e965"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0a69e4e0-0872-4604-98ae-6a0502e7e965?source=api-prod","cve":"CVE-2025-60244","affectedVersions":"<=1.0.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/33490873-da99-465e-bfb6-44d2ba84f3ee/posts-table-filterable","title":"TableOn – WordPress Posts Table Filterable <= 1.0.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Shortcode Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-07 15:35:29","sources":[{"name":"Wordfence","remoteId":"33490873-da99-465e-bfb6-44d2ba84f3ee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/33490873-da99-465e-bfb6-44d2ba84f3ee?source=api-prod","cve":"CVE-2026-3513","affectedVersions":"<=1.0.4.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/3a03b32f-a5a4-4c1b-ad93-0833af6c302e/posts-table-filterable","title":"TableOn – WordPress Posts Table Filterable <= 1.0.4.3 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"3a03b32f-a5a4-4c1b-ad93-0833af6c302e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3a03b32f-a5a4-4c1b-ad93-0833af6c302e?source=api-prod","cve":"CVE-2025-32569","affectedVersions":"<=1.0.4.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/447d3aa6-2ed3-4da3-b9e8-fc7792c8c29a/posts-table-filterable","title":"TableOn – WordPress Posts Table Filterable <= 1.0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via tableon_popup_iframe_button Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-20 18:15:37","sources":[{"name":"Wordfence","remoteId":"447d3aa6-2ed3-4da3-b9e8-fc7792c8c29a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/447d3aa6-2ed3-4da3-b9e8-fc7792c8c29a?source=api-prod","cve":"CVE-2025-5143","affectedVersions":"<=1.0.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/46fd4e5d-e1d7-4de6-ae24-66e260a1b288/posts-table-filterable","title":"TableOn <= 1.0.4.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"46fd4e5d-e1d7-4de6-ae24-66e260a1b288"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/46fd4e5d-e1d7-4de6-ae24-66e260a1b288?source=api-prod","cve":"CVE-2025-69316","affectedVersions":"<=1.0.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/bc547d3d-9b08-472a-937d-d9c815c33087/posts-table-filterable","title":"TableOn – WordPress Posts Table Filterable <= 1.0.3 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"bc547d3d-9b08-472a-937d-d9c815c33087"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bc547d3d-9b08-472a-937d-d9c815c33087?source=api-prod","cve":"CVE-2025-32592","affectedVersions":"<=1.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/d60f69f1-eaea-49cb-bbe3-281ec4f872f1/posts-table-filterable","title":"TableOn – WordPress Posts Table Filterable <= 1.0.0 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"d60f69f1-eaea-49cb-bbe3-281ec4f872f1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d60f69f1-eaea-49cb-bbe3-281ec4f872f1?source=api-prod","affectedVersions":"<1.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/ebe59b29-f8d4-4ea0-b4a8-d758ddb1c594/posts-table-filterable","title":"TableOn – WordPress Posts Table Filterable <= 1.0.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"ebe59b29-f8d4-4ea0-b4a8-d758ddb1c594"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ebe59b29-f8d4-4ea0-b4a8-d758ddb1c594?source=api-prod","cve":"CVE-2025-32218","affectedVersions":"<=1.0.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0a69e4e0-0872-4604-98ae-6a0502e7e965/posts-table-filterable","title":"TableOn <= 1.0.5.1 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"0a69e4e0-0872-4604-98ae-6a0502e7e965"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0a69e4e0-0872-4604-98ae-6a0502e7e965?source=api-prod","cve":"CVE-2025-60244","affectedVersions":"<=1.0.5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/33490873-da99-465e-bfb6-44d2ba84f3ee/posts-table-filterable","title":"TableOn – WordPress Posts Table Filterable <= 1.0.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Shortcode Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-07 15:35:29","sources":[{"name":"Wordfence","remoteId":"33490873-da99-465e-bfb6-44d2ba84f3ee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/33490873-da99-465e-bfb6-44d2ba84f3ee?source=api-prod","cve":"CVE-2026-3513","affectedVersions":"<=1.0.4.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/3a03b32f-a5a4-4c1b-ad93-0833af6c302e/posts-table-filterable","title":"TableOn – WordPress Posts Table Filterable <= 1.0.4.3 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"3a03b32f-a5a4-4c1b-ad93-0833af6c302e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3a03b32f-a5a4-4c1b-ad93-0833af6c302e?source=api-prod","cve":"CVE-2025-32569","affectedVersions":"<=1.0.4.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/447d3aa6-2ed3-4da3-b9e8-fc7792c8c29a/posts-table-filterable","title":"TableOn – WordPress Posts Table Filterable <= 1.0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via tableon_popup_iframe_button Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-20 18:15:37","sources":[{"name":"Wordfence","remoteId":"447d3aa6-2ed3-4da3-b9e8-fc7792c8c29a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/447d3aa6-2ed3-4da3-b9e8-fc7792c8c29a?source=api-prod","cve":"CVE-2025-5143","affectedVersions":"<=1.0.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/46fd4e5d-e1d7-4de6-ae24-66e260a1b288/posts-table-filterable","title":"TableOn <= 1.0.4.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"46fd4e5d-e1d7-4de6-ae24-66e260a1b288"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/46fd4e5d-e1d7-4de6-ae24-66e260a1b288?source=api-prod","cve":"CVE-2025-69316","affectedVersions":"<=1.0.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/bc547d3d-9b08-472a-937d-d9c815c33087/posts-table-filterable","title":"TableOn – WordPress Posts Table Filterable <= 1.0.3 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"bc547d3d-9b08-472a-937d-d9c815c33087"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bc547d3d-9b08-472a-937d-d9c815c33087?source=api-prod","cve":"CVE-2025-32592","affectedVersions":"<=1.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/d60f69f1-eaea-49cb-bbe3-281ec4f872f1/posts-table-filterable","title":"TableOn – WordPress Posts Table Filterable <= 1.0.0 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"d60f69f1-eaea-49cb-bbe3-281ec4f872f1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d60f69f1-eaea-49cb-bbe3-281ec4f872f1?source=api-prod","affectedVersions":"<1.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/ebe59b29-f8d4-4ea0-b4a8-d758ddb1c594/posts-table-filterable","title":"TableOn – WordPress Posts Table Filterable <= 1.0.5.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"ebe59b29-f8d4-4ea0-b4a8-d758ddb1c594"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ebe59b29-f8d4-4ea0-b4a8-d758ddb1c594?source=api-prod","cve":"CVE-2025-32218","affectedVersions":"<=1.0.5.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_706f7765727061636b2d656c656d656e7473811c9dc5_gen.json b/internal/data/assets/plugin_706f7765727061636b2d656c656d656e7473811c9dc5_gen.json index bf7774ff..b36a33f7 100644 --- a/internal/data/assets/plugin_706f7765727061636b2d656c656d656e7473811c9dc5_gen.json +++ b/internal/data/assets/plugin_706f7765727061636b2d656c656d656e7473811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/249ccc77-0daf-41bc-b5c5-991bf17d645d/powerpack-elements","title":"PowerPack Pro for Elementor <= 2.10.17 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-07 16:16:46","sources":[{"name":"Wordfence","remoteId":"249ccc77-0daf-41bc-b5c5-991bf17d645d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/249ccc77-0daf-41bc-b5c5-991bf17d645d?source=api-prod","cve":"CVE-2024-3668","affectedVersions":"<=2.10.17","severity":"high"},{"advisoryId":"WPSECADV/WF/2feabc97-0463-4e50-91a8-234445ca2504/powerpack-elements","title":"PowerPack Pro for Elementor <= 2.9.23 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"2feabc97-0463-4e50-91a8-234445ca2504"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2feabc97-0463-4e50-91a8-234445ca2504?source=api-prod","cve":"CVE-2023-49739","affectedVersions":"<=2.9.23","severity":"medium"},{"advisoryId":"WPSECADV/WF/883e1f3c-7e47-4522-ae8c-a9a6b4160be2/powerpack-elements","title":"PowerPack Pro for Elementor <= 2.10.6 - Missing Authorization to Settings Reset\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"883e1f3c-7e47-4522-ae8c-a9a6b4160be2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/883e1f3c-7e47-4522-ae8c-a9a6b4160be2?source=api-prod","cve":"CVE-2024-24844","affectedVersions":"<=2.10.6","severity":"high"},{"advisoryId":"WPSECADV/WF/d35e2d84-12c7-4c01-bde9-2fb05583a212/powerpack-elements","title":"PowerPack Pro for Elementor <= 2.10.14 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"d35e2d84-12c7-4c01-bde9-2fb05583a212"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d35e2d84-12c7-4c01-bde9-2fb05583a212?source=api-prod","cve":"CVE-2024-39634","affectedVersions":"<=2.10.14","severity":"high"},{"advisoryId":"WPSECADV/WF/e68bbee2-1c1a-4751-988e-dde423f8aab3/powerpack-elements","title":"PowerPack Pro for Elementor < 2.10.8 - Cross-Site Request Forgery to Plugin Settings Modification and Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"e68bbee2-1c1a-4751-988e-dde423f8aab3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e68bbee2-1c1a-4751-988e-dde423f8aab3?source=api-prod","cve":"CVE-2024-24843","affectedVersions":"<2.10.8","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/249ccc77-0daf-41bc-b5c5-991bf17d645d/powerpack-elements","title":"PowerPack Pro for Elementor <= 2.10.17 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-07 16:16:46","sources":[{"name":"Wordfence","remoteId":"249ccc77-0daf-41bc-b5c5-991bf17d645d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/249ccc77-0daf-41bc-b5c5-991bf17d645d?source=api-prod","cve":"CVE-2024-3668","affectedVersions":"<=2.10.17","severity":"high"},{"advisoryId":"WPSECADV/WF/2feabc97-0463-4e50-91a8-234445ca2504/powerpack-elements","title":"PowerPack Pro for Elementor <= 2.9.23 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"2feabc97-0463-4e50-91a8-234445ca2504"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2feabc97-0463-4e50-91a8-234445ca2504?source=api-prod","cve":"CVE-2023-49739","affectedVersions":"<=2.9.23","severity":"medium"},{"advisoryId":"WPSECADV/WF/883e1f3c-7e47-4522-ae8c-a9a6b4160be2/powerpack-elements","title":"PowerPack Pro for Elementor <= 2.10.6 - Missing Authorization to Settings Reset\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"883e1f3c-7e47-4522-ae8c-a9a6b4160be2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/883e1f3c-7e47-4522-ae8c-a9a6b4160be2?source=api-prod","cve":"CVE-2024-24844","affectedVersions":"<=2.10.6","severity":"high"},{"advisoryId":"WPSECADV/WF/a1069b36-3e9a-43ef-8ea1-9a77daf71dcc/powerpack-elements","title":"PowerPack Pro for Elementor < v2.13.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"a1069b36-3e9a-43ef-8ea1-9a77daf71dcc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a1069b36-3e9a-43ef-8ea1-9a77daf71dcc?source=api-prod","cve":"CVE-2026-42629","affectedVersions":"=1.3,<=1.3.70","severity":"medium"},{"advisoryId":"WPSECADV/WF/55db7d81-7ffb-49da-b64e-23e892bddc57/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Cross-Site Request Forgery to Menu Template creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"55db7d81-7ffb-49da-b64e-23e892bddc57"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/55db7d81-7ffb-49da-b64e-23e892bddc57?source=api-prod","cve":"CVE-2022-4707","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/55f7e39b-e7a5-462b-b1e4-c3d92038f17e/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Activation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"55f7e39b-e7a5-462b-b1e4-c3d92038f17e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/55f7e39b-e7a5-462b-b1e4-c3d92038f17e?source=api-prod","cve":"CVE-2022-4701","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/5666e2b7-acb3-4abb-ac2a-1575206435cf/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"5666e2b7-acb3-4abb-ac2a-1575206435cf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5666e2b7-acb3-4abb-ac2a-1575206435cf?source=api-prod","cve":"CVE-2025-1455","affectedVersions":"<=1.7.1012","severity":"medium"},{"advisoryId":"WPSECADV/WF/57bf222b-5f49-46e2-be84-3e6444807096/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"57bf222b-5f49-46e2-be84-3e6444807096"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/57bf222b-5f49-46e2-be84-3e6444807096?source=api-prod","cve":"CVE-2024-4489","affectedVersions":"<=1.3.976","severity":"medium"},{"advisoryId":"WPSECADV/WF/5ccece54-18fa-42e4-ba1a-d0879b73d66d/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.986 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"5ccece54-18fa-42e4-ba1a-d0879b73d66d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ccece54-18fa-42e4-ba1a-d0879b73d66d?source=api-prod","cve":"CVE-2024-8482","affectedVersions":"<=1.3.986","severity":"medium"},{"advisoryId":"WPSECADV/WF/5ee7b4d8-c397-41f6-981f-9a010e4ab2f1/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1017 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"5ee7b4d8-c397-41f6-981f-9a010e4ab2f1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ee7b4d8-c397-41f6-981f-9a010e4ab2f1?source=api-prod","cve":"CVE-2024-12120","affectedVersions":"<=1.7.1017","severity":"medium"},{"advisoryId":"WPSECADV/WF/62a5c796-1c14-4cb1-9f21-340b40e418df/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Import Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"62a5c796-1c14-4cb1-9f21-340b40e418df"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62a5c796-1c14-4cb1-9f21-340b40e418df?source=api-prod","cve":"CVE-2022-4703","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/64cce528-0ad0-45ec-a8f6-e8791b0bece0/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Import\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"64cce528-0ad0-45ec-a8f6-e8791b0bece0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/64cce528-0ad0-45ec-a8f6-e8791b0bece0?source=api-prod","cve":"CVE-2022-4704","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/68c6e428-b9cf-442f-a896-a8ceb4b9be0e/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"68c6e428-b9cf-442f-a896-a8ceb4b9be0e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/68c6e428-b9cf-442f-a896-a8ceb4b9be0e?source=api-prod","cve":"CVE-2025-1456","affectedVersions":"<=1.7.1012","severity":"medium"},{"advisoryId":"WPSECADV/WF/6aa3d312-485a-4a93-a075-fa7152395f11/royal-elementor-addons","title":"Royal Elementor Addons <=1.3.55 - Authenticated (Subscriber+) Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"6aa3d312-485a-4a93-a075-fa7152395f11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6aa3d312-485a-4a93-a075-fa7152395f11?source=api-prod","cve":"CVE-2022-4102","affectedVersions":"<=1.3.55","severity":"high"},{"advisoryId":"WPSECADV/WF/6bc6a436-6df3-4eaf-a16b-d8b3c3ca7d87/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1007 - Cross-Site Request Forgery to Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"6bc6a436-6df3-4eaf-a16b-d8b3c3ca7d87"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6bc6a436-6df3-4eaf-a16b-d8b3c3ca7d87?source=api-prod","cve":"CVE-2025-1441","affectedVersions":"<=1.7.1007","severity":"medium"},{"advisoryId":"WPSECADV/WF/70582781-9de5-4124-bde4-d3d26724e9b3/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"70582781-9de5-4124-bde4-d3d26724e9b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/70582781-9de5-4124-bde4-d3d26724e9b3?source=api-prod","cve":"CVE-2024-2798","affectedVersions":"<=1.3.971","severity":"medium"},{"advisoryId":"WPSECADV/WF/7a04705d-cd17-4b4b-b04d-de55d6479dab/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.94 - Unauthenticated Limited File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"7a04705d-cd17-4b4b-b04d-de55d6479dab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7a04705d-cd17-4b4b-b04d-de55d6479dab?source=api-prod","cve":"CVE-2024-1567","affectedVersions":"<=1.3.94","severity":"high"},{"advisoryId":"WPSECADV/WF/83a0150d-a9fa-4cc2-8fe8-a429747a9964/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.980 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"83a0150d-a9fa-4cc2-8fe8-a429747a9964"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/83a0150d-a9fa-4cc2-8fe8-a429747a9964?source=api-prod","cve":"CVE-2024-5818","affectedVersions":"<=1.3.980","severity":"medium"},{"advisoryId":"WPSECADV/WF/83ea2ec3-5d5b-44ea-83e6-41c4fa6e2e5f/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"83ea2ec3-5d5b-44ea-83e6-41c4fa6e2e5f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/83ea2ec3-5d5b-44ea-83e6-41c4fa6e2e5f?source=api-prod","cve":"CVE-2024-3889","affectedVersions":"<=1.3.971","severity":"medium"},{"advisoryId":"WPSECADV/WF/8619c999-5cf7-4888-bdb2-815238411303/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"8619c999-5cf7-4888-bdb2-815238411303"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8619c999-5cf7-4888-bdb2-815238411303?source=api-prod","cve":"CVE-2024-1500","affectedVersions":"<=1.3.91","severity":"medium"},{"advisoryId":"WPSECADV/WF/86c9bcf1-c69e-47ca-b74b-8ce6157f520b/royal-elementor-addons","title":"Royal Elementor Addons <=1.3.70 - Unauthenticated MailChimp API Key Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"86c9bcf1-c69e-47ca-b74b-8ce6157f520b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/86c9bcf1-c69e-47ca-b74b-8ce6157f520b?source=api-prod","cve":"CVE-2023-3709","affectedVersions":"<=1.3.70","severity":"medium"},{"advisoryId":"WPSECADV/WF/9744055a-b199-4945-afcc-4f5b85f5f1e8/royal-elementor-addons","title":"Royal Addons for Elementor <= 1.7.1057 - Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"9744055a-b199-4945-afcc-4f5b85f5f1e8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9744055a-b199-4945-afcc-4f5b85f5f1e8?source=api-prod","cve":"CVE-2026-6229","affectedVersions":"<=1.7.1057","severity":"high"},{"advisoryId":"WPSECADV/WF/9e860c60-b330-4a6c-8d15-947451af62fc/royal-elementor-addons","title":"Royal Elementor Addons <= 1.7.1001 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"9e860c60-b330-4a6c-8d15-947451af62fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9e860c60-b330-4a6c-8d15-947451af62fc?source=api-prod","cve":"CVE-2024-56226","affectedVersions":"<=1.7.1001","severity":"medium"},{"advisoryId":"WPSECADV/WF/a4178271-c09e-4094-a616-5a00d28f39a3/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_compare\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"a4178271-c09e-4094-a616-5a00d28f39a3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4178271-c09e-4094-a616-5a00d28f39a3?source=api-prod","cve":"CVE-2024-0515","affectedVersions":"<=1.3.87","severity":"medium"},{"advisoryId":"WPSECADV/WF/a4b353bf-f9be-465a-8723-9ea721b5baab/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.987 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"a4b353bf-f9be-465a-8723-9ea721b5baab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4b353bf-f9be-465a-8723-9ea721b5baab?source=api-prod","cve":"CVE-2024-56062","affectedVersions":"<=1.3.987","severity":"medium"},{"advisoryId":"WPSECADV/WF/a720b38c-37f0-4edf-9868-de3a105551ee/royal-elementor-addons","title":"Royal Elementor Addons <= 1.7.1017 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"a720b38c-37f0-4edf-9868-de3a105551ee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a720b38c-37f0-4edf-9868-de3a105551ee?source=api-prod","cve":"CVE-2025-39361","affectedVersions":"<=1.7.1017","severity":"medium"},{"advisoryId":"WPSECADV/WF/a8e34c05-7431-4acd-91f3-aab5e66f61ad/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1006 - Cross-Site Request Forgery to Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-13 19:52:46","sources":[{"name":"Wordfence","remoteId":"a8e34c05-7431-4acd-91f3-aab5e66f61ad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a8e34c05-7431-4acd-91f3-aab5e66f61ad?source=api-prod","cve":"CVE-2025-0393","affectedVersions":"<=1.7.1006","severity":"medium"},{"advisoryId":"WPSECADV/WF/a8e39f0b-eb4c-4568-9f5a-60a0dc3eb6ba/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1001 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"a8e39f0b-eb4c-4568-9f5a-60a0dc3eb6ba"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a8e39f0b-eb4c-4568-9f5a-60a0dc3eb6ba?source=api-prod","cve":"CVE-2024-9668","affectedVersions":"<=1.7.1001","severity":"medium"},{"advisoryId":"WPSECADV/WF/a9d95af5-96da-4259-98c6-e2c4c574a896/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.78 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"a9d95af5-96da-4259-98c6-e2c4c574a896"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a9d95af5-96da-4259-98c6-e2c4c574a896?source=api-prod","cve":"CVE-2023-5360","affectedVersions":"<=1.3.78","severity":"critical"},{"advisoryId":"WPSECADV/WF/ac6c6ce4-9944-4c8e-89aa-6a2e870ef205/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"ac6c6ce4-9944-4c8e-89aa-6a2e870ef205"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ac6c6ce4-9944-4c8e-89aa-6a2e870ef205?source=api-prod","cve":"CVE-2022-4710","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/acaa3142-2bbc-43d3-8ecc-05e8edb931ec/royal-elementor-addons","title":"Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"acaa3142-2bbc-43d3-8ecc-05e8edb931ec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/acaa3142-2bbc-43d3-8ecc-05e8edb931ec?source=api-prod","cve":"CVE-2025-5092","affectedVersions":"<=1.7.1031","severity":"medium"},{"advisoryId":"WPSECADV/WF/b0955689-43a0-442c-974b-5db5e4171f6a/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_compare\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"b0955689-43a0-442c-974b-5db5e4171f6a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b0955689-43a0-442c-974b-5db5e4171f6a?source=api-prod","cve":"CVE-2024-0514","affectedVersions":"<=1.3.87","severity":"medium"},{"advisoryId":"WPSECADV/WF/b2ff2954-f494-4cd7-9f29-ee0e8551e339/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_wishlist\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"b2ff2954-f494-4cd7-9f29-ee0e8551e339"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b2ff2954-f494-4cd7-9f29-ee0e8551e339?source=api-prod","cve":"CVE-2024-0512","affectedVersions":"<=1.3.87","severity":"medium"},{"advisoryId":"WPSECADV/WF/b3e12653-ddfe-4e02-9d9e-0263b9f71def/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Conditions Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"b3e12653-ddfe-4e02-9d9e-0263b9f71def"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b3e12653-ddfe-4e02-9d9e-0263b9f71def?source=api-prod","cve":"CVE-2022-4708","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/b957eb0d-882d-4646-ad84-9c64f957be14/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1020 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"b957eb0d-882d-4646-ad84-9c64f957be14"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b957eb0d-882d-4646-ad84-9c64f957be14?source=api-prod","cve":"CVE-2025-3813","affectedVersions":"<=1.7.1020","severity":"medium"},{"advisoryId":"WPSECADV/WF/ba7b8fe5-aa49-4a70-89c9-1b95a30b1142/royal-elementor-addons","title":"Royal Addons for Elementor <= 1.7.1056 - Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-23 16:35:20","sources":[{"name":"Wordfence","remoteId":"ba7b8fe5-aa49-4a70-89c9-1b95a30b1142"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ba7b8fe5-aa49-4a70-89c9-1b95a30b1142?source=api-prod","cve":"CVE-2026-5428","affectedVersions":"<=1.7.1056","severity":"medium"},{"advisoryId":"WPSECADV/WF/bc2e883b-fb91-425c-a779-89a34eed2ba8/royal-elementor-addons","title":"Royal Elementor Addons <=1.3.55 - Missing Authorization to Subscriber+ Arbitrary Post Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"bc2e883b-fb91-425c-a779-89a34eed2ba8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bc2e883b-fb91-425c-a779-89a34eed2ba8?source=api-prod","cve":"CVE-2022-4103","affectedVersions":"<=1.3.55","severity":"medium"},{"advisoryId":"WPSECADV/WF/bd90b85e-22a9-4c08-b2cf-4f75406e7ca3/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1001 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"bd90b85e-22a9-4c08-b2cf-4f75406e7ca3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bd90b85e-22a9-4c08-b2cf-4f75406e7ca3?source=api-prod","cve":"CVE-2024-9682","affectedVersions":"<=1.7.1001","severity":"medium"},{"advisoryId":"WPSECADV/WF/bdd4022f-b038-4351-9798-77e7c24f1173/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.977 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"bdd4022f-b038-4351-9798-77e7c24f1173"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bdd4022f-b038-4351-9798-77e7c24f1173?source=api-prod","cve":"CVE-2025-39543","affectedVersions":"<=1.3.977","severity":"medium"},{"advisoryId":"WPSECADV/WF/be6db702-43bc-4d1f-a222-d323c70c6bb3/royal-elementor-addons","title":"Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1052 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"be6db702-43bc-4d1f-a222-d323c70c6bb3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be6db702-43bc-4d1f-a222-d323c70c6bb3?source=api-prod","cve":"CVE-2026-28135","affectedVersions":"<=1.7.1052","severity":"medium"},{"advisoryId":"WPSECADV/WF/c23e9810-40ea-43e2-9292-f05f300a7ddf/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Menu Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"c23e9810-40ea-43e2-9292-f05f300a7ddf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c23e9810-40ea-43e2-9292-f05f300a7ddf?source=api-prod","cve":"CVE-2022-4711","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/c3dfb0b7-5d9f-492b-9a1a-d4445d39c00c/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.986 - Authenticated (Subscriber+) Private Post Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"c3dfb0b7-5d9f-492b-9a1a-d4445d39c00c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c3dfb0b7-5d9f-492b-9a1a-d4445d39c00c?source=api-prod","cve":"CVE-2024-7417","affectedVersions":"<=1.3.986","severity":"medium"},{"advisoryId":"WPSECADV/WF/c3e47d14-4c00-4b10-9e4d-7f1d7946a2b4/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.93 - Authenticated (Contributor+) Stored Cross-Site Scriting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"c3e47d14-4c00-4b10-9e4d-7f1d7946a2b4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c3e47d14-4c00-4b10-9e4d-7f1d7946a2b4?source=api-prod","cve":"CVE-2024-31236","affectedVersions":"<=1.3.93","severity":"medium"},{"advisoryId":"WPSECADV/WF/c4192a7f-b962-46f9-a524-7271ed6f4917/royal-elementor-addons","title":"Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 15:17:51","sources":[{"name":"Wordfence","remoteId":"c4192a7f-b962-46f9-a524-7271ed6f4917"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c4192a7f-b962-46f9-a524-7271ed6f4917?source=api-prod","cve":"CVE-2026-2373","affectedVersions":"<=1.7.1049","severity":"medium"},{"advisoryId":"WPSECADV/WF/cb0ac434-7e85-44d4-b21e-df462f63cd9c/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"cb0ac434-7e85-44d4-b21e-df462f63cd9c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cb0ac434-7e85-44d4-b21e-df462f63cd9c?source=api-prod","cve":"CVE-2024-4488","affectedVersions":"<=1.3.976","severity":"medium"},{"advisoryId":"WPSECADV/WF/cb47b6cc-87e4-4d29-bbc7-6d7552bc3943/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Deactivation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"cb47b6cc-87e4-4d29-bbc7-6d7552bc3943"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cb47b6cc-87e4-4d29-bbc7-6d7552bc3943?source=api-prod","cve":"CVE-2022-4702","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/cca7bb88-4a2c-4406-8610-15ce6e77c31f/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting via Back to Top Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-31 17:38:07","sources":[{"name":"Wordfence","remoteId":"cca7bb88-4a2c-4406-8610-15ce6e77c31f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cca7bb88-4a2c-4406-8610-15ce6e77c31f?source=api-prod","cve":"CVE-2024-4087","affectedVersions":"<=1.3.975","severity":"medium"},{"advisoryId":"WPSECADV/WF/cdc37da4-9de6-467b-a168-e3fa29baa06b/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1036 - Missing Authorization to Unauthenticated Media File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"cdc37da4-9de6-467b-a168-e3fa29baa06b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cdc37da4-9de6-467b-a168-e3fa29baa06b?source=api-prod","cve":"CVE-2025-11363","affectedVersions":"<=1.7.1036","severity":"medium"},{"advisoryId":"WPSECADV/WF/cdd464ad-24bc-4922-8bfa-ac42fbe60b52/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Theme Activation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"cdd464ad-24bc-4922-8bfa-ac42fbe60b52"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cdd464ad-24bc-4922-8bfa-ac42fbe60b52?source=api-prod","cve":"CVE-2022-4700","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/d2031289-eaf3-4a1b-8771-769c08d99ca3/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.55 - Cross-Site Request Forgery\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"d2031289-eaf3-4a1b-8771-769c08d99ca3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d2031289-eaf3-4a1b-8771-769c08d99ca3?source=api-prod","affectedVersions":"<=1.3.55","severity":"high"},{"advisoryId":"WPSECADV/WF/d3457b87-c860-4cf2-ac3d-2c6521b629ea/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.87 - Missing Authorization via wpr_update_form_action_meta\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"d3457b87-c860-4cf2-ac3d-2c6521b629ea"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d3457b87-c860-4cf2-ac3d-2c6521b629ea?source=api-prod","cve":"CVE-2024-0516","affectedVersions":"<=1.3.87","severity":"medium"},{"advisoryId":"WPSECADV/WF/dc8bef03-51e0-4448-bddd-85300104e875/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via wpr_update_form_action_meta\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"dc8bef03-51e0-4448-bddd-85300104e875"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dc8bef03-51e0-4448-bddd-85300104e875?source=api-prod","cve":"CVE-2024-0511","affectedVersions":"<=1.3.87","severity":"medium"},{"advisoryId":"WPSECADV/WF/ead108c4-ac09-42ea-95c5-e95dc514f1cb/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1036 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-18 15:19:11","sources":[{"name":"Wordfence","remoteId":"ead108c4-ac09-42ea-95c5-e95dc514f1cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ead108c4-ac09-42ea-95c5-e95dc514f1cb?source=api-prod","cve":"CVE-2025-6251","affectedVersions":"<=1.7.1036","severity":"medium"},{"advisoryId":"WPSECADV/WF/f7f9b1ef-2efc-4d88-bff8-e0dd711b85ab/royal-elementor-addons","title":"Royal Elementor Addons <= 1.7.1001 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"f7f9b1ef-2efc-4d88-bff8-e0dd711b85ab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f7f9b1ef-2efc-4d88-bff8-e0dd711b85ab?source=api-prod","cve":"CVE-2024-56227","affectedVersions":"<=1.7.1001","severity":"medium"},{"advisoryId":"WPSECADV/WF/fa530112-a7cd-4c54-aa87-9e7337d01557/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Kit Import\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"fa530112-a7cd-4c54-aa87-9e7337d01557"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fa530112-a7cd-4c54-aa87-9e7337d01557?source=api-prod","cve":"CVE-2022-4709","affectedVersions":"<=1.3.59","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0a941aef-85f6-4719-b6ab-ace77a03e93e/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Activation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"0a941aef-85f6-4719-b6ab-ace77a03e93e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0a941aef-85f6-4719-b6ab-ace77a03e93e?source=api-prod","cve":"CVE-2022-4705","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/16d083bc-d726-4291-bc6d-a7bf83fa78c3/royal-elementor-addons","title":"Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-16 13:10:11","sources":[{"name":"Wordfence","remoteId":"16d083bc-d726-4291-bc6d-a7bf83fa78c3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/16d083bc-d726-4291-bc6d-a7bf83fa78c3?source=api-prod","cve":"CVE-2026-5162","affectedVersions":"<=1.7.1056","severity":"medium"},{"advisoryId":"WPSECADV/WF/201ff7b6-d72a-43c3-a7b1-c4f917c9d27f/royal-elementor-addons","title":"Royal Elementor Addons <= 1.7.1028 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-25 20:58:34","sources":[{"name":"Wordfence","remoteId":"201ff7b6-d72a-43c3-a7b1-c4f917c9d27f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/201ff7b6-d72a-43c3-a7b1-c4f917c9d27f?source=api-prod","cve":"CVE-2025-5338","affectedVersions":"<=1.7.1028","severity":"medium"},{"advisoryId":"WPSECADV/WF/256b4818-290b-4660-8e83-c18b068a8959/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.87 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"256b4818-290b-4660-8e83-c18b068a8959"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/256b4818-290b-4660-8e83-c18b068a8959?source=api-prod","cve":"CVE-2024-0442","affectedVersions":"<=1.3.87","severity":"medium"},{"advisoryId":"WPSECADV/WF/2626db42-0047-4801-bbcb-e236440c1677/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.93 - Unauthenticated IP Spoofing\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"2626db42-0047-4801-bbcb-e236440c1677"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2626db42-0047-4801-bbcb-e236440c1677?source=api-prod","cve":"CVE-2024-32786","affectedVersions":"<=1.3.93","severity":"medium"},{"advisoryId":"WPSECADV/WF/2d4225a6-4aae-49a5-93e1-8dcc9a77e089/royal-elementor-addons","title":"Royal Elementor Addons <= 1.7.1049 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API Meta Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-03 19:31:46","sources":[{"name":"Wordfence","remoteId":"2d4225a6-4aae-49a5-93e1-8dcc9a77e089"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2d4225a6-4aae-49a5-93e1-8dcc9a77e089?source=api-prod","cve":"CVE-2026-0664","affectedVersions":"<=1.7.1049","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ecec7d7-d1b2-4ccf-ade6-1f78224968c6/royal-elementor-addons","title":"Royal Addons for Elementor <= 1.7.1056 - Missing Authorization to Unauthenticated Form Action Meta Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-01 20:11:49","sources":[{"name":"Wordfence","remoteId":"2ecec7d7-d1b2-4ccf-ade6-1f78224968c6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ecec7d7-d1b2-4ccf-ade6-1f78224968c6?source=api-prod","cve":"CVE-2026-4024","affectedVersions":"<=1.7.1056","severity":"medium"},{"advisoryId":"WPSECADV/WF/30a89e75-2ab1-4e65-8646-b100efed5dbd/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.980 - Authenticated (Author+) External Entity Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"30a89e75-2ab1-4e65-8646-b100efed5dbd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/30a89e75-2ab1-4e65-8646-b100efed5dbd?source=api-prod","cve":"CVE-2024-50442","affectedVersions":"<=1.3.980","severity":"medium"},{"advisoryId":"WPSECADV/WF/337cbec1-c8a8-41b5-8c32-779be671120f/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"337cbec1-c8a8-41b5-8c32-779be671120f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/337cbec1-c8a8-41b5-8c32-779be671120f?source=api-prod","cve":"CVE-2024-3675","affectedVersions":"<=1.3.971","severity":"medium"},{"advisoryId":"WPSECADV/WF/37223d1f-82c8-414f-bf39-63e728541aa3/royal-elementor-addons","title":"Royal Elementor Addons and Template <= 1.7.1001 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"37223d1f-82c8-414f-bf39-63e728541aa3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/37223d1f-82c8-414f-bf39-63e728541aa3?source=api-prod","cve":"CVE-2024-9059","affectedVersions":"<=1.7.1001","severity":"medium"},{"advisoryId":"WPSECADV/WF/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42/royal-elementor-addons","title":"Freemius SDK <= 2.4.2 - Missing Authorization Checks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"39fb0499-9ab4-4a2f-b0db-ece86bcf4d42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=api-prod","cve":"CVE-2022-4974","affectedVersions":"<1.3.33","severity":"medium"},{"advisoryId":"WPSECADV/WF/3ba3cf12-facb-479b-8077-fd279c40607e/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.80 - Missing Authorization to Private/Password Protected Post Read\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"3ba3cf12-facb-479b-8077-fd279c40607e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3ba3cf12-facb-479b-8077-fd279c40607e?source=api-prod","cve":"CVE-2023-5922","affectedVersions":"<=1.3.80","severity":"medium"},{"advisoryId":"WPSECADV/WF/3d3516e7-cce4-4def-be38-d16be3110d59/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_wishlist\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"3d3516e7-cce4-4def-be38-d16be3110d59"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3d3516e7-cce4-4def-be38-d16be3110d59?source=api-prod","cve":"CVE-2024-0513","affectedVersions":"<=1.3.87","severity":"medium"},{"advisoryId":"WPSECADV/WF/3dc3b715-23eb-4cb9-8f44-1d3134c560ec/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.55 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"3dc3b715-23eb-4cb9-8f44-1d3134c560ec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3dc3b715-23eb-4cb9-8f44-1d3134c560ec?source=api-prod","cve":"CVE-2022-4102","affectedVersions":"<=1.3.55","severity":"high"},{"advisoryId":"WPSECADV/WF/3edfc4af-2a28-4bdf-becf-018d9f656947/royal-elementor-addons","title":"Royal Addons for Elementor <= 1.7.1049 - Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 15:36:21","sources":[{"name":"Wordfence","remoteId":"3edfc4af-2a28-4bdf-becf-018d9f656947"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3edfc4af-2a28-4bdf-becf-018d9f656947?source=api-prod","cve":"CVE-2025-13067","affectedVersions":"<=1.7.1049","severity":"high"},{"advisoryId":"WPSECADV/WF/40ca3778-95ff-4b2c-ac47-4ae8c86e245a/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"40ca3778-95ff-4b2c-ac47-4ae8c86e245a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/40ca3778-95ff-4b2c-ac47-4ae8c86e245a?source=api-prod","cve":"CVE-2024-2799","affectedVersions":"<=1.3.971","severity":"medium"},{"advisoryId":"WPSECADV/WF/4529464e-6830-4c2a-8146-79cf5fc1bc7c/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.982 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"4529464e-6830-4c2a-8146-79cf5fc1bc7c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4529464e-6830-4c2a-8146-79cf5fc1bc7c?source=api-prod","cve":"CVE-2024-44001","affectedVersions":"<=1.3.982","severity":"medium"},{"advisoryId":"WPSECADV/WF/4809d513-69e8-4572-9549-9dba9f40cb80/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.75 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"4809d513-69e8-4572-9549-9dba9f40cb80"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4809d513-69e8-4572-9549-9dba9f40cb80?source=api-prod","cve":"CVE-2022-47175","affectedVersions":"<=1.3.75","severity":"medium"},{"advisoryId":"WPSECADV/WF/4a7ef5a0-f6c8-41e1-bb3b-119a682be69f/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1003 - Authenticated (Contributor+) Post Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"4a7ef5a0-f6c8-41e1-bb3b-119a682be69f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4a7ef5a0-f6c8-41e1-bb3b-119a682be69f?source=api-prod","cve":"CVE-2024-10798","affectedVersions":"<=1.7.1003","severity":"medium"},{"advisoryId":"WPSECADV/WF/4d565196-592d-415c-b37c-e54456aa9ed8/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-31 17:22:35","sources":[{"name":"Wordfence","remoteId":"4d565196-592d-415c-b37c-e54456aa9ed8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d565196-592d-415c-b37c-e54456aa9ed8?source=api-prod","cve":"CVE-2024-4342","affectedVersions":"<=1.3.975","severity":"medium"},{"advisoryId":"WPSECADV/WF/50518a54-16d8-4467-beca-a6b8196ed9b9/royal-elementor-addons","title":"Royal Elementor Addons <= 1.7.1006 - Authenticated (Admin+) Server Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"50518a54-16d8-4467-beca-a6b8196ed9b9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/50518a54-16d8-4467-beca-a6b8196ed9b9?source=api-prod","cve":"CVE-2025-26990","affectedVersions":"<=1.7.1006","severity":"medium"},{"advisoryId":"WPSECADV/WF/5122800d-f274-4129-84d4-02380269502c/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.974 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"5122800d-f274-4129-84d4-02380269502c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5122800d-f274-4129-84d4-02380269502c?source=api-prod","cve":"CVE-2024-3887","affectedVersions":"<=1.3.974","severity":"medium"},{"advisoryId":"WPSECADV/WF/5253fe2b-040b-417c-b257-0cb59ee5aa6e/royal-elementor-addons","title":"Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"5253fe2b-040b-417c-b257-0cb59ee5aa6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5253fe2b-040b-417c-b257-0cb59ee5aa6e?source=api-prod","cve":"CVE-2023-33999","affectedVersions":">=1.3,<=1.3.70","severity":"medium"},{"advisoryId":"WPSECADV/WF/55db7d81-7ffb-49da-b64e-23e892bddc57/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Cross-Site Request Forgery to Menu Template creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"55db7d81-7ffb-49da-b64e-23e892bddc57"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/55db7d81-7ffb-49da-b64e-23e892bddc57?source=api-prod","cve":"CVE-2022-4707","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/55f7e39b-e7a5-462b-b1e4-c3d92038f17e/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Activation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"55f7e39b-e7a5-462b-b1e4-c3d92038f17e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/55f7e39b-e7a5-462b-b1e4-c3d92038f17e?source=api-prod","cve":"CVE-2022-4701","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/5666e2b7-acb3-4abb-ac2a-1575206435cf/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"5666e2b7-acb3-4abb-ac2a-1575206435cf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5666e2b7-acb3-4abb-ac2a-1575206435cf?source=api-prod","cve":"CVE-2025-1455","affectedVersions":"<=1.7.1012","severity":"medium"},{"advisoryId":"WPSECADV/WF/57bf222b-5f49-46e2-be84-3e6444807096/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"57bf222b-5f49-46e2-be84-3e6444807096"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/57bf222b-5f49-46e2-be84-3e6444807096?source=api-prod","cve":"CVE-2024-4489","affectedVersions":"<=1.3.976","severity":"medium"},{"advisoryId":"WPSECADV/WF/5ccece54-18fa-42e4-ba1a-d0879b73d66d/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.986 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"5ccece54-18fa-42e4-ba1a-d0879b73d66d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ccece54-18fa-42e4-ba1a-d0879b73d66d?source=api-prod","cve":"CVE-2024-8482","affectedVersions":"<=1.3.986","severity":"medium"},{"advisoryId":"WPSECADV/WF/5ee7b4d8-c397-41f6-981f-9a010e4ab2f1/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1017 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"5ee7b4d8-c397-41f6-981f-9a010e4ab2f1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ee7b4d8-c397-41f6-981f-9a010e4ab2f1?source=api-prod","cve":"CVE-2024-12120","affectedVersions":"<=1.7.1017","severity":"medium"},{"advisoryId":"WPSECADV/WF/62a5c796-1c14-4cb1-9f21-340b40e418df/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Import Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"62a5c796-1c14-4cb1-9f21-340b40e418df"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62a5c796-1c14-4cb1-9f21-340b40e418df?source=api-prod","cve":"CVE-2022-4703","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/64cce528-0ad0-45ec-a8f6-e8791b0bece0/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Import\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"64cce528-0ad0-45ec-a8f6-e8791b0bece0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/64cce528-0ad0-45ec-a8f6-e8791b0bece0?source=api-prod","cve":"CVE-2022-4704","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/68c6e428-b9cf-442f-a896-a8ceb4b9be0e/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"68c6e428-b9cf-442f-a896-a8ceb4b9be0e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/68c6e428-b9cf-442f-a896-a8ceb4b9be0e?source=api-prod","cve":"CVE-2025-1456","affectedVersions":"<=1.7.1012","severity":"medium"},{"advisoryId":"WPSECADV/WF/6aa3d312-485a-4a93-a075-fa7152395f11/royal-elementor-addons","title":"Royal Elementor Addons <=1.3.55 - Authenticated (Subscriber+) Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"6aa3d312-485a-4a93-a075-fa7152395f11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6aa3d312-485a-4a93-a075-fa7152395f11?source=api-prod","cve":"CVE-2022-4102","affectedVersions":"<=1.3.55","severity":"high"},{"advisoryId":"WPSECADV/WF/6bc6a436-6df3-4eaf-a16b-d8b3c3ca7d87/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1007 - Cross-Site Request Forgery to Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"6bc6a436-6df3-4eaf-a16b-d8b3c3ca7d87"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6bc6a436-6df3-4eaf-a16b-d8b3c3ca7d87?source=api-prod","cve":"CVE-2025-1441","affectedVersions":"<=1.7.1007","severity":"medium"},{"advisoryId":"WPSECADV/WF/70582781-9de5-4124-bde4-d3d26724e9b3/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"70582781-9de5-4124-bde4-d3d26724e9b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/70582781-9de5-4124-bde4-d3d26724e9b3?source=api-prod","cve":"CVE-2024-2798","affectedVersions":"<=1.3.971","severity":"medium"},{"advisoryId":"WPSECADV/WF/7a04705d-cd17-4b4b-b04d-de55d6479dab/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.94 - Unauthenticated Limited File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"7a04705d-cd17-4b4b-b04d-de55d6479dab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7a04705d-cd17-4b4b-b04d-de55d6479dab?source=api-prod","cve":"CVE-2024-1567","affectedVersions":"<=1.3.94","severity":"high"},{"advisoryId":"WPSECADV/WF/83a0150d-a9fa-4cc2-8fe8-a429747a9964/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.980 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"83a0150d-a9fa-4cc2-8fe8-a429747a9964"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/83a0150d-a9fa-4cc2-8fe8-a429747a9964?source=api-prod","cve":"CVE-2024-5818","affectedVersions":"<=1.3.980","severity":"medium"},{"advisoryId":"WPSECADV/WF/83ea2ec3-5d5b-44ea-83e6-41c4fa6e2e5f/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"83ea2ec3-5d5b-44ea-83e6-41c4fa6e2e5f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/83ea2ec3-5d5b-44ea-83e6-41c4fa6e2e5f?source=api-prod","cve":"CVE-2024-3889","affectedVersions":"<=1.3.971","severity":"medium"},{"advisoryId":"WPSECADV/WF/8619c999-5cf7-4888-bdb2-815238411303/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"8619c999-5cf7-4888-bdb2-815238411303"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8619c999-5cf7-4888-bdb2-815238411303?source=api-prod","cve":"CVE-2024-1500","affectedVersions":"<=1.3.91","severity":"medium"},{"advisoryId":"WPSECADV/WF/86c9bcf1-c69e-47ca-b74b-8ce6157f520b/royal-elementor-addons","title":"Royal Elementor Addons <=1.3.70 - Unauthenticated MailChimp API Key Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"86c9bcf1-c69e-47ca-b74b-8ce6157f520b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/86c9bcf1-c69e-47ca-b74b-8ce6157f520b?source=api-prod","cve":"CVE-2023-3709","affectedVersions":"<=1.3.70","severity":"medium"},{"advisoryId":"WPSECADV/WF/9744055a-b199-4945-afcc-4f5b85f5f1e8/royal-elementor-addons","title":"Royal Addons for Elementor <= 1.7.1057 - Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"9744055a-b199-4945-afcc-4f5b85f5f1e8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9744055a-b199-4945-afcc-4f5b85f5f1e8?source=api-prod","cve":"CVE-2026-6229","affectedVersions":"<=1.7.1057","severity":"high"},{"advisoryId":"WPSECADV/WF/9e860c60-b330-4a6c-8d15-947451af62fc/royal-elementor-addons","title":"Royal Elementor Addons <= 1.7.1001 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"9e860c60-b330-4a6c-8d15-947451af62fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9e860c60-b330-4a6c-8d15-947451af62fc?source=api-prod","cve":"CVE-2024-56226","affectedVersions":"<=1.7.1001","severity":"medium"},{"advisoryId":"WPSECADV/WF/a4178271-c09e-4094-a616-5a00d28f39a3/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_compare\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"a4178271-c09e-4094-a616-5a00d28f39a3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4178271-c09e-4094-a616-5a00d28f39a3?source=api-prod","cve":"CVE-2024-0515","affectedVersions":"<=1.3.87","severity":"medium"},{"advisoryId":"WPSECADV/WF/a4b353bf-f9be-465a-8723-9ea721b5baab/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.987 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"a4b353bf-f9be-465a-8723-9ea721b5baab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4b353bf-f9be-465a-8723-9ea721b5baab?source=api-prod","cve":"CVE-2024-56062","affectedVersions":"<=1.3.987","severity":"medium"},{"advisoryId":"WPSECADV/WF/a720b38c-37f0-4edf-9868-de3a105551ee/royal-elementor-addons","title":"Royal Elementor Addons <= 1.7.1017 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"a720b38c-37f0-4edf-9868-de3a105551ee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a720b38c-37f0-4edf-9868-de3a105551ee?source=api-prod","cve":"CVE-2025-39361","affectedVersions":"<=1.7.1017","severity":"medium"},{"advisoryId":"WPSECADV/WF/a8e34c05-7431-4acd-91f3-aab5e66f61ad/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1006 - Cross-Site Request Forgery to Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-13 19:52:46","sources":[{"name":"Wordfence","remoteId":"a8e34c05-7431-4acd-91f3-aab5e66f61ad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a8e34c05-7431-4acd-91f3-aab5e66f61ad?source=api-prod","cve":"CVE-2025-0393","affectedVersions":"<=1.7.1006","severity":"medium"},{"advisoryId":"WPSECADV/WF/a8e39f0b-eb4c-4568-9f5a-60a0dc3eb6ba/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1001 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"a8e39f0b-eb4c-4568-9f5a-60a0dc3eb6ba"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a8e39f0b-eb4c-4568-9f5a-60a0dc3eb6ba?source=api-prod","cve":"CVE-2024-9668","affectedVersions":"<=1.7.1001","severity":"medium"},{"advisoryId":"WPSECADV/WF/a9d95af5-96da-4259-98c6-e2c4c574a896/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.78 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"a9d95af5-96da-4259-98c6-e2c4c574a896"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a9d95af5-96da-4259-98c6-e2c4c574a896?source=api-prod","cve":"CVE-2023-5360","affectedVersions":"<=1.3.78","severity":"critical"},{"advisoryId":"WPSECADV/WF/ac6c6ce4-9944-4c8e-89aa-6a2e870ef205/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"ac6c6ce4-9944-4c8e-89aa-6a2e870ef205"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ac6c6ce4-9944-4c8e-89aa-6a2e870ef205?source=api-prod","cve":"CVE-2022-4710","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/acaa3142-2bbc-43d3-8ecc-05e8edb931ec/royal-elementor-addons","title":"Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"acaa3142-2bbc-43d3-8ecc-05e8edb931ec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/acaa3142-2bbc-43d3-8ecc-05e8edb931ec?source=api-prod","cve":"CVE-2025-5092","affectedVersions":"<=1.7.1031","severity":"medium"},{"advisoryId":"WPSECADV/WF/b0955689-43a0-442c-974b-5db5e4171f6a/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_compare\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"b0955689-43a0-442c-974b-5db5e4171f6a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b0955689-43a0-442c-974b-5db5e4171f6a?source=api-prod","cve":"CVE-2024-0514","affectedVersions":"<=1.3.87","severity":"medium"},{"advisoryId":"WPSECADV/WF/b2ff2954-f494-4cd7-9f29-ee0e8551e339/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_wishlist\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"b2ff2954-f494-4cd7-9f29-ee0e8551e339"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b2ff2954-f494-4cd7-9f29-ee0e8551e339?source=api-prod","cve":"CVE-2024-0512","affectedVersions":"<=1.3.87","severity":"medium"},{"advisoryId":"WPSECADV/WF/b3e12653-ddfe-4e02-9d9e-0263b9f71def/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Conditions Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"b3e12653-ddfe-4e02-9d9e-0263b9f71def"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b3e12653-ddfe-4e02-9d9e-0263b9f71def?source=api-prod","cve":"CVE-2022-4708","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/b957eb0d-882d-4646-ad84-9c64f957be14/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1020 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"b957eb0d-882d-4646-ad84-9c64f957be14"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b957eb0d-882d-4646-ad84-9c64f957be14?source=api-prod","cve":"CVE-2025-3813","affectedVersions":"<=1.7.1020","severity":"medium"},{"advisoryId":"WPSECADV/WF/ba7b8fe5-aa49-4a70-89c9-1b95a30b1142/royal-elementor-addons","title":"Royal Addons for Elementor <= 1.7.1056 - Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-23 16:35:20","sources":[{"name":"Wordfence","remoteId":"ba7b8fe5-aa49-4a70-89c9-1b95a30b1142"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ba7b8fe5-aa49-4a70-89c9-1b95a30b1142?source=api-prod","cve":"CVE-2026-5428","affectedVersions":"<=1.7.1056","severity":"medium"},{"advisoryId":"WPSECADV/WF/bc2e883b-fb91-425c-a779-89a34eed2ba8/royal-elementor-addons","title":"Royal Elementor Addons <=1.3.55 - Missing Authorization to Subscriber+ Arbitrary Post Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"bc2e883b-fb91-425c-a779-89a34eed2ba8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bc2e883b-fb91-425c-a779-89a34eed2ba8?source=api-prod","cve":"CVE-2022-4103","affectedVersions":"<=1.3.55","severity":"medium"},{"advisoryId":"WPSECADV/WF/bd90b85e-22a9-4c08-b2cf-4f75406e7ca3/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1001 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"bd90b85e-22a9-4c08-b2cf-4f75406e7ca3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bd90b85e-22a9-4c08-b2cf-4f75406e7ca3?source=api-prod","cve":"CVE-2024-9682","affectedVersions":"<=1.7.1001","severity":"medium"},{"advisoryId":"WPSECADV/WF/bdd4022f-b038-4351-9798-77e7c24f1173/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.977 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"bdd4022f-b038-4351-9798-77e7c24f1173"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bdd4022f-b038-4351-9798-77e7c24f1173?source=api-prod","cve":"CVE-2025-39543","affectedVersions":"<=1.3.977","severity":"medium"},{"advisoryId":"WPSECADV/WF/be6db702-43bc-4d1f-a222-d323c70c6bb3/royal-elementor-addons","title":"Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1052 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"be6db702-43bc-4d1f-a222-d323c70c6bb3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be6db702-43bc-4d1f-a222-d323c70c6bb3?source=api-prod","cve":"CVE-2026-28135","affectedVersions":"<=1.7.1052","severity":"medium"},{"advisoryId":"WPSECADV/WF/c23e9810-40ea-43e2-9292-f05f300a7ddf/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Menu Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"c23e9810-40ea-43e2-9292-f05f300a7ddf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c23e9810-40ea-43e2-9292-f05f300a7ddf?source=api-prod","cve":"CVE-2022-4711","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/c3dfb0b7-5d9f-492b-9a1a-d4445d39c00c/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.986 - Authenticated (Subscriber+) Private Post Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"c3dfb0b7-5d9f-492b-9a1a-d4445d39c00c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c3dfb0b7-5d9f-492b-9a1a-d4445d39c00c?source=api-prod","cve":"CVE-2024-7417","affectedVersions":"<=1.3.986","severity":"medium"},{"advisoryId":"WPSECADV/WF/c3e47d14-4c00-4b10-9e4d-7f1d7946a2b4/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.93 - Authenticated (Contributor+) Stored Cross-Site Scriting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"c3e47d14-4c00-4b10-9e4d-7f1d7946a2b4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c3e47d14-4c00-4b10-9e4d-7f1d7946a2b4?source=api-prod","cve":"CVE-2024-31236","affectedVersions":"<=1.3.93","severity":"medium"},{"advisoryId":"WPSECADV/WF/c4192a7f-b962-46f9-a524-7271ed6f4917/royal-elementor-addons","title":"Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 15:17:51","sources":[{"name":"Wordfence","remoteId":"c4192a7f-b962-46f9-a524-7271ed6f4917"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c4192a7f-b962-46f9-a524-7271ed6f4917?source=api-prod","cve":"CVE-2026-2373","affectedVersions":"<=1.7.1049","severity":"medium"},{"advisoryId":"WPSECADV/WF/c91a14d3-bc41-4490-888c-486ad2994095/royal-elementor-addons","title":"Royal Addons for Elementor <= 1.7.1056 - Unauthenticated Stored Cross-Site Scripting via 'status' Parameter in wpr_update_form_action_meta\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:32:14","sources":[{"name":"Wordfence","remoteId":"c91a14d3-bc41-4490-888c-486ad2994095"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c91a14d3-bc41-4490-888c-486ad2994095?source=api-prod","cve":"CVE-2026-4803","affectedVersions":"<=1.7.1056","severity":"high"},{"advisoryId":"WPSECADV/WF/cb0ac434-7e85-44d4-b21e-df462f63cd9c/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"cb0ac434-7e85-44d4-b21e-df462f63cd9c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cb0ac434-7e85-44d4-b21e-df462f63cd9c?source=api-prod","cve":"CVE-2024-4488","affectedVersions":"<=1.3.976","severity":"medium"},{"advisoryId":"WPSECADV/WF/cb47b6cc-87e4-4d29-bbc7-6d7552bc3943/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Deactivation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"cb47b6cc-87e4-4d29-bbc7-6d7552bc3943"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cb47b6cc-87e4-4d29-bbc7-6d7552bc3943?source=api-prod","cve":"CVE-2022-4702","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/cca7bb88-4a2c-4406-8610-15ce6e77c31f/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting via Back to Top Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-31 17:38:07","sources":[{"name":"Wordfence","remoteId":"cca7bb88-4a2c-4406-8610-15ce6e77c31f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cca7bb88-4a2c-4406-8610-15ce6e77c31f?source=api-prod","cve":"CVE-2024-4087","affectedVersions":"<=1.3.975","severity":"medium"},{"advisoryId":"WPSECADV/WF/cdc37da4-9de6-467b-a168-e3fa29baa06b/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1036 - Missing Authorization to Unauthenticated Media File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"cdc37da4-9de6-467b-a168-e3fa29baa06b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cdc37da4-9de6-467b-a168-e3fa29baa06b?source=api-prod","cve":"CVE-2025-11363","affectedVersions":"<=1.7.1036","severity":"medium"},{"advisoryId":"WPSECADV/WF/cdd464ad-24bc-4922-8bfa-ac42fbe60b52/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Theme Activation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"cdd464ad-24bc-4922-8bfa-ac42fbe60b52"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cdd464ad-24bc-4922-8bfa-ac42fbe60b52?source=api-prod","cve":"CVE-2022-4700","affectedVersions":"<=1.3.59","severity":"medium"},{"advisoryId":"WPSECADV/WF/d2031289-eaf3-4a1b-8771-769c08d99ca3/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.55 - Cross-Site Request Forgery\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"d2031289-eaf3-4a1b-8771-769c08d99ca3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d2031289-eaf3-4a1b-8771-769c08d99ca3?source=api-prod","affectedVersions":"<=1.3.55","severity":"high"},{"advisoryId":"WPSECADV/WF/d3457b87-c860-4cf2-ac3d-2c6521b629ea/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.87 - Missing Authorization via wpr_update_form_action_meta\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"d3457b87-c860-4cf2-ac3d-2c6521b629ea"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d3457b87-c860-4cf2-ac3d-2c6521b629ea?source=api-prod","cve":"CVE-2024-0516","affectedVersions":"<=1.3.87","severity":"medium"},{"advisoryId":"WPSECADV/WF/dc8bef03-51e0-4448-bddd-85300104e875/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via wpr_update_form_action_meta\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"dc8bef03-51e0-4448-bddd-85300104e875"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dc8bef03-51e0-4448-bddd-85300104e875?source=api-prod","cve":"CVE-2024-0511","affectedVersions":"<=1.3.87","severity":"medium"},{"advisoryId":"WPSECADV/WF/ead108c4-ac09-42ea-95c5-e95dc514f1cb/royal-elementor-addons","title":"Royal Elementor Addons and Templates <= 1.7.1036 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-18 15:19:11","sources":[{"name":"Wordfence","remoteId":"ead108c4-ac09-42ea-95c5-e95dc514f1cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ead108c4-ac09-42ea-95c5-e95dc514f1cb?source=api-prod","cve":"CVE-2025-6251","affectedVersions":"<=1.7.1036","severity":"medium"},{"advisoryId":"WPSECADV/WF/ee96d8c5-baf0-4c5c-9ace-e88bbb95ee0a/royal-elementor-addons","title":"Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Follow Button Text' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:53:29","sources":[{"name":"Wordfence","remoteId":"ee96d8c5-baf0-4c5c-9ace-e88bbb95ee0a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ee96d8c5-baf0-4c5c-9ace-e88bbb95ee0a?source=api-prod","cve":"CVE-2026-5159","affectedVersions":"<=1.7.1056","severity":"medium"},{"advisoryId":"WPSECADV/WF/f7f9b1ef-2efc-4d88-bff8-e0dd711b85ab/royal-elementor-addons","title":"Royal Elementor Addons <= 1.7.1001 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"f7f9b1ef-2efc-4d88-bff8-e0dd711b85ab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f7f9b1ef-2efc-4d88-bff8-e0dd711b85ab?source=api-prod","cve":"CVE-2024-56227","affectedVersions":"<=1.7.1001","severity":"medium"},{"advisoryId":"WPSECADV/WF/fa530112-a7cd-4c54-aa87-9e7337d01557/royal-elementor-addons","title":"Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Kit Import\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"fa530112-a7cd-4c54-aa87-9e7337d01557"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fa530112-a7cd-4c54-aa87-9e7337d01557?source=api-prod","cve":"CVE-2022-4709","affectedVersions":"<=1.3.59","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_73622d656c656d656e746f722d636f6e746163742d666f726d2d6462811c9dc5_gen.json b/internal/data/assets/plugin_73622d656c656d656e746f722d636f6e746163742d666f726d2d6462811c9dc5_gen.json index c2b67db9..01ed7878 100644 --- a/internal/data/assets/plugin_73622d656c656d656e746f722d636f6e746163742d666f726d2d6462811c9dc5_gen.json +++ b/internal/data/assets/plugin_73622d656c656d656e746f722d636f6e746163742d666f726d2d6462811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/43a1e5b7-9361-406e-97b7-776b831acc33/sb-elementor-contact-form-db","title":"Contact Form DB - Elementor <= 1.7 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-07-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"43a1e5b7-9361-406e-97b7-776b831acc33"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/43a1e5b7-9361-406e-97b7-776b831acc33?source=api-prod","cve":"CVE-2022-2116","affectedVersions":"<=1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/e287e85d-8687-4079-99ea-92718031f343/sb-elementor-contact-form-db","title":"Elementor Contact Form DB <= 1.5 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-01-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"e287e85d-8687-4079-99ea-92718031f343"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e287e85d-8687-4079-99ea-92718031f343?source=api-prod","cve":"CVE-2021-3133","affectedVersions":"<=1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/f708e910-7745-4ff5-9f9f-5552dbaf1113/sb-elementor-contact-form-db","title":"Elementor Contact Form DB <= 1.5 - Sensitive Information Disclosure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-06-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"f708e910-7745-4ff5-9f9f-5552dbaf1113"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f708e910-7745-4ff5-9f9f-5552dbaf1113?source=api-prod","affectedVersions":"<=1.5","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/3cbd58da-3d72-4b8c-add9-c38afc6fa3d0/sb-elementor-contact-form-db","title":"FormsDB – Save Elementor Forms to Google Sheets & Post Type <= 2.1.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"3cbd58da-3d72-4b8c-add9-c38afc6fa3d0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3cbd58da-3d72-4b8c-add9-c38afc6fa3d0?source=api-prod","cve":"CVE-2026-25320","affectedVersions":"<=2.1.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/43a1e5b7-9361-406e-97b7-776b831acc33/sb-elementor-contact-form-db","title":"Contact Form DB - Elementor <= 1.7 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-07-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"43a1e5b7-9361-406e-97b7-776b831acc33"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/43a1e5b7-9361-406e-97b7-776b831acc33?source=api-prod","cve":"CVE-2022-2116","affectedVersions":"<=1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/e287e85d-8687-4079-99ea-92718031f343/sb-elementor-contact-form-db","title":"Elementor Contact Form DB <= 1.5 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-01-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"e287e85d-8687-4079-99ea-92718031f343"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e287e85d-8687-4079-99ea-92718031f343?source=api-prod","cve":"CVE-2021-3133","affectedVersions":"<=1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/f708e910-7745-4ff5-9f9f-5552dbaf1113/sb-elementor-contact-form-db","title":"Elementor Contact Form DB <= 1.5 - Sensitive Information Disclosure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-06-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"f708e910-7745-4ff5-9f9f-5552dbaf1113"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f708e910-7745-4ff5-9f9f-5552dbaf1113?source=api-prod","affectedVersions":"<=1.5","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_736374762d73616c65732d636f756e74646f776e2d74696d6572811c9dc5_gen.json b/internal/data/assets/plugin_736374762d73616c65732d636f756e74646f776e2d74696d6572811c9dc5_gen.json new file mode 100644 index 00000000..8295309e --- /dev/null +++ b/internal/data/assets/plugin_736374762d73616c65732d636f756e74646f776e2d74696d6572811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/f200062a-5f53-4abc-ae96-904f85d8b4e8/sctv-sales-countdown-timer","title":"Sales Countdown Timer for WooCommerce and WordPress <= 1.1.8.1 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"f200062a-5f53-4abc-ae96-904f85d8b4e8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f200062a-5f53-4abc-ae96-904f85d8b4e8?source=api-prod","cve":"CVE-2026-27052","affectedVersions":"<=1.1.8.1","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7365637572652d636f70792d636f6e74656e742d70726f74656374696f6e811c9dc5_gen.json b/internal/data/assets/plugin_7365637572652d636f70792d636f6e74656e742d70726f74656374696f6e811c9dc5_gen.json index 124760c6..aa375de8 100644 --- a/internal/data/assets/plugin_7365637572652d636f70792d636f6e74656e742d70726f74656374696f6e811c9dc5_gen.json +++ b/internal/data/assets/plugin_7365637572652d636f70792d636f6e74656e742d70726f74656374696f6e811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0afc98b1-e1ee-4c77-89fc-9ccb045c6733/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 3.9.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"0afc98b1-e1ee-4c77-89fc-9ccb045c6733"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0afc98b1-e1ee-4c77-89fc-9ccb045c6733?source=api-prod","cve":"CVE-2024-33587","affectedVersions":"<=3.9.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/0b52cc2a-c511-4801-8a95-f90d8d980c85/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 2.8.1 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"0b52cc2a-c511-4801-8a95-f90d8d980c85"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0b52cc2a-c511-4801-8a95-f90d8d980c85?source=api-prod","cve":"CVE-2021-24931","affectedVersions":"<=2.8.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/25c35a42-9f1a-4f67-a074-c6359e8b1a41/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.1.6 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"25c35a42-9f1a-4f67-a074-c6359e8b1a41"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/25c35a42-9f1a-4f67-a074-c6359e8b1a41?source=api-prod","cve":"CVE-2024-6889","affectedVersions":"<=4.1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/72b95777-d17b-4504-95fd-c83b18106b9e/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.9.2 - Unauthenticated Sensitive Information Exposure via Exposed CSV Export File\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-11 21:22:25","sources":[{"name":"Wordfence","remoteId":"72b95777-d17b-4504-95fd-c83b18106b9e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/72b95777-d17b-4504-95fd-c83b18106b9e?source=api-prod","cve":"CVE-2025-14442","affectedVersions":"<=4.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/7363b5de-db30-4b35-b701-5c8f2835ec6c/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.4.7 - Missing Authorization to Unauthenticated User Email Retrieval via ays_sccp_reports_user_search Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-28 22:01:07","sources":[{"name":"Wordfence","remoteId":"7363b5de-db30-4b35-b701-5c8f2835ec6c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7363b5de-db30-4b35-b701-5c8f2835ec6c?source=api-prod","cve":"CVE-2025-1404","affectedVersions":"<=4.4.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/7cffe04e-a2e5-4752-a5c1-7c95f0007e0b/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data Export\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-11 21:20:54","sources":[{"name":"Wordfence","remoteId":"7cffe04e-a2e5-4752-a5c1-7c95f0007e0b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7cffe04e-a2e5-4752-a5c1-7c95f0007e0b?source=api-prod","cve":"CVE-2025-14159","affectedVersions":"<=4.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/81d73996-d192-485b-bc47-1db7e6ca70e6/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.2.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"81d73996-d192-485b-bc47-1db7e6ca70e6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/81d73996-d192-485b-bc47-1db7e6ca70e6?source=api-prod","cve":"CVE-2024-47306","affectedVersions":"<=4.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/a621cd24-d012-40f0-bfac-29268751f772/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.1.6 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"a621cd24-d012-40f0-bfac-29268751f772"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a621cd24-d012-40f0-bfac-29268751f772?source=api-prod","cve":"CVE-2024-6888","affectedVersions":"<=4.1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/bbc1b46e-139a-4e1a-a0c7-e45e10adada5/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 2.6.6 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-06-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"bbc1b46e-139a-4e1a-a0c7-e45e10adada5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bbc1b46e-139a-4e1a-a0c7-e45e10adada5?source=api-prod","cve":"CVE-2021-24484","affectedVersions":"<2.6.7","severity":"high"},{"advisoryId":"WPSECADV/WF/c4dd681d-90cb-44dc-adf0-d7e269d15a60/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.9.8 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-12 01:05:30","sources":[{"name":"Wordfence","remoteId":"c4dd681d-90cb-44dc-adf0-d7e269d15a60"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c4dd681d-90cb-44dc-adf0-d7e269d15a60?source=api-prod","cve":"CVE-2026-1320","affectedVersions":"<=4.9.8","severity":"high"},{"advisoryId":"WPSECADV/WF/d4c8333f-1570-4bf2-a7d0-cce705e88f27/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.0.8 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"d4c8333f-1570-4bf2-a7d0-cce705e88f27"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d4c8333f-1570-4bf2-a7d0-cce705e88f27?source=api-prod","cve":"CVE-2024-6138","affectedVersions":"<=4.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/db510706-b916-49f5-8a09-bd254f1abbf6/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.5.5 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"db510706-b916-49f5-8a09-bd254f1abbf6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/db510706-b916-49f5-8a09-bd254f1abbf6?source=api-prod","cve":"CVE-2025-32133","affectedVersions":"<=4.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/dfd95489-c1d5-45cc-8ac4-400a39391aa2/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 3.7.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"dfd95489-c1d5-45cc-8ac4-400a39391aa2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dfd95489-c1d5-45cc-8ac4-400a39391aa2?source=api-prod","cve":"CVE-2024-32787","affectedVersions":"<=3.7.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f138d917-0dc2-4408-aa6a-db1fd0410eb4/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 5.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-24 20:52:46","sources":[{"name":"Wordfence","remoteId":"f138d917-0dc2-4408-aa6a-db1fd0410eb4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f138d917-0dc2-4408-aa6a-db1fd0410eb4?source=api-prod","cve":"CVE-2026-2367","affectedVersions":"<=5.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f7c93236-09d9-4e52-a96b-917d57d667f7/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.4.3 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"f7c93236-09d9-4e52-a96b-917d57d667f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f7c93236-09d9-4e52-a96b-917d57d667f7?source=api-prod","cve":"CVE-2025-30905","affectedVersions":"<=4.4.3","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0afc98b1-e1ee-4c77-89fc-9ccb045c6733/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 3.9.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"0afc98b1-e1ee-4c77-89fc-9ccb045c6733"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0afc98b1-e1ee-4c77-89fc-9ccb045c6733?source=api-prod","cve":"CVE-2024-33587","affectedVersions":"<=3.9.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/0b52cc2a-c511-4801-8a95-f90d8d980c85/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 2.8.1 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"0b52cc2a-c511-4801-8a95-f90d8d980c85"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0b52cc2a-c511-4801-8a95-f90d8d980c85?source=api-prod","cve":"CVE-2021-24931","affectedVersions":"<=2.8.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/25c35a42-9f1a-4f67-a074-c6359e8b1a41/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.1.6 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"25c35a42-9f1a-4f67-a074-c6359e8b1a41"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/25c35a42-9f1a-4f67-a074-c6359e8b1a41?source=api-prod","cve":"CVE-2024-6889","affectedVersions":"<=4.1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/6ea4ad81-dba6-4055-b81c-682424a6ffd0/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 5.0.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"6ea4ad81-dba6-4055-b81c-682424a6ffd0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6ea4ad81-dba6-4055-b81c-682424a6ffd0?source=api-prod","cve":"CVE-2026-25335","affectedVersions":"<=5.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/72b95777-d17b-4504-95fd-c83b18106b9e/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.9.2 - Unauthenticated Sensitive Information Exposure via Exposed CSV Export File\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-11 21:22:25","sources":[{"name":"Wordfence","remoteId":"72b95777-d17b-4504-95fd-c83b18106b9e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/72b95777-d17b-4504-95fd-c83b18106b9e?source=api-prod","cve":"CVE-2025-14442","affectedVersions":"<=4.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/7363b5de-db30-4b35-b701-5c8f2835ec6c/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.4.7 - Missing Authorization to Unauthenticated User Email Retrieval via ays_sccp_reports_user_search Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-28 22:01:07","sources":[{"name":"Wordfence","remoteId":"7363b5de-db30-4b35-b701-5c8f2835ec6c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7363b5de-db30-4b35-b701-5c8f2835ec6c?source=api-prod","cve":"CVE-2025-1404","affectedVersions":"<=4.4.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/7cffe04e-a2e5-4752-a5c1-7c95f0007e0b/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data Export\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-11 21:20:54","sources":[{"name":"Wordfence","remoteId":"7cffe04e-a2e5-4752-a5c1-7c95f0007e0b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7cffe04e-a2e5-4752-a5c1-7c95f0007e0b?source=api-prod","cve":"CVE-2025-14159","affectedVersions":"<=4.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/81d73996-d192-485b-bc47-1db7e6ca70e6/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.2.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"81d73996-d192-485b-bc47-1db7e6ca70e6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/81d73996-d192-485b-bc47-1db7e6ca70e6?source=api-prod","cve":"CVE-2024-47306","affectedVersions":"<=4.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/a621cd24-d012-40f0-bfac-29268751f772/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.1.6 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"a621cd24-d012-40f0-bfac-29268751f772"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a621cd24-d012-40f0-bfac-29268751f772?source=api-prod","cve":"CVE-2024-6888","affectedVersions":"<=4.1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/bbc1b46e-139a-4e1a-a0c7-e45e10adada5/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 2.6.6 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-06-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"bbc1b46e-139a-4e1a-a0c7-e45e10adada5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bbc1b46e-139a-4e1a-a0c7-e45e10adada5?source=api-prod","cve":"CVE-2021-24484","affectedVersions":"<2.6.7","severity":"high"},{"advisoryId":"WPSECADV/WF/c4dd681d-90cb-44dc-adf0-d7e269d15a60/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.9.8 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-12 01:05:30","sources":[{"name":"Wordfence","remoteId":"c4dd681d-90cb-44dc-adf0-d7e269d15a60"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c4dd681d-90cb-44dc-adf0-d7e269d15a60?source=api-prod","cve":"CVE-2026-1320","affectedVersions":"<=4.9.8","severity":"high"},{"advisoryId":"WPSECADV/WF/d4c8333f-1570-4bf2-a7d0-cce705e88f27/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.0.8 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"d4c8333f-1570-4bf2-a7d0-cce705e88f27"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d4c8333f-1570-4bf2-a7d0-cce705e88f27?source=api-prod","cve":"CVE-2024-6138","affectedVersions":"<=4.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/db510706-b916-49f5-8a09-bd254f1abbf6/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.5.5 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"db510706-b916-49f5-8a09-bd254f1abbf6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/db510706-b916-49f5-8a09-bd254f1abbf6?source=api-prod","cve":"CVE-2025-32133","affectedVersions":"<=4.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/dfd95489-c1d5-45cc-8ac4-400a39391aa2/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 3.7.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"dfd95489-c1d5-45cc-8ac4-400a39391aa2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dfd95489-c1d5-45cc-8ac4-400a39391aa2?source=api-prod","cve":"CVE-2024-32787","affectedVersions":"<=3.7.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f138d917-0dc2-4408-aa6a-db1fd0410eb4/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 5.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-24 20:52:46","sources":[{"name":"Wordfence","remoteId":"f138d917-0dc2-4408-aa6a-db1fd0410eb4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f138d917-0dc2-4408-aa6a-db1fd0410eb4?source=api-prod","cve":"CVE-2026-2367","affectedVersions":"<=5.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f7c93236-09d9-4e52-a96b-917d57d667f7/secure-copy-content-protection","title":"Secure Copy Content Protection and Content Locking <= 4.4.3 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"f7c93236-09d9-4e52-a96b-917d57d667f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f7c93236-09d9-4e52-a96b-917d57d667f7?source=api-prod","cve":"CVE-2025-30905","affectedVersions":"<=4.4.3","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_73696d706c652d6d656d62657273686970811c9dc5_gen.json b/internal/data/assets/plugin_73696d706c652d6d656d62657273686970811c9dc5_gen.json index 052b2b3f..4a0e8bcc 100644 --- a/internal/data/assets/plugin_73696d706c652d6d656d62657273686970811c9dc5_gen.json +++ b/internal/data/assets/plugin_73696d706c652d6d656d62657273686970811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/1664fef3-6416-4678-9ee7-bed2184d7490/simple-membership","title":"Simple Membership <= 4.0.3 - Authenticated (Admin+) SQL Injections\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"1664fef3-6416-4678-9ee7-bed2184d7490"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1664fef3-6416-4678-9ee7-bed2184d7490?source=api-prod","affectedVersions":"<=4.0.3","severity":"high"},{"advisoryId":"WPSECADV/WF/18fe9769-3681-4a5e-866a-640b4cc76199/simple-membership","title":"Simple Membership <= 4.3.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"18fe9769-3681-4a5e-866a-640b4cc76199"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/18fe9769-3681-4a5e-866a-640b4cc76199?source=api-prod","cve":"CVE-2023-50376","affectedVersions":"<4.3.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/284eafb9-94bc-4478-abff-f7dafd510a1d/simple-membership","title":"Simple Membership <= 4.1.2 - Membership Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-07-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"284eafb9-94bc-4478-abff-f7dafd510a1d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/284eafb9-94bc-4478-abff-f7dafd510a1d?source=api-prod","cve":"CVE-2022-2317","affectedVersions":"<=4.1.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/366165fe-93e5-49ab-b2e5-1de624f22286/simple-membership","title":"Simple Membership <= 4.3.8 - Reflected Cross-Site Scripting Vulnerability via environment_mode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"366165fe-93e5-49ab-b2e5-1de624f22286"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/366165fe-93e5-49ab-b2e5-1de624f22286?source=api-prod","cve":"CVE-2023-6882","affectedVersions":"<=4.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/45bb4a6f-560f-4dc8-9005-1e4c5727d56f/simple-membership","title":"Simple Membership <= 4.6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"45bb4a6f-560f-4dc8-9005-1e4c5727d56f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/45bb4a6f-560f-4dc8-9005-1e4c5727d56f?source=api-prod","cve":"CVE-2025-49333","affectedVersions":"<=4.6.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/4e4df9a6-8f7d-428b-a596-0751ca047169/simple-membership","title":"Simple Membership <= 4.7.0 - Unauthenticated Improper Handling of Missing Values\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"4e4df9a6-8f7d-428b-a596-0751ca047169"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4e4df9a6-8f7d-428b-a596-0751ca047169?source=api-prod","cve":"CVE-2026-1461","affectedVersions":"<=4.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/56fdbf80-8ea2-412a-b166-b7c27de88e70/simple-membership","title":"Simple Membership <= 4.4.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"56fdbf80-8ea2-412a-b166-b7c27de88e70"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/56fdbf80-8ea2-412a-b166-b7c27de88e70?source=api-prod","cve":"CVE-2024-4383","affectedVersions":"<=4.4.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/63779ab7-ba8b-459d-beb3-a32faf8f4394/simple-membership","title":"Simple Membership <= 4.4.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"63779ab7-ba8b-459d-beb3-a32faf8f4394"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63779ab7-ba8b-459d-beb3-a32faf8f4394?source=api-prod","cve":"CVE-2024-3730","affectedVersions":"<=4.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/6f721aa1-d12f-4829-8e82-61f9af6a3519/simple-membership","title":"Simple Membership <= 3.3.2 - Multiple Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-09-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f721aa1-d12f-4829-8e82-61f9af6a3519"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f721aa1-d12f-4829-8e82-61f9af6a3519?source=api-prod","cve":"CVE-2016-10884","affectedVersions":"<=3.3.2","severity":"high"},{"advisoryId":"WPSECADV/WF/70fa060f-11eb-4b51-b985-59421f44414e/simple-membership","title":"Simple Membership <= 4.0.8 - Cross-Site Request Forgery to Arbitrary Member Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"70fa060f-11eb-4b51-b985-59421f44414e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/70fa060f-11eb-4b51-b985-59421f44414e?source=api-prod","cve":"CVE-2022-0328","affectedVersions":"<4.0.9","severity":"high"},{"advisoryId":"WPSECADV/WF/7772c78e-3134-4855-ac4e-3520c584c2e7/simple-membership","title":"Simple Membership <= 4.2.1 - Authenticated (Contributor+) Cross Site Scripting via shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"7772c78e-3134-4855-ac4e-3520c584c2e7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7772c78e-3134-4855-ac4e-3520c584c2e7?source=api-prod","cve":"CVE-2022-4469","affectedVersions":"<=4.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/792282d1-5f43-4511-becc-9c5bb5ae513a/simple-membership","title":"Simple Membership <= 4.1.2 - Membership Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-07-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"792282d1-5f43-4511-becc-9c5bb5ae513a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/792282d1-5f43-4511-becc-9c5bb5ae513a?source=api-prod","cve":"CVE-2022-2273","affectedVersions":"<=4.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/7aa6da4d-7221-4878-8532-5372227f906a/simple-membership","title":"Simple Membership <= 4.0.9 - Cross-Site Request Forgery to Arbitrary Transaction Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7aa6da4d-7221-4878-8532-5372227f906a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7aa6da4d-7221-4878-8532-5372227f906a?source=api-prod","cve":"CVE-2022-0681","affectedVersions":"<4.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/7cff7dc5-23e1-424c-923b-68eef49dec6f/simple-membership","title":"Simple Membership <= 4.3.4 - Privilege escalation via Registration\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7cff7dc5-23e1-424c-923b-68eef49dec6f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7cff7dc5-23e1-424c-923b-68eef49dec6f?source=api-prod","cve":"CVE-2023-41957","affectedVersions":"<=4.3.4","severity":"high"},{"advisoryId":"WPSECADV/WF/839957ea-5186-4cce-971d-57eed84639d5/simple-membership","title":"Simple Membership <= 3.8.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-07-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"839957ea-5186-4cce-971d-57eed84639d5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/839957ea-5186-4cce-971d-57eed84639d5?source=api-prod","cve":"CVE-2019-14328","affectedVersions":"<3.8.5","severity":"high"},{"advisoryId":"WPSECADV/WF/8a6ca886-de4c-4d45-a934-3e90378e7eb3/simple-membership","title":"Simple Membership <= 4.4.2 - Unauthenticated Stored Self-Based Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"8a6ca886-de4c-4d45-a934-3e90378e7eb3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8a6ca886-de4c-4d45-a934-3e90378e7eb3?source=api-prod","cve":"CVE-2024-1985","affectedVersions":"<=4.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/95c2038f-c4f9-472a-92ab-59ee395bda3d/simple-membership","title":"Simple Membership < 3.2.9 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-07-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"95c2038f-c4f9-472a-92ab-59ee395bda3d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/95c2038f-c4f9-472a-92ab-59ee395bda3d?source=api-prod","affectedVersions":"<3.2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/b0086de8-448f-452f-89d1-84b77b2e25a8/simple-membership","title":"Simple Membership <= 4.4.1 - Open Redirect\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"b0086de8-448f-452f-89d1-84b77b2e25a8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b0086de8-448f-452f-89d1-84b77b2e25a8?source=api-prod","cve":"CVE-2024-22308","affectedVersions":"<=4.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/b4b7adcf-c58b-4019-89ff-a69ebf8262bc/simple-membership","title":"Simple Membership <= 4.5.3 - Unauthenticated Open Redirect\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"b4b7adcf-c58b-4019-89ff-a69ebf8262bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b4b7adcf-c58b-4019-89ff-a69ebf8262bc?source=api-prod","cve":"CVE-2024-49682","affectedVersions":"<=4.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/bd9336ba-0a91-4fe5-b564-1adf739f4193/simple-membership","title":"Simple Membership <= 4.7.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"bd9336ba-0a91-4fe5-b564-1adf739f4193"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bd9336ba-0a91-4fe5-b564-1adf739f4193?source=api-prod","cve":"CVE-2026-34886","affectedVersions":"<=4.7.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/c1558b08-a33b-4cf2-bacb-c88065f513cc/simple-membership","title":"Simple Membership <= 4.5.5 - Exposure of Private Personal Information to an Unauthorized Actor\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"c1558b08-a33b-4cf2-bacb-c88065f513cc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c1558b08-a33b-4cf2-bacb-c88065f513cc?source=api-prod","cve":"CVE-2024-11088","affectedVersions":"<=4.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/cfd3f0e3-e73e-4ec2-ac67-da1cc15aa217/simple-membership","title":"Simple Membership <= 3.5.6 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"cfd3f0e3-e73e-4ec2-ac67-da1cc15aa217"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cfd3f0e3-e73e-4ec2-ac67-da1cc15aa217?source=api-prod","cve":"CVE-2017-18499","affectedVersions":"<3.5.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/dc322548-ffc9-4246-9835-fcc5705cef3f/simple-membership","title":"Simple Membership <= 4.1.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-05-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"dc322548-ffc9-4246-9835-fcc5705cef3f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dc322548-ffc9-4246-9835-fcc5705cef3f?source=api-prod","cve":"CVE-2022-1724","affectedVersions":"<=4.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e4b10172-7e54-4ff8-9fbb-41d160ce49e4/simple-membership","title":"Simple Membership <= 4.3.5 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"e4b10172-7e54-4ff8-9fbb-41d160ce49e4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e4b10172-7e54-4ff8-9fbb-41d160ce49e4?source=api-prod","cve":"CVE-2023-4719","affectedVersions":"<=4.3.5","severity":"high"},{"advisoryId":"WPSECADV/WF/e53bb240-8784-4d34-8d3f-4a7af917f3f4/simple-membership","title":"Simple Membership <= 4.3.4 - Account Takeover via Password Reset\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"e53bb240-8784-4d34-8d3f-4a7af917f3f4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e53bb240-8784-4d34-8d3f-4a7af917f3f4?source=api-prod","cve":"CVE-2023-41956","affectedVersions":"<=4.3.4","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/1664fef3-6416-4678-9ee7-bed2184d7490/simple-membership","title":"Simple Membership <= 4.0.3 - Authenticated (Admin+) SQL Injections\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"1664fef3-6416-4678-9ee7-bed2184d7490"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1664fef3-6416-4678-9ee7-bed2184d7490?source=api-prod","affectedVersions":"<=4.0.3","severity":"high"},{"advisoryId":"WPSECADV/WF/18fe9769-3681-4a5e-866a-640b4cc76199/simple-membership","title":"Simple Membership <= 4.3.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"18fe9769-3681-4a5e-866a-640b4cc76199"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/18fe9769-3681-4a5e-866a-640b4cc76199?source=api-prod","cve":"CVE-2023-50376","affectedVersions":"<4.3.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/284eafb9-94bc-4478-abff-f7dafd510a1d/simple-membership","title":"Simple Membership <= 4.1.2 - Membership Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-07-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"284eafb9-94bc-4478-abff-f7dafd510a1d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/284eafb9-94bc-4478-abff-f7dafd510a1d?source=api-prod","cve":"CVE-2022-2317","affectedVersions":"<=4.1.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/366165fe-93e5-49ab-b2e5-1de624f22286/simple-membership","title":"Simple Membership <= 4.3.8 - Reflected Cross-Site Scripting Vulnerability via environment_mode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"366165fe-93e5-49ab-b2e5-1de624f22286"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/366165fe-93e5-49ab-b2e5-1de624f22286?source=api-prod","cve":"CVE-2023-6882","affectedVersions":"<=4.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/45bb4a6f-560f-4dc8-9005-1e4c5727d56f/simple-membership","title":"Simple Membership <= 4.6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"45bb4a6f-560f-4dc8-9005-1e4c5727d56f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/45bb4a6f-560f-4dc8-9005-1e4c5727d56f?source=api-prod","cve":"CVE-2025-49333","affectedVersions":"<=4.6.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/4e4df9a6-8f7d-428b-a596-0751ca047169/simple-membership","title":"Simple Membership <= 4.7.0 - Unauthenticated Improper Handling of Missing Values\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"4e4df9a6-8f7d-428b-a596-0751ca047169"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4e4df9a6-8f7d-428b-a596-0751ca047169?source=api-prod","cve":"CVE-2026-1461","affectedVersions":"<=4.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/56fdbf80-8ea2-412a-b166-b7c27de88e70/simple-membership","title":"Simple Membership <= 4.4.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"56fdbf80-8ea2-412a-b166-b7c27de88e70"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/56fdbf80-8ea2-412a-b166-b7c27de88e70?source=api-prod","cve":"CVE-2024-4383","affectedVersions":"<=4.4.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/63779ab7-ba8b-459d-beb3-a32faf8f4394/simple-membership","title":"Simple Membership <= 4.4.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"63779ab7-ba8b-459d-beb3-a32faf8f4394"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63779ab7-ba8b-459d-beb3-a32faf8f4394?source=api-prod","cve":"CVE-2024-3730","affectedVersions":"<=4.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/6b7ce040-32b7-4440-be4f-d33fe9c49e51/simple-membership","title":"Simple Membership <= 4.6.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"6b7ce040-32b7-4440-be4f-d33fe9c49e51"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6b7ce040-32b7-4440-be4f-d33fe9c49e51?source=api-prod","cve":"CVE-2026-25308","affectedVersions":"<=4.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/6f721aa1-d12f-4829-8e82-61f9af6a3519/simple-membership","title":"Simple Membership <= 3.3.2 - Multiple Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-09-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f721aa1-d12f-4829-8e82-61f9af6a3519"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f721aa1-d12f-4829-8e82-61f9af6a3519?source=api-prod","cve":"CVE-2016-10884","affectedVersions":"<=3.3.2","severity":"high"},{"advisoryId":"WPSECADV/WF/70fa060f-11eb-4b51-b985-59421f44414e/simple-membership","title":"Simple Membership <= 4.0.8 - Cross-Site Request Forgery to Arbitrary Member Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"70fa060f-11eb-4b51-b985-59421f44414e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/70fa060f-11eb-4b51-b985-59421f44414e?source=api-prod","cve":"CVE-2022-0328","affectedVersions":"<4.0.9","severity":"high"},{"advisoryId":"WPSECADV/WF/7772c78e-3134-4855-ac4e-3520c584c2e7/simple-membership","title":"Simple Membership <= 4.2.1 - Authenticated (Contributor+) Cross Site Scripting via shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"7772c78e-3134-4855-ac4e-3520c584c2e7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7772c78e-3134-4855-ac4e-3520c584c2e7?source=api-prod","cve":"CVE-2022-4469","affectedVersions":"<=4.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/792282d1-5f43-4511-becc-9c5bb5ae513a/simple-membership","title":"Simple Membership <= 4.1.2 - Membership Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-07-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"792282d1-5f43-4511-becc-9c5bb5ae513a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/792282d1-5f43-4511-becc-9c5bb5ae513a?source=api-prod","cve":"CVE-2022-2273","affectedVersions":"<=4.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/7aa6da4d-7221-4878-8532-5372227f906a/simple-membership","title":"Simple Membership <= 4.0.9 - Cross-Site Request Forgery to Arbitrary Transaction Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7aa6da4d-7221-4878-8532-5372227f906a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7aa6da4d-7221-4878-8532-5372227f906a?source=api-prod","cve":"CVE-2022-0681","affectedVersions":"<4.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/7cff7dc5-23e1-424c-923b-68eef49dec6f/simple-membership","title":"Simple Membership <= 4.3.4 - Privilege escalation via Registration\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7cff7dc5-23e1-424c-923b-68eef49dec6f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7cff7dc5-23e1-424c-923b-68eef49dec6f?source=api-prod","cve":"CVE-2023-41957","affectedVersions":"<=4.3.4","severity":"high"},{"advisoryId":"WPSECADV/WF/839957ea-5186-4cce-971d-57eed84639d5/simple-membership","title":"Simple Membership <= 3.8.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-07-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"839957ea-5186-4cce-971d-57eed84639d5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/839957ea-5186-4cce-971d-57eed84639d5?source=api-prod","cve":"CVE-2019-14328","affectedVersions":"<3.8.5","severity":"high"},{"advisoryId":"WPSECADV/WF/8a6ca886-de4c-4d45-a934-3e90378e7eb3/simple-membership","title":"Simple Membership <= 4.4.2 - Unauthenticated Stored Self-Based Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"8a6ca886-de4c-4d45-a934-3e90378e7eb3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8a6ca886-de4c-4d45-a934-3e90378e7eb3?source=api-prod","cve":"CVE-2024-1985","affectedVersions":"<=4.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/95c2038f-c4f9-472a-92ab-59ee395bda3d/simple-membership","title":"Simple Membership < 3.2.9 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-07-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"95c2038f-c4f9-472a-92ab-59ee395bda3d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/95c2038f-c4f9-472a-92ab-59ee395bda3d?source=api-prod","affectedVersions":"<3.2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/b0086de8-448f-452f-89d1-84b77b2e25a8/simple-membership","title":"Simple Membership <= 4.4.1 - Open Redirect\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"b0086de8-448f-452f-89d1-84b77b2e25a8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b0086de8-448f-452f-89d1-84b77b2e25a8?source=api-prod","cve":"CVE-2024-22308","affectedVersions":"<=4.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/b4b7adcf-c58b-4019-89ff-a69ebf8262bc/simple-membership","title":"Simple Membership <= 4.5.3 - Unauthenticated Open Redirect\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"b4b7adcf-c58b-4019-89ff-a69ebf8262bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b4b7adcf-c58b-4019-89ff-a69ebf8262bc?source=api-prod","cve":"CVE-2024-49682","affectedVersions":"<=4.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/bd9336ba-0a91-4fe5-b564-1adf739f4193/simple-membership","title":"Simple Membership <= 4.7.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"bd9336ba-0a91-4fe5-b564-1adf739f4193"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bd9336ba-0a91-4fe5-b564-1adf739f4193?source=api-prod","cve":"CVE-2026-34886","affectedVersions":"<=4.7.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/c1558b08-a33b-4cf2-bacb-c88065f513cc/simple-membership","title":"Simple Membership <= 4.5.5 - Exposure of Private Personal Information to an Unauthorized Actor\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"c1558b08-a33b-4cf2-bacb-c88065f513cc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c1558b08-a33b-4cf2-bacb-c88065f513cc?source=api-prod","cve":"CVE-2024-11088","affectedVersions":"<=4.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/cfd3f0e3-e73e-4ec2-ac67-da1cc15aa217/simple-membership","title":"Simple Membership <= 3.5.6 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"cfd3f0e3-e73e-4ec2-ac67-da1cc15aa217"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cfd3f0e3-e73e-4ec2-ac67-da1cc15aa217?source=api-prod","cve":"CVE-2017-18499","affectedVersions":"<3.5.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/dc322548-ffc9-4246-9835-fcc5705cef3f/simple-membership","title":"Simple Membership <= 4.1.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-05-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"dc322548-ffc9-4246-9835-fcc5705cef3f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dc322548-ffc9-4246-9835-fcc5705cef3f?source=api-prod","cve":"CVE-2022-1724","affectedVersions":"<=4.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e4b10172-7e54-4ff8-9fbb-41d160ce49e4/simple-membership","title":"Simple Membership <= 4.3.5 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"e4b10172-7e54-4ff8-9fbb-41d160ce49e4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e4b10172-7e54-4ff8-9fbb-41d160ce49e4?source=api-prod","cve":"CVE-2023-4719","affectedVersions":"<=4.3.5","severity":"high"},{"advisoryId":"WPSECADV/WF/e53bb240-8784-4d34-8d3f-4a7af917f3f4/simple-membership","title":"Simple Membership <= 4.3.4 - Account Takeover via Password Reset\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"e53bb240-8784-4d34-8d3f-4a7af917f3f4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e53bb240-8784-4d34-8d3f-4a7af917f3f4?source=api-prod","cve":"CVE-2023-41956","affectedVersions":"<=4.3.4","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_73696d706c652d6f776c2d73686f7274636f646573811c9dc5_gen.json b/internal/data/assets/plugin_73696d706c652d6f776c2d73686f7274636f646573811c9dc5_gen.json new file mode 100644 index 00000000..f6a5db16 --- /dev/null +++ b/internal/data/assets/plugin_73696d706c652d6f776c2d73686f7274636f646573811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/e33a2f27-20c2-4963-9558-1eead0515690/simple-owl-shortcodes","title":"Simple Owl Shortcodes <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num' Shortcode Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:06:27","sources":[{"name":"Wordfence","remoteId":"e33a2f27-20c2-4963-9558-1eead0515690"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e33a2f27-20c2-4963-9558-1eead0515690?source=api-prod","cve":"CVE-2026-6255","affectedVersions":"<=2.1.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_736d6172742d6175746f2d75706c6f61642d696d61676573811c9dc5_gen.json b/internal/data/assets/plugin_736d6172742d6175746f2d75706c6f61642d696d61676573811c9dc5_gen.json index 4a0a5f92..45060cf2 100644 --- a/internal/data/assets/plugin_736d6172742d6175746f2d75706c6f61642d696d61676573811c9dc5_gen.json +++ b/internal/data/assets/plugin_736d6172742d6175746f2d75706c6f61642d696d61676573811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/86dab8e6-b9fd-45ca-bdd1-8665f3bb75f2/smart-auto-upload-images","title":"Smart Auto Upload Images <= 1.2.0 - Authenticated (Contributor+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"86dab8e6-b9fd-45ca-bdd1-8665f3bb75f2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/86dab8e6-b9fd-45ca-bdd1-8665f3bb75f2?source=api-prod","cve":"CVE-2025-12161","affectedVersions":"<=1.2.0","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/124bf96a-9ace-428a-897b-24243d5cb260/smart-auto-upload-images","title":"Smart Auto Upload Images – Import External Images <= 1.2.2 - Authenticated (Contributor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"124bf96a-9ace-428a-897b-24243d5cb260"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/124bf96a-9ace-428a-897b-24243d5cb260?source=api-prod","cve":"CVE-2026-23803","affectedVersions":"<=1.2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/86dab8e6-b9fd-45ca-bdd1-8665f3bb75f2/smart-auto-upload-images","title":"Smart Auto Upload Images <= 1.2.0 - Authenticated (Contributor+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"86dab8e6-b9fd-45ca-bdd1-8665f3bb75f2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/86dab8e6-b9fd-45ca-bdd1-8665f3bb75f2?source=api-prod","cve":"CVE-2025-12161","affectedVersions":"<=1.2.0","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_736d6172742d776973686c6973742d666f722d6d6f72652d636f6e766572742d7072656d69756d811c9dc5_gen.json b/internal/data/assets/plugin_736d6172742d776973686c6973742d666f722d6d6f72652d636f6e766572742d7072656d69756d811c9dc5_gen.json new file mode 100644 index 00000000..e044aac3 --- /dev/null +++ b/internal/data/assets/plugin_736d6172742d776973686c6973742d666f722d6d6f72652d636f6e766572742d7072656d69756d811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/fe887475-f7e8-4fda-a793-bc6f37b70f3e/smart-wishlist-for-more-convert-premium","title":"MoreConvert Pro <= 1.9.14 - Authentication Bypass via Waitlist Guest Verification Token Reuse\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 13:18:12","sources":[{"name":"Wordfence","remoteId":"fe887475-f7e8-4fda-a793-bc6f37b70f3e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fe887475-f7e8-4fda-a793-bc6f37b70f3e?source=api-prod","cve":"CVE-2026-5722","affectedVersions":"<=1.9.14","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7375627363726962652d746f2d636f6d6d656e74732d72656c6f61646564811c9dc5_gen.json b/internal/data/assets/plugin_7375627363726962652d746f2d636f6d6d656e74732d72656c6f61646564811c9dc5_gen.json index 5194c9f4..0d6a5c08 100644 --- a/internal/data/assets/plugin_7375627363726962652d746f2d636f6d6d656e74732d72656c6f61646564811c9dc5_gen.json +++ b/internal/data/assets/plugin_7375627363726962652d746f2d636f6d6d656e74732d72656c6f61646564811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/014dcf08-1968-4a3f-a772-2248e65dfb07/subscribe-to-comments-reloaded","title":"Subscribe To Comments Reloaded <= 140129 - Cross-Site Request Forgery to Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"014dcf08-1968-4a3f-a772-2248e65dfb07"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/014dcf08-1968-4a3f-a772-2248e65dfb07?source=api-prod","cve":"CVE-2014-2274","affectedVersions":"<=140129","severity":"high"},{"advisoryId":"WPSECADV/WF/5be2c2e7-f982-410d-a5dc-f3ef976dff02/subscribe-to-comments-reloaded","title":"Subscribe To Comments Reloaded <= 211130 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-04-29 12:07:00","sources":[{"name":"Wordfence","remoteId":"5be2c2e7-f982-410d-a5dc-f3ef976dff02"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5be2c2e7-f982-410d-a5dc-f3ef976dff02?source=api-prod","cve":"CVE-2022-29414","affectedVersions":"<=211130","severity":"high"},{"advisoryId":"WPSECADV/WF/c64956c3-b6f5-419e-82f3-3c9e90e1d677/subscribe-to-comments-reloaded","title":"Subscribe To Comments Reloaded <= 220725 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"c64956c3-b6f5-419e-82f3-3c9e90e1d677"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c64956c3-b6f5-419e-82f3-3c9e90e1d677?source=api-prod","cve":"CVE-2024-31249","affectedVersions":"<=220725","severity":"medium"},{"advisoryId":"WPSECADV/WF/ce03e98d-7c29-405f-81bc-4a1114d9889d/subscribe-to-comments-reloaded","title":"Subscribe To Comments Reloaded < 150820 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-08-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"ce03e98d-7c29-405f-81bc-4a1114d9889d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ce03e98d-7c29-405f-81bc-4a1114d9889d?source=api-prod","affectedVersions":"<150820","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/014dcf08-1968-4a3f-a772-2248e65dfb07/subscribe-to-comments-reloaded","title":"Subscribe To Comments Reloaded <= 140129 - Cross-Site Request Forgery to Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"014dcf08-1968-4a3f-a772-2248e65dfb07"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/014dcf08-1968-4a3f-a772-2248e65dfb07?source=api-prod","cve":"CVE-2014-2274","affectedVersions":"<=140129","severity":"high"},{"advisoryId":"WPSECADV/WF/5be2c2e7-f982-410d-a5dc-f3ef976dff02/subscribe-to-comments-reloaded","title":"Subscribe To Comments Reloaded <= 211130 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-04-29 12:07:00","sources":[{"name":"Wordfence","remoteId":"5be2c2e7-f982-410d-a5dc-f3ef976dff02"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5be2c2e7-f982-410d-a5dc-f3ef976dff02?source=api-prod","cve":"CVE-2022-29414","affectedVersions":"<=211130","severity":"high"},{"advisoryId":"WPSECADV/WF/91f9235e-f578-475f-92c3-34062d6d1e3d/subscribe-to-comments-reloaded","title":"Subscribe To Comments Reloaded <= 240119 - Improper Authorization to Unauthenticated Arbitrary Subscription Management\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:11:52","sources":[{"name":"Wordfence","remoteId":"91f9235e-f578-475f-92c3-34062d6d1e3d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91f9235e-f578-475f-92c3-34062d6d1e3d?source=api-prod","cve":"CVE-2026-4409","affectedVersions":"<=240119","severity":"medium"},{"advisoryId":"WPSECADV/WF/c64956c3-b6f5-419e-82f3-3c9e90e1d677/subscribe-to-comments-reloaded","title":"Subscribe To Comments Reloaded <= 220725 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"c64956c3-b6f5-419e-82f3-3c9e90e1d677"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c64956c3-b6f5-419e-82f3-3c9e90e1d677?source=api-prod","cve":"CVE-2024-31249","affectedVersions":"<=220725","severity":"medium"},{"advisoryId":"WPSECADV/WF/ce03e98d-7c29-405f-81bc-4a1114d9889d/subscribe-to-comments-reloaded","title":"Subscribe To Comments Reloaded < 150820 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-08-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"ce03e98d-7c29-405f-81bc-4a1114d9889d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ce03e98d-7c29-405f-81bc-4a1114d9889d?source=api-prod","affectedVersions":"<150820","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_737570706f727463616e6479811c9dc5_gen.json b/internal/data/assets/plugin_737570706f727463616e6479811c9dc5_gen.json index ed33fbf8..730b2289 100644 --- a/internal/data/assets/plugin_737570706f727463616e6479811c9dc5_gen.json +++ b/internal/data/assets/plugin_737570706f727463616e6479811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/07c0b4c5-d76e-4bdc-87d1-3144a1466c77/supportcandy","title":"SupportCandy <= 3.1.3 - Sensitive Data Exposure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"07c0b4c5-d76e-4bdc-87d1-3144a1466c77"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/07c0b4c5-d76e-4bdc-87d1-3144a1466c77?source=api-prod","affectedVersions":"<=3.1.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/13f87248-cc0b-4351-b79d-6efc5190b021/supportcandy","title":"SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.0 - Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-06 20:26:26","sources":[{"name":"Wordfence","remoteId":"13f87248-cc0b-4351-b79d-6efc5190b021"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/13f87248-cc0b-4351-b79d-6efc5190b021?source=api-prod","cve":"CVE-2024-13552","affectedVersions":"<=3.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/1a10af61-6451-4dda-aeda-ba8fa44bee35/supportcandy","title":"SupportCandy – Helpdesk & Support Ticket System <= 2.2.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"1a10af61-6451-4dda-aeda-ba8fa44bee35"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1a10af61-6451-4dda-aeda-ba8fa44bee35?source=api-prod","cve":"CVE-2021-24879","affectedVersions":"<2.2.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/2b11670a-f6e4-4555-ab76-4223f0194517/supportcandy","title":"SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.7 - Authentication Bypass to Support Session Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"2b11670a-f6e4-4555-ab76-4223f0194517"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b11670a-f6e4-4555-ab76-4223f0194517?source=api-prod","cve":"CVE-2025-10658","affectedVersions":"<=3.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/35fb04aa-5899-4797-9ea1-24e7a98ad8d3/supportcandy","title":"SupportCandy <= 2.2.6 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"35fb04aa-5899-4797-9ea1-24e7a98ad8d3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/35fb04aa-5899-4797-9ea1-24e7a98ad8d3?source=api-prod","cve":"CVE-2021-24878","affectedVersions":"<=2.2.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/5ca1c55a-cd4e-429a-ab74-dd1bad1a65f5/supportcandy","title":"SupportCandy <= 3.1.4 - Unauthenticated SQL Injection via parse_user_filters\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"5ca1c55a-cd4e-429a-ab74-dd1bad1a65f5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ca1c55a-cd4e-429a-ab74-dd1bad1a65f5?source=api-prod","cve":"CVE-2023-1730","affectedVersions":"<=3.1.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/653ab9cb-7084-47e4-b5e3-6788fa5d7496/supportcandy","title":"SupportCandy <= 2.2.4 - Unauthenticated Arbitrary Ticket Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"653ab9cb-7084-47e4-b5e3-6788fa5d7496"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/653ab9cb-7084-47e4-b5e3-6788fa5d7496?source=api-prod","cve":"CVE-2021-24839","affectedVersions":"<=2.2.4","severity":"high"},{"advisoryId":"WPSECADV/WF/663c54f4-4ca5-4916-b2a5-de3cabe77f38/supportcandy","title":"SupportCandy <= 3.2.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"663c54f4-4ca5-4916-b2a5-de3cabe77f38"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/663c54f4-4ca5-4916-b2a5-de3cabe77f38?source=api-prod","cve":"CVE-2024-27991","affectedVersions":"<=3.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/75f01eb4-5d53-441d-9bee-e97857dadaf9/supportcandy","title":"SupportCandy <= 3.1.6 - Authenticated (Admin+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"75f01eb4-5d53-441d-9bee-e97857dadaf9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/75f01eb4-5d53-441d-9bee-e97857dadaf9?source=api-prod","cve":"CVE-2023-2805","affectedVersions":"<=3.1.6","severity":"high"},{"advisoryId":"WPSECADV/WF/89df3005-0967-474f-8a4e-3b23273dd1a2/supportcandy","title":"SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"89df3005-0967-474f-8a4e-3b23273dd1a2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/89df3005-0967-474f-8a4e-3b23273dd1a2?source=api-prod","cve":"CVE-2026-1251","affectedVersions":"<=3.4.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/9e1fa691-3934-4e15-b339-e679976d6d5c/supportcandy","title":"SupportCandy <= 2.2.6 - Cross-Site Request Forgery to Arbitrary Ticket Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"9e1fa691-3934-4e15-b339-e679976d6d5c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9e1fa691-3934-4e15-b339-e679976d6d5c?source=api-prod","cve":"CVE-2021-24843","affectedVersions":"<2.2.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/9fc6d947-4b6e-4dcb-9f20-02e39b4e730e/supportcandy","title":"SupportCandy <= 2.2.6 - Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"9fc6d947-4b6e-4dcb-9f20-02e39b4e730e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9fc6d947-4b6e-4dcb-9f20-02e39b4e730e?source=api-prod","cve":"CVE-2021-24880","affectedVersions":"<2.2.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/a7856d0f-bc7d-436c-968c-631fd6a686ab/supportcandy","title":"SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) SQL Injection via Number Field Filter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"a7856d0f-bc7d-436c-968c-631fd6a686ab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a7856d0f-bc7d-436c-968c-631fd6a686ab?source=api-prod","cve":"CVE-2026-0683","affectedVersions":"<=3.4.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/c1d2b6bd-a75a-4a07-b2f0-8ec206d41211/supportcandy","title":"SupportCandy <= 3.1.6 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"c1d2b6bd-a75a-4a07-b2f0-8ec206d41211"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c1d2b6bd-a75a-4a07-b2f0-8ec206d41211?source=api-prod","cve":"CVE-2023-2719","affectedVersions":"<=3.1.6","severity":"high"},{"advisoryId":"WPSECADV/WF/caa73e10-fc2d-4a51-a2fb-6f13817e7c74/supportcandy","title":"SupportCandy <= 3.4.1 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"caa73e10-fc2d-4a51-a2fb-6f13817e7c74"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/caa73e10-fc2d-4a51-a2fb-6f13817e7c74?source=api-prod","cve":"CVE-2025-67598","affectedVersions":"<=3.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/dcea4ecf-e690-4d1f-beab-fbb30c5bb52e/supportcandy","title":"SupportCandy – Helpdesk & Support Ticket System <= 2.0.0 - Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-04-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"dcea4ecf-e690-4d1f-beab-fbb30c5bb52e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dcea4ecf-e690-4d1f-beab-fbb30c5bb52e?source=api-prod","cve":"CVE-2019-11223","affectedVersions":"<2.0.1","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/07c0b4c5-d76e-4bdc-87d1-3144a1466c77/supportcandy","title":"SupportCandy <= 3.1.3 - Sensitive Data Exposure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"07c0b4c5-d76e-4bdc-87d1-3144a1466c77"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/07c0b4c5-d76e-4bdc-87d1-3144a1466c77?source=api-prod","affectedVersions":"<=3.1.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/13f87248-cc0b-4351-b79d-6efc5190b021/supportcandy","title":"SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.0 - Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-06 20:26:26","sources":[{"name":"Wordfence","remoteId":"13f87248-cc0b-4351-b79d-6efc5190b021"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/13f87248-cc0b-4351-b79d-6efc5190b021?source=api-prod","cve":"CVE-2024-13552","affectedVersions":"<=3.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/1a10af61-6451-4dda-aeda-ba8fa44bee35/supportcandy","title":"SupportCandy – Helpdesk & Support Ticket System <= 2.2.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"1a10af61-6451-4dda-aeda-ba8fa44bee35"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1a10af61-6451-4dda-aeda-ba8fa44bee35?source=api-prod","cve":"CVE-2021-24879","affectedVersions":"<2.2.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/2b11670a-f6e4-4555-ab76-4223f0194517/supportcandy","title":"SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.7 - Authentication Bypass to Support Session Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"2b11670a-f6e4-4555-ab76-4223f0194517"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b11670a-f6e4-4555-ab76-4223f0194517?source=api-prod","cve":"CVE-2025-10658","affectedVersions":"<=3.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/35fb04aa-5899-4797-9ea1-24e7a98ad8d3/supportcandy","title":"SupportCandy <= 2.2.6 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"35fb04aa-5899-4797-9ea1-24e7a98ad8d3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/35fb04aa-5899-4797-9ea1-24e7a98ad8d3?source=api-prod","cve":"CVE-2021-24878","affectedVersions":"<=2.2.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/5ca1c55a-cd4e-429a-ab74-dd1bad1a65f5/supportcandy","title":"SupportCandy <= 3.1.4 - Unauthenticated SQL Injection via parse_user_filters\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"5ca1c55a-cd4e-429a-ab74-dd1bad1a65f5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ca1c55a-cd4e-429a-ab74-dd1bad1a65f5?source=api-prod","cve":"CVE-2023-1730","affectedVersions":"<=3.1.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/653ab9cb-7084-47e4-b5e3-6788fa5d7496/supportcandy","title":"SupportCandy <= 2.2.4 - Unauthenticated Arbitrary Ticket Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"653ab9cb-7084-47e4-b5e3-6788fa5d7496"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/653ab9cb-7084-47e4-b5e3-6788fa5d7496?source=api-prod","cve":"CVE-2021-24839","affectedVersions":"<=2.2.4","severity":"high"},{"advisoryId":"WPSECADV/WF/663c54f4-4ca5-4916-b2a5-de3cabe77f38/supportcandy","title":"SupportCandy <= 3.2.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"663c54f4-4ca5-4916-b2a5-de3cabe77f38"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/663c54f4-4ca5-4916-b2a5-de3cabe77f38?source=api-prod","cve":"CVE-2024-27991","affectedVersions":"<=3.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/75f01eb4-5d53-441d-9bee-e97857dadaf9/supportcandy","title":"SupportCandy <= 3.1.6 - Authenticated (Admin+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"75f01eb4-5d53-441d-9bee-e97857dadaf9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/75f01eb4-5d53-441d-9bee-e97857dadaf9?source=api-prod","cve":"CVE-2023-2805","affectedVersions":"<=3.1.6","severity":"high"},{"advisoryId":"WPSECADV/WF/89df3005-0967-474f-8a4e-3b23273dd1a2/supportcandy","title":"SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"89df3005-0967-474f-8a4e-3b23273dd1a2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/89df3005-0967-474f-8a4e-3b23273dd1a2?source=api-prod","cve":"CVE-2026-1251","affectedVersions":"<=3.4.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/9e1fa691-3934-4e15-b339-e679976d6d5c/supportcandy","title":"SupportCandy <= 2.2.6 - Cross-Site Request Forgery to Arbitrary Ticket Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"9e1fa691-3934-4e15-b339-e679976d6d5c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9e1fa691-3934-4e15-b339-e679976d6d5c?source=api-prod","cve":"CVE-2021-24843","affectedVersions":"<2.2.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/9fc6d947-4b6e-4dcb-9f20-02e39b4e730e/supportcandy","title":"SupportCandy <= 2.2.6 - Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"9fc6d947-4b6e-4dcb-9f20-02e39b4e730e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9fc6d947-4b6e-4dcb-9f20-02e39b4e730e?source=api-prod","cve":"CVE-2021-24880","affectedVersions":"<2.2.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/a7856d0f-bc7d-436c-968c-631fd6a686ab/supportcandy","title":"SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) SQL Injection via Number Field Filter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"a7856d0f-bc7d-436c-968c-631fd6a686ab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a7856d0f-bc7d-436c-968c-631fd6a686ab?source=api-prod","cve":"CVE-2026-0683","affectedVersions":"<=3.4.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/c1d2b6bd-a75a-4a07-b2f0-8ec206d41211/supportcandy","title":"SupportCandy <= 3.1.6 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"c1d2b6bd-a75a-4a07-b2f0-8ec206d41211"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c1d2b6bd-a75a-4a07-b2f0-8ec206d41211?source=api-prod","cve":"CVE-2023-2719","affectedVersions":"<=3.1.6","severity":"high"},{"advisoryId":"WPSECADV/WF/caa73e10-fc2d-4a51-a2fb-6f13817e7c74/supportcandy","title":"SupportCandy <= 3.4.1 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"caa73e10-fc2d-4a51-a2fb-6f13817e7c74"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/caa73e10-fc2d-4a51-a2fb-6f13817e7c74?source=api-prod","cve":"CVE-2025-67598","affectedVersions":"<=3.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/d0064a76-3ccc-4dd6-b312-d19abb3944fa/supportcandy","title":"SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"d0064a76-3ccc-4dd6-b312-d19abb3944fa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d0064a76-3ccc-4dd6-b312-d19abb3944fa?source=api-prod","cve":"CVE-2026-25321","affectedVersions":"<=3.4.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/dcea4ecf-e690-4d1f-beab-fbb30c5bb52e/supportcandy","title":"SupportCandy – Helpdesk & Support Ticket System <= 2.0.0 - Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-04-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"dcea4ecf-e690-4d1f-beab-fbb30c5bb52e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dcea4ecf-e690-4d1f-beab-fbb30c5bb52e?source=api-prod","cve":"CVE-2019-11223","affectedVersions":"<2.0.1","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_73763130302d636f6d70616e696f6e811c9dc5_gen.json b/internal/data/assets/plugin_73763130302d636f6d70616e696f6e811c9dc5_gen.json index b515afbd..8c153055 100644 --- a/internal/data/assets/plugin_73763130302d636f6d70616e696f6e811c9dc5_gen.json +++ b/internal/data/assets/plugin_73763130302d636f6d70616e696f6e811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/5253fe2b-040b-417c-b257-0cb59ee5aa6e/sv100-companion","title":"Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"5253fe2b-040b-417c-b257-0cb59ee5aa6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5253fe2b-040b-417c-b257-0cb59ee5aa6e?source=api-prod","cve":"CVE-2023-33999","affectedVersions":"<=1.9.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/c244eb33-acaf-460b-ae1d-6688b21cc60f/sv100-companion","title":"SV100 Companion <= 2.0.02 - Missing Authorization to Unuathenticated Arbitrary Options Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-05 19:32:55","sources":[{"name":"Wordfence","remoteId":"c244eb33-acaf-460b-ae1d-6688b21cc60f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c244eb33-acaf-460b-ae1d-6688b21cc60f?source=api-prod","cve":"CVE-2024-12155","affectedVersions":"<=2.0.02","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/5253fe2b-040b-417c-b257-0cb59ee5aa6e/sv100-companion","title":"Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"5253fe2b-040b-417c-b257-0cb59ee5aa6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5253fe2b-040b-417c-b257-0cb59ee5aa6e?source=api-prod","cve":"CVE-2023-33999","affectedVersions":"<=1.9.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/c244eb33-acaf-460b-ae1d-6688b21cc60f/sv100-companion","title":"SV100 Companion <= 2.0.02 - Missing Authorization to Unuathenticated Arbitrary Options Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-05 19:32:55","sources":[{"name":"Wordfence","remoteId":"c244eb33-acaf-460b-ae1d-6688b21cc60f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c244eb33-acaf-460b-ae1d-6688b21cc60f?source=api-prod","cve":"CVE-2024-12155","affectedVersions":"<=2.0.02","severity":"critical"},{"advisoryId":"WPSECADV/WF/f52a9da3-f8bb-4e52-9b4c-b8e5bbf077cb/sv100-companion","title":"SV100 Companion <= 2.0.02 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"f52a9da3-f8bb-4e52-9b4c-b8e5bbf077cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f52a9da3-f8bb-4e52-9b4c-b8e5bbf077cb?source=api-prod","cve":"CVE-2024-54229","affectedVersions":"<=2.0.02","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_746f702d7461626c652d6f662d636f6e74656e7473811c9dc5_gen.json b/internal/data/assets/plugin_746f702d7461626c652d6f662d636f6e74656e7473811c9dc5_gen.json index 24d96182..dd5fa207 100644 --- a/internal/data/assets/plugin_746f702d7461626c652d6f662d636f6e74656e7473811c9dc5_gen.json +++ b/internal/data/assets/plugin_746f702d7461626c652d6f662d636f6e74656e7473811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/376c5091-7921-4470-acbf-44db53db38fc/top-table-of-contents","title":"Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"376c5091-7921-4470-acbf-44db53db38fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/376c5091-7921-4470-acbf-44db53db38fc?source=api-prod","cve":"CVE-2024-32110","affectedVersions":"<=1.3.15","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/376c5091-7921-4470-acbf-44db53db38fc/top-table-of-contents","title":"Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"376c5091-7921-4470-acbf-44db53db38fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/376c5091-7921-4470-acbf-44db53db38fc?source=api-prod","cve":"CVE-2024-32110","affectedVersions":"<=1.3.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/82002a9d-68a5-43fe-b46d-da4bf35b4e81/top-table-of-contents","title":"TOP Table Of Contents <= 1.3.31 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"82002a9d-68a5-43fe-b46d-da4bf35b4e81"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/82002a9d-68a5-43fe-b46d-da4bf35b4e81?source=api-prod","cve":"CVE-2026-25314","affectedVersions":"<=1.3.31","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7570646174652d75726c73811c9dc5_gen.json b/internal/data/assets/plugin_7570646174652d75726c73811c9dc5_gen.json index ee596386..977715c1 100644 --- a/internal/data/assets/plugin_7570646174652d75726c73811c9dc5_gen.json +++ b/internal/data/assets/plugin_7570646174652d75726c73811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/5253fe2b-040b-417c-b257-0cb59ee5aa6e/update-urls","title":"Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"5253fe2b-040b-417c-b257-0cb59ee5aa6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5253fe2b-040b-417c-b257-0cb59ee5aa6e?source=api-prod","cve":"CVE-2023-33999","affectedVersions":"=1.2.1","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/366ff716-e325-48e2-8fbd-ad4edbdaf9eb/update-urls","title":"Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress <= 1.4.1 - Unauthenticated Open Redirect\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"366ff716-e325-48e2-8fbd-ad4edbdaf9eb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/366ff716-e325-48e2-8fbd-ad4edbdaf9eb?source=api-prod","cve":"CVE-2026-25392","affectedVersions":"<=1.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/5253fe2b-040b-417c-b257-0cb59ee5aa6e/update-urls","title":"Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"5253fe2b-040b-417c-b257-0cb59ee5aa6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5253fe2b-040b-417c-b257-0cb59ee5aa6e?source=api-prod","cve":"CVE-2023-33999","affectedVersions":"=1.2.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_757365722d61637469766974792d6c6f67811c9dc5_gen.json b/internal/data/assets/plugin_757365722d61637469766974792d6c6f67811c9dc5_gen.json index 75a13368..7eb1c2b6 100644 --- a/internal/data/assets/plugin_757365722d61637469766974792d6c6f67811c9dc5_gen.json +++ b/internal/data/assets/plugin_757365722d61637469766974792d6c6f67811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/001e066f-6add-4426-8cd7-32229a9188d1/user-activity-log","title":"User Activity Log <= 1.4.6 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-08-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"001e066f-6add-4426-8cd7-32229a9188d1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/001e066f-6add-4426-8cd7-32229a9188d1?source=api-prod","affectedVersions":"<=1.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/17a787da-5630-42ec-b5b0-47435db765a7/user-activity-log","title":"User Activity Log <= 1.6.2 - Authenticated(Administrator+) SQL Injection via txtsearch\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"17a787da-5630-42ec-b5b0-47435db765a7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/17a787da-5630-42ec-b5b0-47435db765a7?source=api-prod","cve":"CVE-2023-2761","affectedVersions":"<=1.6.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/24225f47-cec2-4270-88f0-8696ebfb7168/user-activity-log","title":"User Activity Log <= 2.2 - Unauthenticated Limited Options Update via Failed Login\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 19:31:04","sources":[{"name":"Wordfence","remoteId":"24225f47-cec2-4270-88f0-8696ebfb7168"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/24225f47-cec2-4270-88f0-8696ebfb7168?source=api-prod","cve":"CVE-2025-11877","affectedVersions":"<=2.2","severity":"high"},{"advisoryId":"WPSECADV/WF/57be47e2-9aac-42bd-af6a-5060d2f86449/user-activity-log","title":"User Activity Log <= 1.4.6 - Reflected Cross Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-08-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"57be47e2-9aac-42bd-af6a-5060d2f86449"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/57be47e2-9aac-42bd-af6a-5060d2f86449?source=api-prod","affectedVersions":"<=1.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/64be6e85-00c9-49f5-9ee2-08dbe434a848/user-activity-log","title":"User Activity Log <= 1.6.2 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"64be6e85-00c9-49f5-9ee2-08dbe434a848"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/64be6e85-00c9-49f5-9ee2-08dbe434a848?source=api-prod","cve":"CVE-2023-37966","affectedVersions":"<=1.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/77462f1f-f7d8-4d11-aaf1-82395897fcfa/user-activity-log","title":"User Activity Log <= 1.6.6 - IP Address Spoofing\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"77462f1f-f7d8-4d11-aaf1-82395897fcfa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/77462f1f-f7d8-4d11-aaf1-82395897fcfa?source=api-prod","cve":"CVE-2023-4279","affectedVersions":"<=1.6.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/8483196e-f476-41e5-a988-bcd8a9952a64/user-activity-log","title":"User Activity Log <= 1.6.2 - Unauthenticated SQL Injection via username\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"8483196e-f476-41e5-a988-bcd8a9952a64"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8483196e-f476-41e5-a988-bcd8a9952a64?source=api-prod","affectedVersions":"<=1.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/b4ca985e-cae1-4e26-ad2d-413724cfd45d/user-activity-log","title":"User Activity Log <= 1.6.4 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"b4ca985e-cae1-4e26-ad2d-413724cfd45d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b4ca985e-cae1-4e26-ad2d-413724cfd45d?source=api-prod","cve":"CVE-2023-3435","affectedVersions":"<=1.6.4","severity":"high"},{"advisoryId":"WPSECADV/WF/bb7e9ea4-c450-491f-b924-47ed4abec64a/user-activity-log","title":"User Activity Log <= 1.6.5 - Unauthenticated Data Export to Sensitive Information Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"bb7e9ea4-c450-491f-b924-47ed4abec64a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bb7e9ea4-c450-491f-b924-47ed4abec64a?source=api-prod","cve":"CVE-2023-4269","affectedVersions":"<=1.6.5","severity":"high"},{"advisoryId":"WPSECADV/WF/c9df788e-a92e-4519-9e23-8aed08479b68/user-activity-log","title":"User Activity Log <= 1.9 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"c9df788e-a92e-4519-9e23-8aed08479b68"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c9df788e-a92e-4519-9e23-8aed08479b68?source=api-prod","cve":"CVE-2024-31356","affectedVersions":"<=1.9","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/001e066f-6add-4426-8cd7-32229a9188d1/user-activity-log","title":"User Activity Log <= 1.4.6 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-08-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"001e066f-6add-4426-8cd7-32229a9188d1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/001e066f-6add-4426-8cd7-32229a9188d1?source=api-prod","affectedVersions":"<=1.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/17a787da-5630-42ec-b5b0-47435db765a7/user-activity-log","title":"User Activity Log <= 1.6.2 - Authenticated(Administrator+) SQL Injection via txtsearch\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"17a787da-5630-42ec-b5b0-47435db765a7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/17a787da-5630-42ec-b5b0-47435db765a7?source=api-prod","cve":"CVE-2023-2761","affectedVersions":"<=1.6.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/24225f47-cec2-4270-88f0-8696ebfb7168/user-activity-log","title":"User Activity Log <= 2.2 - Unauthenticated Limited Options Update via Failed Login\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 19:31:04","sources":[{"name":"Wordfence","remoteId":"24225f47-cec2-4270-88f0-8696ebfb7168"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/24225f47-cec2-4270-88f0-8696ebfb7168?source=api-prod","cve":"CVE-2025-11877","affectedVersions":"<=2.2","severity":"high"},{"advisoryId":"WPSECADV/WF/2c931bd2-8c19-4211-9378-f32a1302defd/user-activity-log","title":"User Activity Log <= 2.2 - Unauthenticated Limited Arbitrary Option Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"2c931bd2-8c19-4211-9378-f32a1302defd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2c931bd2-8c19-4211-9378-f32a1302defd?source=api-prod","cve":"CVE-2025-13471","affectedVersions":"<=2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/57be47e2-9aac-42bd-af6a-5060d2f86449/user-activity-log","title":"User Activity Log <= 1.4.6 - Reflected Cross Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-08-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"57be47e2-9aac-42bd-af6a-5060d2f86449"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/57be47e2-9aac-42bd-af6a-5060d2f86449?source=api-prod","affectedVersions":"<=1.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/64be6e85-00c9-49f5-9ee2-08dbe434a848/user-activity-log","title":"User Activity Log <= 1.6.2 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"64be6e85-00c9-49f5-9ee2-08dbe434a848"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/64be6e85-00c9-49f5-9ee2-08dbe434a848?source=api-prod","cve":"CVE-2023-37966","affectedVersions":"<=1.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/77462f1f-f7d8-4d11-aaf1-82395897fcfa/user-activity-log","title":"User Activity Log <= 1.6.6 - IP Address Spoofing\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"77462f1f-f7d8-4d11-aaf1-82395897fcfa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/77462f1f-f7d8-4d11-aaf1-82395897fcfa?source=api-prod","cve":"CVE-2023-4279","affectedVersions":"<=1.6.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/8483196e-f476-41e5-a988-bcd8a9952a64/user-activity-log","title":"User Activity Log <= 1.6.2 - Unauthenticated SQL Injection via username\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"8483196e-f476-41e5-a988-bcd8a9952a64"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8483196e-f476-41e5-a988-bcd8a9952a64?source=api-prod","affectedVersions":"<=1.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/b4ca985e-cae1-4e26-ad2d-413724cfd45d/user-activity-log","title":"User Activity Log <= 1.6.4 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"b4ca985e-cae1-4e26-ad2d-413724cfd45d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b4ca985e-cae1-4e26-ad2d-413724cfd45d?source=api-prod","cve":"CVE-2023-3435","affectedVersions":"<=1.6.4","severity":"high"},{"advisoryId":"WPSECADV/WF/bb7e9ea4-c450-491f-b924-47ed4abec64a/user-activity-log","title":"User Activity Log <= 1.6.5 - Unauthenticated Data Export to Sensitive Information Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"bb7e9ea4-c450-491f-b924-47ed4abec64a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bb7e9ea4-c450-491f-b924-47ed4abec64a?source=api-prod","cve":"CVE-2023-4269","affectedVersions":"<=1.6.5","severity":"high"},{"advisoryId":"WPSECADV/WF/c9df788e-a92e-4519-9e23-8aed08479b68/user-activity-log","title":"User Activity Log <= 1.9 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"c9df788e-a92e-4519-9e23-8aed08479b68"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c9df788e-a92e-4519-9e23-8aed08479b68?source=api-prod","cve":"CVE-2024-31356","affectedVersions":"<=1.9","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_757365722d746f6f6c6b6974811c9dc5_gen.json b/internal/data/assets/plugin_757365722d746f6f6c6b6974811c9dc5_gen.json index 98e8154b..3194bfa7 100644 --- a/internal/data/assets/plugin_757365722d746f6f6c6b6974811c9dc5_gen.json +++ b/internal/data/assets/plugin_757365722d746f6f6c6b6974811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/805f18e2-9a5a-48cf-81f4-825da4bfd8ef/user-toolkit","title":"User Toolkit <= 1.2.3 - Authenticated (Subscriber+) Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"805f18e2-9a5a-48cf-81f4-825da4bfd8ef"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/805f18e2-9a5a-48cf-81f4-825da4bfd8ef?source=api-prod","cve":"CVE-2024-9890","affectedVersions":"<=1.2.3","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/805f18e2-9a5a-48cf-81f4-825da4bfd8ef/user-toolkit","title":"User Toolkit <= 1.2.3 - Authenticated (Subscriber+) Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"805f18e2-9a5a-48cf-81f4-825da4bfd8ef"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/805f18e2-9a5a-48cf-81f4-825da4bfd8ef?source=api-prod","cve":"CVE-2024-9890","affectedVersions":"<=1.2.3","severity":"high"},{"advisoryId":"WPSECADV/WF/9bd3b7d6-7ad1-44f4-b28d-fdcb81692a8f/user-toolkit","title":"User Toolkit <= 1.2.3 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"9bd3b7d6-7ad1-44f4-b28d-fdcb81692a8f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9bd3b7d6-7ad1-44f4-b28d-fdcb81692a8f?source=api-prod","cve":"CVE-2024-50503","affectedVersions":"<=1.2.3","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77616c6c65742d73797374656d2d666f722d776f6f636f6d6d65726365811c9dc5_gen.json b/internal/data/assets/plugin_77616c6c65742d73797374656d2d666f722d776f6f636f6d6d65726365811c9dc5_gen.json index df0a8042..ce38ea10 100644 --- a/internal/data/assets/plugin_77616c6c65742d73797374656d2d666f722d776f6f636f6d6d65726365811c9dc5_gen.json +++ b/internal/data/assets/plugin_77616c6c65742d73797374656d2d666f722d776f6f636f6d6d65726365811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/19f8a656-696c-4e4f-a0a6-c71010a1ee12/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce <= 2.5.13 - Information Exposure via Log Files\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"19f8a656-696c-4e4f-a0a6-c71010a1ee12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/19f8a656-696c-4e4f-a0a6-c71010a1ee12?source=api-prod","cve":"CVE-2024-38699","affectedVersions":"<=2.5.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/33800fbb-7660-4704-a978-d5b64ff9f66e/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce <= 2.7.3 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"33800fbb-7660-4704-a978-d5b64ff9f66e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/33800fbb-7660-4704-a978-d5b64ff9f66e?source=api-prod","cve":"CVE-2025-68029","affectedVersions":"<=2.7.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/466a5315-fc05-4b96-9dfd-17862fc406c5/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Wallet Balance Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-16 14:05:30","sources":[{"name":"Wordfence","remoteId":"466a5315-fc05-4b96-9dfd-17862fc406c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/466a5315-fc05-4b96-9dfd-17862fc406c5?source=api-prod","cve":"CVE-2025-14450","affectedVersions":"<=2.7.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/6a423fff-7264-448e-ad97-2922a3a7151a/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce <= 2.6.7 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"6a423fff-7264-448e-ad97-2922a3a7151a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6a423fff-7264-448e-ad97-2922a3a7151a?source=api-prod","cve":"CVE-2025-54041","affectedVersions":"<=2.6.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/779a9f7a-4582-4d5e-bd9a-9ff7f14b452a/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-03 20:19:36","sources":[{"name":"Wordfence","remoteId":"779a9f7a-4582-4d5e-bd9a-9ff7f14b452a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/779a9f7a-4582-4d5e-bd9a-9ff7f14b452a?source=api-prod","cve":"CVE-2024-13682","affectedVersions":"<=2.6.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/8cea16a6-fb4c-48d5-a187-b7fe1679fd35/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce <= 2.6.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"8cea16a6-fb4c-48d5-a187-b7fe1679fd35"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8cea16a6-fb4c-48d5-a187-b7fe1679fd35?source=api-prod","cve":"CVE-2025-32530","affectedVersions":"<=2.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/b81b06b4-559f-4b69-9fdd-e09e66525867/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce <= 2.5.9 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"b81b06b4-559f-4b69-9fdd-e09e66525867"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b81b06b4-559f-4b69-9fdd-e09e66525867?source=api-prod","cve":"CVE-2024-32446","affectedVersions":"<=2.5.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/bda326b0-9049-496a-a600-fa65151ce98f/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-03 20:17:55","sources":[{"name":"Wordfence","remoteId":"bda326b0-9049-496a-a600-fa65151ce98f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bda326b0-9049-496a-a600-fa65151ce98f?source=api-prod","cve":"CVE-2024-13724","affectedVersions":"<=2.6.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/19f8a656-696c-4e4f-a0a6-c71010a1ee12/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce <= 2.5.13 - Information Exposure via Log Files\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"19f8a656-696c-4e4f-a0a6-c71010a1ee12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/19f8a656-696c-4e4f-a0a6-c71010a1ee12?source=api-prod","cve":"CVE-2024-38699","affectedVersions":"<=2.5.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/33800fbb-7660-4704-a978-d5b64ff9f66e/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce <= 2.7.3 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"33800fbb-7660-4704-a978-d5b64ff9f66e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/33800fbb-7660-4704-a978-d5b64ff9f66e?source=api-prod","cve":"CVE-2025-68029","affectedVersions":"<=2.7.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/3a49f5f8-eec3-4b43-a007-329a7c1c6840/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments <= 2.7.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"3a49f5f8-eec3-4b43-a007-329a7c1c6840"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3a49f5f8-eec3-4b43-a007-329a7c1c6840?source=api-prod","cve":"CVE-2026-42654","affectedVersions":"<=2.7.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/466a5315-fc05-4b96-9dfd-17862fc406c5/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Wallet Balance Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-16 14:05:30","sources":[{"name":"Wordfence","remoteId":"466a5315-fc05-4b96-9dfd-17862fc406c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/466a5315-fc05-4b96-9dfd-17862fc406c5?source=api-prod","cve":"CVE-2025-14450","affectedVersions":"<=2.7.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/6a423fff-7264-448e-ad97-2922a3a7151a/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce <= 2.6.7 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"6a423fff-7264-448e-ad97-2922a3a7151a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6a423fff-7264-448e-ad97-2922a3a7151a?source=api-prod","cve":"CVE-2025-54041","affectedVersions":"<=2.6.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/779a9f7a-4582-4d5e-bd9a-9ff7f14b452a/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-03 20:19:36","sources":[{"name":"Wordfence","remoteId":"779a9f7a-4582-4d5e-bd9a-9ff7f14b452a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/779a9f7a-4582-4d5e-bd9a-9ff7f14b452a?source=api-prod","cve":"CVE-2024-13682","affectedVersions":"<=2.6.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/8cea16a6-fb4c-48d5-a187-b7fe1679fd35/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce <= 2.6.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"8cea16a6-fb4c-48d5-a187-b7fe1679fd35"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8cea16a6-fb4c-48d5-a187-b7fe1679fd35?source=api-prod","cve":"CVE-2025-32530","affectedVersions":"<=2.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/b81b06b4-559f-4b69-9fdd-e09e66525867/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce <= 2.5.9 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"b81b06b4-559f-4b69-9fdd-e09e66525867"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b81b06b4-559f-4b69-9fdd-e09e66525867?source=api-prod","cve":"CVE-2024-32446","affectedVersions":"<=2.5.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/bda326b0-9049-496a-a600-fa65151ce98f/wallet-system-for-woocommerce","title":"Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-03 20:17:55","sources":[{"name":"Wordfence","remoteId":"bda326b0-9049-496a-a600-fa65151ce98f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bda326b0-9049-496a-a600-fa65151ce98f?source=api-prod","cve":"CVE-2024-13724","affectedVersions":"<=2.6.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_776865656c2d6f662d6c696665811c9dc5_gen.json b/internal/data/assets/plugin_776865656c2d6f662d6c696665811c9dc5_gen.json index b27983c6..330650f2 100644 --- a/internal/data/assets/plugin_776865656c2d6f662d6c696665811c9dc5_gen.json +++ b/internal/data/assets/plugin_776865656c2d6f662d6c696665811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0615d1be-f9fa-45b3-9d5b-3ad1f36be8e1/wheel-of-life","title":"Wheel of Life: Coaching and Assessment Tool for Life Coach <= 1.1.7 - Missing Authorization on Several AJAX Endpoints\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-19 12:15:38","sources":[{"name":"Wordfence","remoteId":"0615d1be-f9fa-45b3-9d5b-3ad1f36be8e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0615d1be-f9fa-45b3-9d5b-3ad1f36be8e1?source=api-prod","cve":"CVE-2024-3627","affectedVersions":"<=1.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/d2b74b9d-b296-4d3b-936f-419dad502d79/wheel-of-life","title":"Wheel of Life <= 1.1.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d2b74b9d-b296-4d3b-936f-419dad502d79"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d2b74b9d-b296-4d3b-936f-419dad502d79?source=api-prod","cve":"CVE-2024-47311","affectedVersions":"<=1.1.8","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0615d1be-f9fa-45b3-9d5b-3ad1f36be8e1/wheel-of-life","title":"Wheel of Life: Coaching and Assessment Tool for Life Coach <= 1.1.7 - Missing Authorization on Several AJAX Endpoints\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-19 12:15:38","sources":[{"name":"Wordfence","remoteId":"0615d1be-f9fa-45b3-9d5b-3ad1f36be8e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0615d1be-f9fa-45b3-9d5b-3ad1f36be8e1?source=api-prod","cve":"CVE-2024-3627","affectedVersions":"<=1.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/4149ee26-86c0-408b-a8e1-976c7fbf6e81/wheel-of-life","title":"Wheel of Life <= 1.2.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"4149ee26-86c0-408b-a8e1-976c7fbf6e81"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4149ee26-86c0-408b-a8e1-976c7fbf6e81?source=api-prod","cve":"CVE-2026-25000","affectedVersions":"<=1.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/d2b74b9d-b296-4d3b-936f-419dad502d79/wheel-of-life","title":"Wheel of Life <= 1.1.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d2b74b9d-b296-4d3b-936f-419dad502d79"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d2b74b9d-b296-4d3b-936f-419dad502d79?source=api-prod","cve":"CVE-2024-47311","affectedVersions":"<=1.1.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77697365722d726576696577811c9dc5_gen.json b/internal/data/assets/plugin_77697365722d726576696577811c9dc5_gen.json new file mode 100644 index 00000000..987636df --- /dev/null +++ b/internal/data/assets/plugin_77697365722d726576696577811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/7ee6ca74-3684-46df-9b42-e97ee8cdbdb8/wiser-review","title":"WiserReview Product Reviews for WooCommerce <= 2.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"7ee6ca74-3684-46df-9b42-e97ee8cdbdb8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7ee6ca74-3684-46df-9b42-e97ee8cdbdb8?source=api-prod","cve":"CVE-2026-25318","affectedVersions":"<=2.9","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_776f6f2d676966742d63617264732d6c697465811c9dc5_gen.json b/internal/data/assets/plugin_776f6f2d676966742d63617264732d6c697465811c9dc5_gen.json index 4a63f78e..96a9a264 100644 --- a/internal/data/assets/plugin_776f6f2d676966742d63617264732d6c697465811c9dc5_gen.json +++ b/internal/data/assets/plugin_776f6f2d676966742d63617264732d6c697465811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/2b0d0c44-0ee8-400b-a4ea-e5520c2a6710/woo-gift-cards-lite","title":"Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates <= 2.6.6 - Missing Authorization to Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"2b0d0c44-0ee8-400b-a4ea-e5520c2a6710"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b0d0c44-0ee8-400b-a4ea-e5520c2a6710?source=api-prod","cve":"CVE-2024-1857","affectedVersions":"<=2.6.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/2da322ea-0206-4838-8ac4-9dd201bb00bc/woo-gift-cards-lite","title":"Ultimate Gift Cards for WooCommerce <= 2.1.1 - Cross-Site Request Forgery Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-06-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"2da322ea-0206-4838-8ac4-9dd201bb00bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2da322ea-0206-4838-8ac4-9dd201bb00bc?source=api-prod","cve":"CVE-2021-4391","affectedVersions":"<=2.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/836884b5-f547-4f50-8a97-5d910d877e5e/woo-gift-cards-lite","title":"Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-07 21:46:18","sources":[{"name":"Wordfence","remoteId":"836884b5-f547-4f50-8a97-5d910d877e5e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/836884b5-f547-4f50-8a97-5d910d877e5e?source=api-prod","cve":"CVE-2024-11423","affectedVersions":"<=3.0.6","severity":"high"},{"advisoryId":"WPSECADV/WF/e9e89383-a9c6-4300-970c-0b36e4d97e3d/woo-gift-cards-lite","title":"Ultimate Gift Cards for WooCommerce <= 3.1.4 - Authenticated (Administrator+) SQL Injection via wps_wgm_save_post Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-02 19:33:48","sources":[{"name":"Wordfence","remoteId":"e9e89383-a9c6-4300-970c-0b36e4d97e3d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e9e89383-a9c6-4300-970c-0b36e4d97e3d?source=api-prod","cve":"CVE-2025-5103","affectedVersions":"<=3.1.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/2b0d0c44-0ee8-400b-a4ea-e5520c2a6710/woo-gift-cards-lite","title":"Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates <= 2.6.6 - Missing Authorization to Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"2b0d0c44-0ee8-400b-a4ea-e5520c2a6710"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b0d0c44-0ee8-400b-a4ea-e5520c2a6710?source=api-prod","cve":"CVE-2024-1857","affectedVersions":"<=2.6.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/2da322ea-0206-4838-8ac4-9dd201bb00bc/woo-gift-cards-lite","title":"Ultimate Gift Cards for WooCommerce <= 2.1.1 - Cross-Site Request Forgery Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-06-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"2da322ea-0206-4838-8ac4-9dd201bb00bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2da322ea-0206-4838-8ac4-9dd201bb00bc?source=api-prod","cve":"CVE-2021-4391","affectedVersions":"<=2.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/836884b5-f547-4f50-8a97-5d910d877e5e/woo-gift-cards-lite","title":"Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-07 21:46:18","sources":[{"name":"Wordfence","remoteId":"836884b5-f547-4f50-8a97-5d910d877e5e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/836884b5-f547-4f50-8a97-5d910d877e5e?source=api-prod","cve":"CVE-2024-11423","affectedVersions":"<=3.0.6","severity":"high"},{"advisoryId":"WPSECADV/WF/8ce1253e-48fe-4005-816c-9cf6127cae54/woo-gift-cards-lite","title":"Ultimate Gift Cards for WooCommerce <= 3.2.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ce1253e-48fe-4005-816c-9cf6127cae54"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ce1253e-48fe-4005-816c-9cf6127cae54?source=api-prod","cve":"CVE-2026-24375","affectedVersions":"<=3.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/e9e89383-a9c6-4300-970c-0b36e4d97e3d/woo-gift-cards-lite","title":"Ultimate Gift Cards for WooCommerce <= 3.1.4 - Authenticated (Administrator+) SQL Injection via wps_wgm_save_post Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-02 19:33:48","sources":[{"name":"Wordfence","remoteId":"e9e89383-a9c6-4300-970c-0b36e4d97e3d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e9e89383-a9c6-4300-970c-0b36e4d97e3d?source=api-prod","cve":"CVE-2025-5103","affectedVersions":"<=3.1.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_776f6f7a6f6e65811c9dc5_gen.json b/internal/data/assets/plugin_776f6f7a6f6e65811c9dc5_gen.json index 6b45747d..534a74a2 100644 --- a/internal/data/assets/plugin_776f6f7a6f6e65811c9dc5_gen.json +++ b/internal/data/assets/plugin_776f6f7a6f6e65811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.31 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3?source=api-prod","cve":"CVE-2026-27039","affectedVersions":"<=14.0.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/2621d2f1-7ce3-4858-9633-080ef916d374/woozone","title":"WZone < 14.1.00 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"2621d2f1-7ce3-4858-9633-080ef916d374"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2621d2f1-7ce3-4858-9633-080ef916d374?source=api-prod","cve":"CVE-2024-33547","affectedVersions":"<14.1.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/7193052f-1bef-426c-b0fe-4d70931f47ed/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin < 14.1.00 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7193052f-1bef-426c-b0fe-4d70931f47ed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7193052f-1bef-426c-b0fe-4d70931f47ed?source=api-prod","cve":"CVE-2024-33545","affectedVersions":"<14.1.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin < 14.1.00 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6?source=api-prod","cve":"CVE-2024-33548","affectedVersions":"<14.1.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca88c62d-0f27-40e0-9dd2-21d3d133fda3/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.10 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca88c62d-0f27-40e0-9dd2-21d3d133fda3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca88c62d-0f27-40e0-9dd2-21d3d133fda3?source=api-prod","cve":"CVE-2024-33544","affectedVersions":"<=14.0.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/d1a14fc2-cebe-4a0e-92b0-af2a9c805401/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.10 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d1a14fc2-cebe-4a0e-92b0-af2a9c805401"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d1a14fc2-cebe-4a0e-92b0-af2a9c805401?source=api-prod","cve":"CVE-2024-33546","affectedVersions":"<=14.0.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/d5b110a5-4027-4c98-a348-325c8b9c8405/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin < 14.1.00 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d5b110a5-4027-4c98-a348-325c8b9c8405"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d5b110a5-4027-4c98-a348-325c8b9c8405?source=api-prod","cve":"CVE-2024-33549","affectedVersions":"<14.1.00","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0d1ff67c-f644-46d1-abad-e5fc2b177786/woozone","title":"WZone <= 14.0.31 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d1ff67c-f644-46d1-abad-e5fc2b177786"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d1ff67c-f644-46d1-abad-e5fc2b177786?source=api-prod","cve":"CVE-2026-25473","affectedVersions":"<=14.0.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.31 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3?source=api-prod","cve":"CVE-2026-27039","affectedVersions":"<=14.0.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/2621d2f1-7ce3-4858-9633-080ef916d374/woozone","title":"WZone < 14.1.00 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"2621d2f1-7ce3-4858-9633-080ef916d374"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2621d2f1-7ce3-4858-9633-080ef916d374?source=api-prod","cve":"CVE-2024-33547","affectedVersions":"<14.1.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/7193052f-1bef-426c-b0fe-4d70931f47ed/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin < 14.1.00 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7193052f-1bef-426c-b0fe-4d70931f47ed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7193052f-1bef-426c-b0fe-4d70931f47ed?source=api-prod","cve":"CVE-2024-33545","affectedVersions":"<14.1.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin < 14.1.00 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6?source=api-prod","cve":"CVE-2024-33548","affectedVersions":"<14.1.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca88c62d-0f27-40e0-9dd2-21d3d133fda3/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.10 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca88c62d-0f27-40e0-9dd2-21d3d133fda3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca88c62d-0f27-40e0-9dd2-21d3d133fda3?source=api-prod","cve":"CVE-2024-33544","affectedVersions":"<=14.0.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/d1a14fc2-cebe-4a0e-92b0-af2a9c805401/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.10 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d1a14fc2-cebe-4a0e-92b0-af2a9c805401"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d1a14fc2-cebe-4a0e-92b0-af2a9c805401?source=api-prod","cve":"CVE-2024-33546","affectedVersions":"<=14.0.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/d5b110a5-4027-4c98-a348-325c8b9c8405/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin < 14.1.00 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d5b110a5-4027-4c98-a348-325c8b9c8405"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d5b110a5-4027-4c98-a348-325c8b9c8405?source=api-prod","cve":"CVE-2024-33549","affectedVersions":"<14.1.00","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77702d627573696e6573732d696e74656c6c6967656e63652d6c697465811c9dc5_gen.json b/internal/data/assets/plugin_77702d627573696e6573732d696e74656c6c6967656e63652d6c697465811c9dc5_gen.json index 6111f90e..05c09ebb 100644 --- a/internal/data/assets/plugin_77702d627573696e6573732d696e74656c6c6967656e63652d6c697465811c9dc5_gen.json +++ b/internal/data/assets/plugin_77702d627573696e6573732d696e74656c6c6967656e63652d6c697465811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/e7eb6137-5c03-4f73-a478-c1c18ee91fba/wp-business-intelligence-lite","title":"WP Business Intelligence Lite <= 1.6.2 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-04-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7eb6137-5c03-4f73-a478-c1c18ee91fba"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7eb6137-5c03-4f73-a478-c1c18ee91fba?source=api-prod","cve":"CVE-2015-9326","affectedVersions":"<=1.6.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/ee8ad691-b598-4eeb-b8a7-645c3bd968ff/wp-business-intelligence-lite","title":"WP Business intelligence lite < 1.3 - Arbitrary File Upload\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"ee8ad691-b598-4eeb-b8a7-645c3bd968ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ee8ad691-b598-4eeb-b8a7-645c3bd968ff?source=api-prod","affectedVersions":"<1.3","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/a7e35f18-7659-4b97-b99f-b57ac941cb22/wp-business-intelligence-lite","title":"WP Business Intelligence Lite <= 3.2.0 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary SQL Modification\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:06:15","sources":[{"name":"Wordfence","remoteId":"a7e35f18-7659-4b97-b99f-b57ac941cb22"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a7e35f18-7659-4b97-b99f-b57ac941cb22?source=api-prod","affectedVersions":"<=3.2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/e7eb6137-5c03-4f73-a478-c1c18ee91fba/wp-business-intelligence-lite","title":"WP Business Intelligence Lite <= 1.6.2 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-04-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7eb6137-5c03-4f73-a478-c1c18ee91fba"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7eb6137-5c03-4f73-a478-c1c18ee91fba?source=api-prod","cve":"CVE-2015-9326","affectedVersions":"<=1.6.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/ee8ad691-b598-4eeb-b8a7-645c3bd968ff/wp-business-intelligence-lite","title":"WP Business intelligence lite < 1.3 - Arbitrary File Upload\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"ee8ad691-b598-4eeb-b8a7-645c3bd968ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ee8ad691-b598-4eeb-b8a7-645c3bd968ff?source=api-prod","affectedVersions":"<1.3","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77702d6361726f7573656c2d66726565811c9dc5_gen.json b/internal/data/assets/plugin_77702d6361726f7573656c2d66726565811c9dc5_gen.json index db91e105..6495c453 100644 --- a/internal/data/assets/plugin_77702d6361726f7573656c2d66726565811c9dc5_gen.json +++ b/internal/data/assets/plugin_77702d6361726f7573656c2d66726565811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/6a192e28-45cf-4d6a-ab87-b03d8264e7df/wp-carousel-free","title":"Carousel, Slider, Gallery by WP Carousel <= 2.7.3 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"6a192e28-45cf-4d6a-ab87-b03d8264e7df"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6a192e28-45cf-4d6a-ab87-b03d8264e7df?source=api-prod","cve":"CVE-2024-13314","affectedVersions":"<=2.7.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/9349208c-3e86-4ec6-9e10-5ecaa4923922/wp-carousel-free","title":"Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sp_wp_carousel_shortcode'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"9349208c-3e86-4ec6-9e10-5ecaa4923922"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9349208c-3e86-4ec6-9e10-5ecaa4923922?source=api-prod","cve":"CVE-2024-2949","affectedVersions":"<=2.6.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/d66df15e-1a0a-49e9-bcf9-67091499b24e/wp-carousel-free","title":"Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"d66df15e-1a0a-49e9-bcf9-67091499b24e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d66df15e-1a0a-49e9-bcf9-67091499b24e?source=api-prod","cve":"CVE-2024-3020","affectedVersions":"<=2.6.3","severity":"high"},{"advisoryId":"WPSECADV/WF/d7051345-8ca6-42e0-95fb-e127e65a5ef2/wp-carousel-free","title":"Carousel, Slider, Gallery by WP Carousel <= 2.6.8 - Authenticated (Editor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"d7051345-8ca6-42e0-95fb-e127e65a5ef2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d7051345-8ca6-42e0-95fb-e127e65a5ef2?source=api-prod","cve":"CVE-2024-4002","affectedVersions":"<=2.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/d99d4b9a-aa09-434d-91a8-7afaa0e8b5db/wp-carousel-free","title":"Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"d99d4b9a-aa09-434d-91a8-7afaa0e8b5db"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d99d4b9a-aa09-434d-91a8-7afaa0e8b5db?source=api-prod","cve":"CVE-2024-5020","affectedVersions":"<=2.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/f3559bba-daa2-4a00-958c-6568cdbb592f/wp-carousel-free","title":"Carousel, Slider, Gallery by WP Carousel <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"f3559bba-daa2-4a00-958c-6568cdbb592f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f3559bba-daa2-4a00-958c-6568cdbb592f?source=api-prod","cve":"CVE-2022-4482","affectedVersions":"<=2.5.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/6a192e28-45cf-4d6a-ab87-b03d8264e7df/wp-carousel-free","title":"Carousel, Slider, Gallery by WP Carousel <= 2.7.3 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"6a192e28-45cf-4d6a-ab87-b03d8264e7df"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6a192e28-45cf-4d6a-ab87-b03d8264e7df?source=api-prod","cve":"CVE-2024-13314","affectedVersions":"<=2.7.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/9349208c-3e86-4ec6-9e10-5ecaa4923922/wp-carousel-free","title":"Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sp_wp_carousel_shortcode'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"9349208c-3e86-4ec6-9e10-5ecaa4923922"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9349208c-3e86-4ec6-9e10-5ecaa4923922?source=api-prod","cve":"CVE-2024-2949","affectedVersions":"<=2.6.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/d66df15e-1a0a-49e9-bcf9-67091499b24e/wp-carousel-free","title":"Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"d66df15e-1a0a-49e9-bcf9-67091499b24e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d66df15e-1a0a-49e9-bcf9-67091499b24e?source=api-prod","cve":"CVE-2024-3020","affectedVersions":"<=2.6.3","severity":"high"},{"advisoryId":"WPSECADV/WF/d7051345-8ca6-42e0-95fb-e127e65a5ef2/wp-carousel-free","title":"Carousel, Slider, Gallery by WP Carousel <= 2.6.8 - Authenticated (Editor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"d7051345-8ca6-42e0-95fb-e127e65a5ef2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d7051345-8ca6-42e0-95fb-e127e65a5ef2?source=api-prod","cve":"CVE-2024-4002","affectedVersions":"<=2.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/d99d4b9a-aa09-434d-91a8-7afaa0e8b5db/wp-carousel-free","title":"Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"d99d4b9a-aa09-434d-91a8-7afaa0e8b5db"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d99d4b9a-aa09-434d-91a8-7afaa0e8b5db?source=api-prod","cve":"CVE-2024-5020","affectedVersions":"<=2.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/e75815a3-2414-47f3-b0c4-e5d3e2cb369d/wp-carousel-free","title":"WP Carousel Free <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-caption' Attribute\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 15:01:27","sources":[{"name":"Wordfence","remoteId":"e75815a3-2414-47f3-b0c4-e5d3e2cb369d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e75815a3-2414-47f3-b0c4-e5d3e2cb369d?source=api-prod","cve":"CVE-2026-4665","affectedVersions":"<=2.7.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/f3559bba-daa2-4a00-958c-6568cdbb592f/wp-carousel-free","title":"Carousel, Slider, Gallery by WP Carousel <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"f3559bba-daa2-4a00-958c-6568cdbb592f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f3559bba-daa2-4a00-958c-6568cdbb592f?source=api-prod","cve":"CVE-2022-4482","affectedVersions":"<=2.5.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77702d636c69707079811c9dc5_gen.json b/internal/data/assets/plugin_77702d636c69707079811c9dc5_gen.json new file mode 100644 index 00000000..82f0af74 --- /dev/null +++ b/internal/data/assets/plugin_77702d636c69707079811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/ec49ed83-a09d-460d-be34-0fb79032b543/wp-clippy","title":"WP-Clippy <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:06:40","sources":[{"name":"Wordfence","remoteId":"ec49ed83-a09d-460d-be34-0fb79032b543"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ec49ed83-a09d-460d-be34-0fb79032b543?source=api-prod","cve":"CVE-2026-5505","affectedVersions":"<=1.0.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77702d636f6f6b69652d616c6c6f77811c9dc5_gen.json b/internal/data/assets/plugin_77702d636f6f6b69652d616c6c6f77811c9dc5_gen.json new file mode 100644 index 00000000..0126b06a --- /dev/null +++ b/internal/data/assets/plugin_77702d636f6f6b69652d616c6c6f77811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/f783e626-37c0-4ad9-9074-c5332583a0cb/wp-cookie-allow","title":"WeePie Cookie Allow <= 3.4.11 - Unauthenticated SQL Injection via 'consent' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 17:38:50","sources":[{"name":"Wordfence","remoteId":"f783e626-37c0-4ad9-9074-c5332583a0cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f783e626-37c0-4ad9-9074-c5332583a0cb?source=api-prod","cve":"CVE-2026-4304","affectedVersions":"<=3.4.11","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77702d652d636f6d6d65726365811c9dc5_gen.json b/internal/data/assets/plugin_77702d652d636f6d6d65726365811c9dc5_gen.json index 89920692..a36420bf 100644 --- a/internal/data/assets/plugin_77702d652d636f6d6d65726365811c9dc5_gen.json +++ b/internal/data/assets/plugin_77702d652d636f6d6d65726365811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0753e172-3ff7-42a9-8651-d12573406d11/wp-e-commerce","title":"WP eCommerce <= 3.8.9 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"0753e172-3ff7-42a9-8651-d12573406d11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0753e172-3ff7-42a9-8651-d12573406d11?source=api-prod","affectedVersions":"<=3.8.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/0ba5da2b-6944-4243-a4f2-0f887abf7a66/wp-e-commerce","title":"WP eCommerce <= 3.15.1 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"0ba5da2b-6944-4243-a4f2-0f887abf7a66"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0ba5da2b-6944-4243-a4f2-0f887abf7a66?source=api-prod","cve":"CVE-2024-1514","affectedVersions":"<=3.15.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/2d1302c4-7aeb-49f4-aa11-2c0e08bd9c71/wp-e-commerce","title":"WP eCommerce < 3.8.7.2 - Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2011-11-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"2d1302c4-7aeb-49f4-aa11-2c0e08bd9c71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2d1302c4-7aeb-49f4-aa11-2c0e08bd9c71?source=api-prod","cve":"CVE-2011-5104","affectedVersions":"<3.8.7.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/3c43939f-c0c7-4388-80ae-44bdf67675c7/wp-e-commerce","title":"WP eCommerce < 3.11.4 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-11-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"3c43939f-c0c7-4388-80ae-44bdf67675c7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3c43939f-c0c7-4388-80ae-44bdf67675c7?source=api-prod","affectedVersions":"<3.11.4","severity":"high"},{"advisoryId":"WPSECADV/WF/4aa89fab-b6fe-423a-a7f5-dbe6c92d1b56/wp-e-commerce","title":"WP eCommerce < 3.8.7.6 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-10-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"4aa89fab-b6fe-423a-a7f5-dbe6c92d1b56"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4aa89fab-b6fe-423a-a7f5-dbe6c92d1b56?source=api-prod","cve":"CVE-2012-5310","affectedVersions":"<3.8.7.6","severity":"critical"},{"advisoryId":"WPSECADV/WF/5c42a966-0035-4c12-8aa1-226a0157d98f/wp-e-commerce","title":"WP eCommerce <= 3.8.9 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"5c42a966-0035-4c12-8aa1-226a0157d98f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5c42a966-0035-4c12-8aa1-226a0157d98f?source=api-prod","affectedVersions":"<=3.8.9","severity":"critical"},{"advisoryId":"WPSECADV/WF/8bc861b2-1e8a-42be-b70b-e9f9224bd8bb/wp-e-commerce","title":"eCommerce <= 3.15.1 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"8bc861b2-1e8a-42be-b70b-e9f9224bd8bb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8bc861b2-1e8a-42be-b70b-e9f9224bd8bb?source=api-prod","cve":"CVE-2026-1235","affectedVersions":"<=3.15.1","severity":"high"},{"advisoryId":"WPSECADV/WF/b0a9f3d2-aa7f-4fc2-9cfd-b69ec3f63160/wp-e-commerce","title":"WP eCommerce <= 3.15.1 - Missing Authorization to Unauthenticated Arbitrary Post Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"b0a9f3d2-aa7f-4fc2-9cfd-b69ec3f63160"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b0a9f3d2-aa7f-4fc2-9cfd-b69ec3f63160?source=api-prod","cve":"CVE-2024-1516","affectedVersions":"<=3.15.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/e92f35dc-7e19-464a-bb8a-40a662e2270a/wp-e-commerce","title":"WP eCommerce <= 3.8.14.3 - Missing Authorization\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-11-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"e92f35dc-7e19-464a-bb8a-40a662e2270a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e92f35dc-7e19-464a-bb8a-40a662e2270a?source=api-prod","affectedVersions":"<=3.8.14.3","severity":"high"},{"advisoryId":"WPSECADV/WF/ed0860db-0e1f-4929-90d5-ff2766ba71ad/wp-e-commerce","title":"WP eCommerce <= 3.9.2 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-04-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"ed0860db-0e1f-4929-90d5-ff2766ba71ad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ed0860db-0e1f-4929-90d5-ff2766ba71ad?source=api-prod","affectedVersions":"<=3.9.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0753e172-3ff7-42a9-8651-d12573406d11/wp-e-commerce","title":"WP eCommerce <= 3.8.9 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"0753e172-3ff7-42a9-8651-d12573406d11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0753e172-3ff7-42a9-8651-d12573406d11?source=api-prod","affectedVersions":"<=3.8.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/0ba5da2b-6944-4243-a4f2-0f887abf7a66/wp-e-commerce","title":"WP eCommerce <= 3.15.1 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"0ba5da2b-6944-4243-a4f2-0f887abf7a66"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0ba5da2b-6944-4243-a4f2-0f887abf7a66?source=api-prod","cve":"CVE-2024-1514","affectedVersions":"<=3.15.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/2d1302c4-7aeb-49f4-aa11-2c0e08bd9c71/wp-e-commerce","title":"WP eCommerce < 3.8.7.2 - Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2011-11-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"2d1302c4-7aeb-49f4-aa11-2c0e08bd9c71"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2d1302c4-7aeb-49f4-aa11-2c0e08bd9c71?source=api-prod","cve":"CVE-2011-5104","affectedVersions":"<3.8.7.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/3c43939f-c0c7-4388-80ae-44bdf67675c7/wp-e-commerce","title":"WP eCommerce < 3.11.4 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-11-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"3c43939f-c0c7-4388-80ae-44bdf67675c7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3c43939f-c0c7-4388-80ae-44bdf67675c7?source=api-prod","affectedVersions":"<3.11.4","severity":"high"},{"advisoryId":"WPSECADV/WF/4aa89fab-b6fe-423a-a7f5-dbe6c92d1b56/wp-e-commerce","title":"WP eCommerce < 3.8.7.6 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-10-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"4aa89fab-b6fe-423a-a7f5-dbe6c92d1b56"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4aa89fab-b6fe-423a-a7f5-dbe6c92d1b56?source=api-prod","cve":"CVE-2012-5310","affectedVersions":"<3.8.7.6","severity":"critical"},{"advisoryId":"WPSECADV/WF/5c42a966-0035-4c12-8aa1-226a0157d98f/wp-e-commerce","title":"WP eCommerce <= 3.8.9 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"5c42a966-0035-4c12-8aa1-226a0157d98f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5c42a966-0035-4c12-8aa1-226a0157d98f?source=api-prod","affectedVersions":"<=3.8.9","severity":"critical"},{"advisoryId":"WPSECADV/WF/8bc861b2-1e8a-42be-b70b-e9f9224bd8bb/wp-e-commerce","title":"eCommerce <= 3.15.1 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"8bc861b2-1e8a-42be-b70b-e9f9224bd8bb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8bc861b2-1e8a-42be-b70b-e9f9224bd8bb?source=api-prod","cve":"CVE-2026-1235","affectedVersions":"<=3.15.1","severity":"high"},{"advisoryId":"WPSECADV/WF/b0a9f3d2-aa7f-4fc2-9cfd-b69ec3f63160/wp-e-commerce","title":"WP eCommerce <= 3.15.1 - Missing Authorization to Unauthenticated Arbitrary Post Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"b0a9f3d2-aa7f-4fc2-9cfd-b69ec3f63160"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b0a9f3d2-aa7f-4fc2-9cfd-b69ec3f63160?source=api-prod","cve":"CVE-2024-1516","affectedVersions":"<=3.15.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/db6167c5-fdae-490f-813c-f1a0b34aa9d8/wp-e-commerce","title":"eCommerce <= 3.15.1 - Cross-Site Request Forgery to Coupon Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"db6167c5-fdae-490f-813c-f1a0b34aa9d8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/db6167c5-fdae-490f-813c-f1a0b34aa9d8?source=api-prod","cve":"CVE-2026-1128","affectedVersions":"<=3.15.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/e92f35dc-7e19-464a-bb8a-40a662e2270a/wp-e-commerce","title":"WP eCommerce <= 3.8.14.3 - Missing Authorization\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-11-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"e92f35dc-7e19-464a-bb8a-40a662e2270a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e92f35dc-7e19-464a-bb8a-40a662e2270a?source=api-prod","affectedVersions":"<=3.8.14.3","severity":"high"},{"advisoryId":"WPSECADV/WF/ed0860db-0e1f-4929-90d5-ff2766ba71ad/wp-e-commerce","title":"WP eCommerce <= 3.9.2 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-04-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"ed0860db-0e1f-4929-90d5-ff2766ba71ad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ed0860db-0e1f-4929-90d5-ff2766ba71ad?source=api-prod","affectedVersions":"<=3.9.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77702d6576656e742d736f6c7574696f6e811c9dc5_gen.json b/internal/data/assets/plugin_77702d6576656e742d736f6c7574696f6e811c9dc5_gen.json index 37a9f948..a8be0389 100644 --- a/internal/data/assets/plugin_77702d6576656e742d736f6c7574696f6e811c9dc5_gen.json +++ b/internal/data/assets/plugin_77702d6576656e742d736f6c7574696f6e811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0cbdf679-1657-4249-a433-8fe0cddd94be/wp-event-solution","title":"Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin <= 3.3.50 - Missing Authorization to Unauthenticated Events Export\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"0cbdf679-1657-4249-a433-8fe0cddd94be"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0cbdf679-1657-4249-a433-8fe0cddd94be?source=api-prod","cve":"CVE-2024-1122","affectedVersions":"<=3.3.50","severity":"medium"},{"advisoryId":"WPSECADV/WF/1479071c-85c3-41fd-8ad7-f0dee32f201b/wp-event-solution","title":"Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 16:25:44","sources":[{"name":"Wordfence","remoteId":"1479071c-85c3-41fd-8ad7-f0dee32f201b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1479071c-85c3-41fd-8ad7-f0dee32f201b?source=api-prod","cve":"CVE-2025-3419","affectedVersions":"<=4.0.26","severity":"high"},{"advisoryId":"WPSECADV/WF/1725c7f3-2fac-4714-a63e-6c43694483fc/wp-event-solution","title":"Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Event Data Import\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"1725c7f3-2fac-4714-a63e-6c43694483fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1725c7f3-2fac-4714-a63e-6c43694483fc?source=api-prod","cve":"CVE-2024-6033","affectedVersions":"<=4.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/37d4d038-3f5c-4c4a-b5f1-3dd23a5b345e/wp-event-solution","title":"Eventin <= 4.0.25 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"37d4d038-3f5c-4c4a-b5f1-3dd23a5b345e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/37d4d038-3f5c-4c4a-b5f1-3dd23a5b345e?source=api-prod","cve":"CVE-2025-39584","affectedVersions":"<=4.0.25","severity":"high"},{"advisoryId":"WPSECADV/WF/3ad2651c-5541-4508-9da1-37838a4df901/wp-event-solution","title":"Eventin <= 4.0.31 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"3ad2651c-5541-4508-9da1-37838a4df901"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3ad2651c-5541-4508-9da1-37838a4df901?source=api-prod","cve":"CVE-2025-49869","affectedVersions":"<=4.0.31","severity":"high"},{"advisoryId":"WPSECADV/WF/4bbb0146-436f-42fa-802b-cdcf39ae97db/wp-event-solution","title":"Eventin <= 4.0.26 - Missing Authorization to Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"4bbb0146-436f-42fa-802b-cdcf39ae97db"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4bbb0146-436f-42fa-802b-cdcf39ae97db?source=api-prod","cve":"CVE-2025-47539","affectedVersions":"<=4.0.26","severity":"critical"},{"advisoryId":"WPSECADV/WF/5f24baee-7003-449b-9072-d95fa1e26c8f/wp-event-solution","title":"Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-19 17:03:49","sources":[{"name":"Wordfence","remoteId":"5f24baee-7003-449b-9072-d95fa1e26c8f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5f24baee-7003-449b-9072-d95fa1e26c8f?source=api-prod","cve":"CVE-2025-1770","affectedVersions":"<=4.0.24","severity":"high"},{"advisoryId":"WPSECADV/WF/70408046-5eb5-4217-9db4-e7b2a7809cf8/wp-event-solution","title":"Eventin <= 4.0.20 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"70408046-5eb5-4217-9db4-e7b2a7809cf8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/70408046-5eb5-4217-9db4-e7b2a7809cf8?source=api-prod","cve":"CVE-2025-26964","affectedVersions":"<=4.0.20","severity":"high"},{"advisoryId":"WPSECADV/WF/75537b61-5622-4b35-b80e-389526bd99f0/wp-event-solution","title":"Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"75537b61-5622-4b35-b80e-389526bd99f0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/75537b61-5622-4b35-b80e-389526bd99f0?source=api-prod","cve":"CVE-2024-7149","affectedVersions":"<=4.0.8","severity":"high"},{"advisoryId":"WPSECADV/WF/87f82d5d-d89a-440d-8c23-ace5160a0739/wp-event-solution","title":"Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-13 18:46:40","sources":[{"name":"Wordfence","remoteId":"87f82d5d-d89a-440d-8c23-ace5160a0739"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/87f82d5d-d89a-440d-8c23-ace5160a0739?source=api-prod","cve":"CVE-2026-4109","affectedVersions":"<=4.1.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/9e0d441d-1da5-45e7-8a14-ce178099c0cc/wp-event-solution","title":"Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"9e0d441d-1da5-45e7-8a14-ce178099c0cc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9e0d441d-1da5-45e7-8a14-ce178099c0cc?source=api-prod","cve":"CVE-2025-4796","affectedVersions":"<=4.0.34","severity":"high"},{"advisoryId":"WPSECADV/WF/a73f806d-5d64-4df5-b032-3d3a149036ff/wp-event-solution","title":"Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin <= 4.0.37 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-22 17:41:53","sources":[{"name":"Wordfence","remoteId":"a73f806d-5d64-4df5-b032-3d3a149036ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a73f806d-5d64-4df5-b032-3d3a149036ff?source=api-prod","cve":"CVE-2025-7813","affectedVersions":"<=4.0.37","severity":"high"},{"advisoryId":"WPSECADV/WF/b5451529-2e3f-414e-884e-cc6761431262/wp-event-solution","title":"Eventin <= 4.0.5 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"b5451529-2e3f-414e-884e-cc6761431262"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b5451529-2e3f-414e-884e-cc6761431262?source=api-prod","cve":"CVE-2024-39648","affectedVersions":"<=4.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/d203f477-ca42-40a2-842e-9af98dd9d410/wp-event-solution","title":"Eventin <= 4.0.28 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"d203f477-ca42-40a2-842e-9af98dd9d410"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d203f477-ca42-40a2-842e-9af98dd9d410?source=api-prod","cve":"CVE-2025-49321","affectedVersions":"<=4.0.28","severity":"medium"},{"advisoryId":"WPSECADV/WF/d6f3de97-5b87-49e4-9239-f405f72b893a/wp-event-solution","title":"Eventin <= 3.3.57 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"d6f3de97-5b87-49e4-9239-f405f72b893a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d6f3de97-5b87-49e4-9239-f405f72b893a?source=api-prod","cve":"CVE-2024-37507","affectedVersions":"<=3.3.57","severity":"medium"},{"advisoryId":"WPSECADV/WF/e4188b26-80f8-41b8-be19-1ddcbd7e39f5/wp-event-solution","title":"Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) <= 4.0.51 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via 'post_settings'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 18:45:19","sources":[{"name":"Wordfence","remoteId":"e4188b26-80f8-41b8-be19-1ddcbd7e39f5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e4188b26-80f8-41b8-be19-1ddcbd7e39f5?source=api-prod","cve":"CVE-2025-14657","affectedVersions":"<=4.0.51","severity":"high"},{"advisoryId":"WPSECADV/WF/e5b01e96-63e6-4ba0-8c83-f9b05e4050b3/wp-event-solution","title":"Eventin <= 4.0.7 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"e5b01e96-63e6-4ba0-8c83-f9b05e4050b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e5b01e96-63e6-4ba0-8c83-f9b05e4050b3?source=api-prod","cve":"CVE-2024-56213","affectedVersions":"<=4.0.7","severity":"high"},{"advisoryId":"WPSECADV/WF/f256036d-11e8-4311-baa0-d15193c72da0/wp-event-solution","title":"Eventin <= 3.3.52 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"f256036d-11e8-4311-baa0-d15193c72da0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f256036d-11e8-4311-baa0-d15193c72da0?source=api-prod","cve":"CVE-2023-49756","affectedVersions":"<=3.3.52","severity":"medium"},{"advisoryId":"WPSECADV/WF/f2bcaff9-bf04-4d8e-9422-c433264067ff/wp-event-solution","title":"Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-19 17:03:39","sources":[{"name":"Wordfence","remoteId":"f2bcaff9-bf04-4d8e-9422-c433264067ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2bcaff9-bf04-4d8e-9422-c433264067ff?source=api-prod","cve":"CVE-2025-1766","affectedVersions":"<=4.0.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/fa098a19-6984-4eeb-b8cd-178d0e41e005/wp-event-solution","title":"Eventin <= 4.1.3 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"fa098a19-6984-4eeb-b8cd-178d0e41e005"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fa098a19-6984-4eeb-b8cd-178d0e41e005?source=api-prod","cve":"CVE-2025-68047","affectedVersions":"<=4.1.3","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0cbdf679-1657-4249-a433-8fe0cddd94be/wp-event-solution","title":"Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin <= 3.3.50 - Missing Authorization to Unauthenticated Events Export\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"0cbdf679-1657-4249-a433-8fe0cddd94be"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0cbdf679-1657-4249-a433-8fe0cddd94be?source=api-prod","cve":"CVE-2024-1122","affectedVersions":"<=3.3.50","severity":"medium"},{"advisoryId":"WPSECADV/WF/1479071c-85c3-41fd-8ad7-f0dee32f201b/wp-event-solution","title":"Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 16:25:44","sources":[{"name":"Wordfence","remoteId":"1479071c-85c3-41fd-8ad7-f0dee32f201b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1479071c-85c3-41fd-8ad7-f0dee32f201b?source=api-prod","cve":"CVE-2025-3419","affectedVersions":"<=4.0.26","severity":"high"},{"advisoryId":"WPSECADV/WF/1725c7f3-2fac-4714-a63e-6c43694483fc/wp-event-solution","title":"Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Event Data Import\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"1725c7f3-2fac-4714-a63e-6c43694483fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1725c7f3-2fac-4714-a63e-6c43694483fc?source=api-prod","cve":"CVE-2024-6033","affectedVersions":"<=4.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/37d4d038-3f5c-4c4a-b5f1-3dd23a5b345e/wp-event-solution","title":"Eventin <= 4.0.25 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"37d4d038-3f5c-4c4a-b5f1-3dd23a5b345e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/37d4d038-3f5c-4c4a-b5f1-3dd23a5b345e?source=api-prod","cve":"CVE-2025-39584","affectedVersions":"<=4.0.25","severity":"high"},{"advisoryId":"WPSECADV/WF/3ad2651c-5541-4508-9da1-37838a4df901/wp-event-solution","title":"Eventin <= 4.0.31 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"3ad2651c-5541-4508-9da1-37838a4df901"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3ad2651c-5541-4508-9da1-37838a4df901?source=api-prod","cve":"CVE-2025-49869","affectedVersions":"<=4.0.31","severity":"high"},{"advisoryId":"WPSECADV/WF/4bbb0146-436f-42fa-802b-cdcf39ae97db/wp-event-solution","title":"Eventin <= 4.0.26 - Missing Authorization to Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"4bbb0146-436f-42fa-802b-cdcf39ae97db"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4bbb0146-436f-42fa-802b-cdcf39ae97db?source=api-prod","cve":"CVE-2025-47539","affectedVersions":"<=4.0.26","severity":"critical"},{"advisoryId":"WPSECADV/WF/5f24baee-7003-449b-9072-d95fa1e26c8f/wp-event-solution","title":"Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-19 17:03:49","sources":[{"name":"Wordfence","remoteId":"5f24baee-7003-449b-9072-d95fa1e26c8f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5f24baee-7003-449b-9072-d95fa1e26c8f?source=api-prod","cve":"CVE-2025-1770","affectedVersions":"<=4.0.24","severity":"high"},{"advisoryId":"WPSECADV/WF/70408046-5eb5-4217-9db4-e7b2a7809cf8/wp-event-solution","title":"Eventin <= 4.0.20 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"70408046-5eb5-4217-9db4-e7b2a7809cf8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/70408046-5eb5-4217-9db4-e7b2a7809cf8?source=api-prod","cve":"CVE-2025-26964","affectedVersions":"<=4.0.20","severity":"high"},{"advisoryId":"WPSECADV/WF/75537b61-5622-4b35-b80e-389526bd99f0/wp-event-solution","title":"Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"75537b61-5622-4b35-b80e-389526bd99f0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/75537b61-5622-4b35-b80e-389526bd99f0?source=api-prod","cve":"CVE-2024-7149","affectedVersions":"<=4.0.8","severity":"high"},{"advisoryId":"WPSECADV/WF/87f82d5d-d89a-440d-8c23-ace5160a0739/wp-event-solution","title":"Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-13 18:46:40","sources":[{"name":"Wordfence","remoteId":"87f82d5d-d89a-440d-8c23-ace5160a0739"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/87f82d5d-d89a-440d-8c23-ace5160a0739?source=api-prod","cve":"CVE-2026-4109","affectedVersions":"<=4.1.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/9e0d441d-1da5-45e7-8a14-ce178099c0cc/wp-event-solution","title":"Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"9e0d441d-1da5-45e7-8a14-ce178099c0cc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9e0d441d-1da5-45e7-8a14-ce178099c0cc?source=api-prod","cve":"CVE-2025-4796","affectedVersions":"<=4.0.34","severity":"high"},{"advisoryId":"WPSECADV/WF/a73f806d-5d64-4df5-b032-3d3a149036ff/wp-event-solution","title":"Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin <= 4.0.37 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-22 17:41:53","sources":[{"name":"Wordfence","remoteId":"a73f806d-5d64-4df5-b032-3d3a149036ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a73f806d-5d64-4df5-b032-3d3a149036ff?source=api-prod","cve":"CVE-2025-7813","affectedVersions":"<=4.0.37","severity":"high"},{"advisoryId":"WPSECADV/WF/b5451529-2e3f-414e-884e-cc6761431262/wp-event-solution","title":"Eventin <= 4.0.5 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"b5451529-2e3f-414e-884e-cc6761431262"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b5451529-2e3f-414e-884e-cc6761431262?source=api-prod","cve":"CVE-2024-39648","affectedVersions":"<=4.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/d203f477-ca42-40a2-842e-9af98dd9d410/wp-event-solution","title":"Eventin <= 4.0.28 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"d203f477-ca42-40a2-842e-9af98dd9d410"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d203f477-ca42-40a2-842e-9af98dd9d410?source=api-prod","cve":"CVE-2025-49321","affectedVersions":"<=4.0.28","severity":"medium"},{"advisoryId":"WPSECADV/WF/d6f3de97-5b87-49e4-9239-f405f72b893a/wp-event-solution","title":"Eventin <= 3.3.57 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"d6f3de97-5b87-49e4-9239-f405f72b893a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d6f3de97-5b87-49e4-9239-f405f72b893a?source=api-prod","cve":"CVE-2024-37507","affectedVersions":"<=3.3.57","severity":"medium"},{"advisoryId":"WPSECADV/WF/dfb7636b-2f4d-4a82-bd63-fea32668530e/wp-event-solution","title":"Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"dfb7636b-2f4d-4a82-bd63-fea32668530e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dfb7636b-2f4d-4a82-bd63-fea32668530e?source=api-prod","cve":"CVE-2026-40776","affectedVersions":"<=4.1.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/e4188b26-80f8-41b8-be19-1ddcbd7e39f5/wp-event-solution","title":"Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) <= 4.0.51 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via 'post_settings'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 18:45:19","sources":[{"name":"Wordfence","remoteId":"e4188b26-80f8-41b8-be19-1ddcbd7e39f5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e4188b26-80f8-41b8-be19-1ddcbd7e39f5?source=api-prod","cve":"CVE-2025-14657","affectedVersions":"<=4.0.51","severity":"high"},{"advisoryId":"WPSECADV/WF/e5b01e96-63e6-4ba0-8c83-f9b05e4050b3/wp-event-solution","title":"Eventin <= 4.0.7 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"e5b01e96-63e6-4ba0-8c83-f9b05e4050b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e5b01e96-63e6-4ba0-8c83-f9b05e4050b3?source=api-prod","cve":"CVE-2024-56213","affectedVersions":"<=4.0.7","severity":"high"},{"advisoryId":"WPSECADV/WF/f256036d-11e8-4311-baa0-d15193c72da0/wp-event-solution","title":"Eventin <= 3.3.52 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"f256036d-11e8-4311-baa0-d15193c72da0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f256036d-11e8-4311-baa0-d15193c72da0?source=api-prod","cve":"CVE-2023-49756","affectedVersions":"<=3.3.52","severity":"medium"},{"advisoryId":"WPSECADV/WF/f2bcaff9-bf04-4d8e-9422-c433264067ff/wp-event-solution","title":"Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-19 17:03:39","sources":[{"name":"Wordfence","remoteId":"f2bcaff9-bf04-4d8e-9422-c433264067ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2bcaff9-bf04-4d8e-9422-c433264067ff?source=api-prod","cve":"CVE-2025-1766","affectedVersions":"<=4.0.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/fa098a19-6984-4eeb-b8cd-178d0e41e005/wp-event-solution","title":"Eventin <= 4.1.3 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"fa098a19-6984-4eeb-b8cd-178d0e41e005"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fa098a19-6984-4eeb-b8cd-178d0e41e005?source=api-prod","cve":"CVE-2025-68047","affectedVersions":"<=4.1.3","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77702d6a6f622d6d616e61676572811c9dc5_gen.json b/internal/data/assets/plugin_77702d6a6f622d6d616e61676572811c9dc5_gen.json index 33acf54a..1c8cdc7e 100644 --- a/internal/data/assets/plugin_77702d6a6f622d6d616e61676572811c9dc5_gen.json +++ b/internal/data/assets/plugin_77702d6a6f622d6d616e61676572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/3099875e-ed6e-4d59-9da2-48fb389112ef/wp-job-manager","title":"Job Manager <= 2.4.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"3099875e-ed6e-4d59-9da2-48fb389112ef"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3099875e-ed6e-4d59-9da2-48fb389112ef?source=api-prod","cve":"CVE-2026-39660","affectedVersions":"<=2.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/61e6db2f-5dfd-44ef-9500-9f0cb5cd67ba/wp-job-manager","title":"WP Job Manager <= 1.29.2 - PHP Object Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"61e6db2f-5dfd-44ef-9500-9f0cb5cd67ba"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/61e6db2f-5dfd-44ef-9500-9f0cb5cd67ba?source=api-prod","affectedVersions":"<=1.29.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/69430e1a-db2f-4715-84aa-5a1dfd712180/wp-job-manager","title":"WP Job Manager <= 2.0.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"69430e1a-db2f-4715-84aa-5a1dfd712180"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/69430e1a-db2f-4715-84aa-5a1dfd712180?source=api-prod","cve":"CVE-2023-52212","affectedVersions":"<=2.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/696d5fe3-1344-461b-a26f-e5099a836c33/wp-job-manager","title":"WP Job Manager < 1.23.8 - Multiple Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-08-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"696d5fe3-1344-461b-a26f-e5099a836c33"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/696d5fe3-1344-461b-a26f-e5099a836c33?source=api-prod","affectedVersions":"<1.23.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/6d53cd00-3d7b-4096-bc25-354fd4020f8b/wp-job-manager","title":"WP Job Manager <= 2.2.2 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"6d53cd00-3d7b-4096-bc25-354fd4020f8b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6d53cd00-3d7b-4096-bc25-354fd4020f8b?source=api-prod","cve":"CVE-2024-34549","affectedVersions":"<=2.2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/8b1af76a-3836-4527-9ea6-8bffa173a84e/wp-job-manager","title":"WP Job Manager <= 2.0.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"8b1af76a-3836-4527-9ea6-8bffa173a84e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8b1af76a-3836-4527-9ea6-8bffa173a84e?source=api-prod","cve":"CVE-2023-52211","affectedVersions":"<=2.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/b96f40fe-3ffa-4fc5-b51a-ff3771224bd5/wp-job-manager","title":"WP Job Manager <= 1.31.2 - PHP Object Injection via PHAR Deserialization\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-01-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"b96f40fe-3ffa-4fc5-b51a-ff3771224bd5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b96f40fe-3ffa-4fc5-b51a-ff3771224bd5?source=api-prod","affectedVersions":"<1.31.3","severity":"high"},{"advisoryId":"WPSECADV/WF/d8029737-f3ad-4025-948a-ba0298c0869d/wp-job-manager","title":"WP Job Manager <= 1.26.1 - Arbitrary File Upload\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"d8029737-f3ad-4025-948a-ba0298c0869d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d8029737-f3ad-4025-948a-ba0298c0869d?source=api-prod","affectedVersions":"<1.26.2","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/3099875e-ed6e-4d59-9da2-48fb389112ef/wp-job-manager","title":"Job Manager <= 2.4.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"3099875e-ed6e-4d59-9da2-48fb389112ef"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3099875e-ed6e-4d59-9da2-48fb389112ef?source=api-prod","cve":"CVE-2026-39660","affectedVersions":"<=2.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/61e6db2f-5dfd-44ef-9500-9f0cb5cd67ba/wp-job-manager","title":"WP Job Manager <= 1.29.2 - PHP Object Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2018-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"61e6db2f-5dfd-44ef-9500-9f0cb5cd67ba"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/61e6db2f-5dfd-44ef-9500-9f0cb5cd67ba?source=api-prod","affectedVersions":"<=1.29.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/69430e1a-db2f-4715-84aa-5a1dfd712180/wp-job-manager","title":"WP Job Manager <= 2.0.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"69430e1a-db2f-4715-84aa-5a1dfd712180"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/69430e1a-db2f-4715-84aa-5a1dfd712180?source=api-prod","cve":"CVE-2023-52212","affectedVersions":"<=2.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/696d5fe3-1344-461b-a26f-e5099a836c33/wp-job-manager","title":"WP Job Manager < 1.23.8 - Multiple Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-08-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"696d5fe3-1344-461b-a26f-e5099a836c33"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/696d5fe3-1344-461b-a26f-e5099a836c33?source=api-prod","affectedVersions":"<1.23.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/6d53cd00-3d7b-4096-bc25-354fd4020f8b/wp-job-manager","title":"WP Job Manager <= 2.2.2 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"6d53cd00-3d7b-4096-bc25-354fd4020f8b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6d53cd00-3d7b-4096-bc25-354fd4020f8b?source=api-prod","cve":"CVE-2024-34549","affectedVersions":"<=2.2.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/8b1af76a-3836-4527-9ea6-8bffa173a84e/wp-job-manager","title":"WP Job Manager <= 2.0.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"8b1af76a-3836-4527-9ea6-8bffa173a84e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8b1af76a-3836-4527-9ea6-8bffa173a84e?source=api-prod","cve":"CVE-2023-52211","affectedVersions":"<=2.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/a4f8585b-5d69-4ef9-a49c-70f59a392ef9/wp-job-manager","title":"WP Job Manager <= 2.4.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"a4f8585b-5d69-4ef9-a49c-70f59a392ef9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4f8585b-5d69-4ef9-a49c-70f59a392ef9?source=api-prod","cve":"CVE-2026-25404","affectedVersions":"<=2.4.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/b96f40fe-3ffa-4fc5-b51a-ff3771224bd5/wp-job-manager","title":"WP Job Manager <= 1.31.2 - PHP Object Injection via PHAR Deserialization\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-01-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"b96f40fe-3ffa-4fc5-b51a-ff3771224bd5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b96f40fe-3ffa-4fc5-b51a-ff3771224bd5?source=api-prod","affectedVersions":"<1.31.3","severity":"high"},{"advisoryId":"WPSECADV/WF/d8029737-f3ad-4025-948a-ba0298c0869d/wp-job-manager","title":"WP Job Manager <= 1.26.1 - Arbitrary File Upload\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"d8029737-f3ad-4025-948a-ba0298c0869d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d8029737-f3ad-4025-948a-ba0298c0869d?source=api-prod","affectedVersions":"<1.26.2","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77702d6d6574612d646174612d66696c7465722d616e642d7461786f6e6f6d792d66696c746572811c9dc5_gen.json b/internal/data/assets/plugin_77702d6d6574612d646174612d66696c7465722d616e642d7461786f6e6f6d792d66696c746572811c9dc5_gen.json index b76045c6..f03288b7 100644 --- a/internal/data/assets/plugin_77702d6d6574612d646174612d66696c7465722d616e642d7461786f6e6f6d792d66696c746572811c9dc5_gen.json +++ b/internal/data/assets/plugin_77702d6d6574612d646174612d66696c7465722d616e642d7461786f6e6f6d792d66696c746572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/09bc815e-cf79-4d94-a934-366c251be551/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"09bc815e-cf79-4d94-a934-366c251be551"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/09bc815e-cf79-4d94-a934-366c251be551?source=api-prod","cve":"CVE-2024-32818","affectedVersions":"<=1.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/0a77ea13-5ac2-427a-8e1c-a5fa29c9f2dc/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF <= 1.3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"0a77ea13-5ac2-427a-8e1c-a5fa29c9f2dc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0a77ea13-5ac2-427a-8e1c-a5fa29c9f2dc?source=api-prod","cve":"CVE-2025-62069","affectedVersions":"<=1.3.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/325298a6-954b-4cf7-a96a-9571cdb0b5a5/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.1 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"325298a6-954b-4cf7-a96a-9571cdb0b5a5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/325298a6-954b-4cf7-a96a-9571cdb0b5a5?source=api-prod","cve":"CVE-2024-30457","affectedVersions":"<=1.3.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/4da52b6a-38dd-4a66-bcaf-8a77f96377fe/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"4da52b6a-38dd-4a66-bcaf-8a77f96377fe"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4da52b6a-38dd-4a66-bcaf-8a77f96377fe?source=api-prod","cve":"CVE-2026-32455","affectedVersions":"<=1.3.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/6edb6604-9da8-421e-933b-bac02b179bd0/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.0.1 - Relected Cross-Site Scripting via 'tax_name'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"6edb6604-9da8-421e-933b-bac02b179bd0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6edb6604-9da8-421e-933b-bac02b179bd0?source=api-prod","cve":"CVE-2023-28664","affectedVersions":"<=1.3.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/77b7fb02-1b79-4b0b-99ab-fa042e86391a/wp-meta-data-filter-and-taxonomy-filter","title":"Meta Data Filter & Taxonomies Filter <= 1.2.7.2 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"77b7fb02-1b79-4b0b-99ab-fa042e86391a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/77b7fb02-1b79-4b0b-99ab-fa042e86391a?source=api-prod","cve":"CVE-2021-20781","affectedVersions":"<2.2.8","severity":"high"},{"advisoryId":"WPSECADV/WF/7a5ab5f1-db14-4448-9186-35a5f382cd1a/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"7a5ab5f1-db14-4448-9186-35a5f382cd1a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7a5ab5f1-db14-4448-9186-35a5f382cd1a?source=api-prod","affectedVersions":"<=1.3.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8c44361b-dbc5-4534-a1a7-416a47ebabe4/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.4 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"8c44361b-dbc5-4534-a1a7-416a47ebabe4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c44361b-dbc5-4534-a1a7-416a47ebabe4?source=api-prod","cve":"CVE-2024-50450","affectedVersions":"<=1.3.3.4","severity":"high"},{"advisoryId":"WPSECADV/WF/8f50812a-c6a7-4bb3-9833-e10acd0460c0/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.3.3 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"8f50812a-c6a7-4bb3-9833-e10acd0460c0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8f50812a-c6a7-4bb3-9833-e10acd0460c0?source=api-prod","cve":"CVE-2024-8624","affectedVersions":"<=1.3.3.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/999d1df5-9c8e-46bd-bf95-9240cd6594ed/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"999d1df5-9c8e-46bd-bf95-9240cd6594ed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/999d1df5-9c8e-46bd-bf95-9240cd6594ed?source=api-prod","cve":"CVE-2024-50451","affectedVersions":"<=1.3.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/a6505b91-ffca-4ec4-9fd5-a9a5adbd2b0e/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF <= 1.3.3.7 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"a6505b91-ffca-4ec4-9fd5-a9a5adbd2b0e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a6505b91-ffca-4ec4-9fd5-a9a5adbd2b0e?source=api-prod","cve":"CVE-2025-54707","affectedVersions":"<=1.3.3.7","severity":"high"},{"advisoryId":"WPSECADV/WF/b097aade-fdfa-4fb0-9921-67b0fc544490/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF <= 1.3.3.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"b097aade-fdfa-4fb0-9921-67b0fc544490"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b097aade-fdfa-4fb0-9921-67b0fc544490?source=api-prod","cve":"CVE-2025-49907","affectedVersions":"<=1.3.3.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/b1f482d3-d2f6-4161-8bcf-3d43d5ac10ee/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"b1f482d3-d2f6-4161-8bcf-3d43d5ac10ee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b1f482d3-d2f6-4161-8bcf-3d43d5ac10ee?source=api-prod","cve":"CVE-2024-29763","affectedVersions":"<=1.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/b3da58a5-3b07-4c53-ae20-35b3d7750023/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.2 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"b3da58a5-3b07-4c53-ae20-35b3d7750023"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b3da58a5-3b07-4c53-ae20-35b3d7750023?source=api-prod","cve":"CVE-2024-34434","affectedVersions":"<=1.3.3.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/ba584e02-5242-4869-a452-21e6b8995bd8/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.3.3 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"ba584e02-5242-4869-a452-21e6b8995bd8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ba584e02-5242-4869-a452-21e6b8995bd8?source=api-prod","cve":"CVE-2024-8623","affectedVersions":"<=1.3.3.3","severity":"high"},{"advisoryId":"WPSECADV/WF/c33b51bb-d368-4056-97f2-03543c4e9f8c/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"c33b51bb-d368-4056-97f2-03543c4e9f8c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c33b51bb-d368-4056-97f2-03543c4e9f8c?source=api-prod","cve":"CVE-2024-29906","affectedVersions":"<=1.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/d2ead824-2722-4b09-8387-e064dee371c1/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.3.5 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"d2ead824-2722-4b09-8387-e064dee371c1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d2ead824-2722-4b09-8387-e064dee371c1?source=api-prod","cve":"CVE-2024-12030","affectedVersions":"<=1.3.3.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/d338b583-4587-4b8d-b78e-a1b9a1054435/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d338b583-4587-4b8d-b78e-a1b9a1054435"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d338b583-4587-4b8d-b78e-a1b9a1054435?source=api-prod","cve":"CVE-2024-29932","affectedVersions":"<=1.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e62e77b2-0fc9-4a6b-a0e2-8858dbf9d8a1/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF <= 1.3.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"e62e77b2-0fc9-4a6b-a0e2-8858dbf9d8a1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e62e77b2-0fc9-4a6b-a0e2-8858dbf9d8a1?source=api-prod","cve":"CVE-2025-62964","affectedVersions":"<=1.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/fcaeae5b-4047-4f09-8197-6ce2c21cc812/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-22 21:28:11","sources":[{"name":"Wordfence","remoteId":"fcaeae5b-4047-4f09-8197-6ce2c21cc812"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fcaeae5b-4047-4f09-8197-6ce2c21cc812?source=api-prod","cve":"CVE-2024-13340","affectedVersions":"<=1.3.3.6","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/09bc815e-cf79-4d94-a934-366c251be551/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"09bc815e-cf79-4d94-a934-366c251be551"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/09bc815e-cf79-4d94-a934-366c251be551?source=api-prod","cve":"CVE-2024-32818","affectedVersions":"<=1.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/0a77ea13-5ac2-427a-8e1c-a5fa29c9f2dc/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF <= 1.3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"0a77ea13-5ac2-427a-8e1c-a5fa29c9f2dc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0a77ea13-5ac2-427a-8e1c-a5fa29c9f2dc?source=api-prod","cve":"CVE-2025-62069","affectedVersions":"<=1.3.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/325298a6-954b-4cf7-a96a-9571cdb0b5a5/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.1 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"325298a6-954b-4cf7-a96a-9571cdb0b5a5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/325298a6-954b-4cf7-a96a-9571cdb0b5a5?source=api-prod","cve":"CVE-2024-30457","affectedVersions":"<=1.3.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/4da52b6a-38dd-4a66-bcaf-8a77f96377fe/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"4da52b6a-38dd-4a66-bcaf-8a77f96377fe"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4da52b6a-38dd-4a66-bcaf-8a77f96377fe?source=api-prod","cve":"CVE-2026-32455","affectedVersions":"<=1.3.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/6edb6604-9da8-421e-933b-bac02b179bd0/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.0.1 - Relected Cross-Site Scripting via 'tax_name'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"6edb6604-9da8-421e-933b-bac02b179bd0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6edb6604-9da8-421e-933b-bac02b179bd0?source=api-prod","cve":"CVE-2023-28664","affectedVersions":"<=1.3.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/77b7fb02-1b79-4b0b-99ab-fa042e86391a/wp-meta-data-filter-and-taxonomy-filter","title":"Meta Data Filter & Taxonomies Filter <= 1.2.7.2 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"77b7fb02-1b79-4b0b-99ab-fa042e86391a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/77b7fb02-1b79-4b0b-99ab-fa042e86391a?source=api-prod","cve":"CVE-2021-20781","affectedVersions":"<2.2.8","severity":"high"},{"advisoryId":"WPSECADV/WF/7a5ab5f1-db14-4448-9186-35a5f382cd1a/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"7a5ab5f1-db14-4448-9186-35a5f382cd1a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7a5ab5f1-db14-4448-9186-35a5f382cd1a?source=api-prod","affectedVersions":"<=1.3.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8c44361b-dbc5-4534-a1a7-416a47ebabe4/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.4 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"8c44361b-dbc5-4534-a1a7-416a47ebabe4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c44361b-dbc5-4534-a1a7-416a47ebabe4?source=api-prod","cve":"CVE-2024-50450","affectedVersions":"<=1.3.3.4","severity":"high"},{"advisoryId":"WPSECADV/WF/8f50812a-c6a7-4bb3-9833-e10acd0460c0/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.3.3 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"8f50812a-c6a7-4bb3-9833-e10acd0460c0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8f50812a-c6a7-4bb3-9833-e10acd0460c0?source=api-prod","cve":"CVE-2024-8624","affectedVersions":"<=1.3.3.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/999d1df5-9c8e-46bd-bf95-9240cd6594ed/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"999d1df5-9c8e-46bd-bf95-9240cd6594ed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/999d1df5-9c8e-46bd-bf95-9240cd6594ed?source=api-prod","cve":"CVE-2024-50451","affectedVersions":"<=1.3.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/a6505b91-ffca-4ec4-9fd5-a9a5adbd2b0e/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF <= 1.3.3.7 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"a6505b91-ffca-4ec4-9fd5-a9a5adbd2b0e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a6505b91-ffca-4ec4-9fd5-a9a5adbd2b0e?source=api-prod","cve":"CVE-2025-54707","affectedVersions":"<=1.3.3.7","severity":"high"},{"advisoryId":"WPSECADV/WF/b097aade-fdfa-4fb0-9921-67b0fc544490/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF <= 1.3.3.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"b097aade-fdfa-4fb0-9921-67b0fc544490"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b097aade-fdfa-4fb0-9921-67b0fc544490?source=api-prod","cve":"CVE-2025-49907","affectedVersions":"<=1.3.3.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/b1f482d3-d2f6-4161-8bcf-3d43d5ac10ee/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"b1f482d3-d2f6-4161-8bcf-3d43d5ac10ee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b1f482d3-d2f6-4161-8bcf-3d43d5ac10ee?source=api-prod","cve":"CVE-2024-29763","affectedVersions":"<=1.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/b3da58a5-3b07-4c53-ae20-35b3d7750023/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.2 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"b3da58a5-3b07-4c53-ae20-35b3d7750023"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b3da58a5-3b07-4c53-ae20-35b3d7750023?source=api-prod","cve":"CVE-2024-34434","affectedVersions":"<=1.3.3.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/ba584e02-5242-4869-a452-21e6b8995bd8/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.3.3 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"ba584e02-5242-4869-a452-21e6b8995bd8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ba584e02-5242-4869-a452-21e6b8995bd8?source=api-prod","cve":"CVE-2024-8623","affectedVersions":"<=1.3.3.3","severity":"high"},{"advisoryId":"WPSECADV/WF/c33b51bb-d368-4056-97f2-03543c4e9f8c/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"c33b51bb-d368-4056-97f2-03543c4e9f8c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c33b51bb-d368-4056-97f2-03543c4e9f8c?source=api-prod","cve":"CVE-2024-29906","affectedVersions":"<=1.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/d2ead824-2722-4b09-8387-e064dee371c1/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.3.5 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"d2ead824-2722-4b09-8387-e064dee371c1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d2ead824-2722-4b09-8387-e064dee371c1?source=api-prod","cve":"CVE-2024-12030","affectedVersions":"<=1.3.3.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/d338b583-4587-4b8d-b78e-a1b9a1054435/wp-meta-data-filter-and-taxonomy-filter","title":"WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d338b583-4587-4b8d-b78e-a1b9a1054435"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d338b583-4587-4b8d-b78e-a1b9a1054435?source=api-prod","cve":"CVE-2024-29932","affectedVersions":"<=1.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e62e77b2-0fc9-4a6b-a0e2-8858dbf9d8a1/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF <= 1.3.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"e62e77b2-0fc9-4a6b-a0e2-8858dbf9d8a1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e62e77b2-0fc9-4a6b-a0e2-8858dbf9d8a1?source=api-prod","cve":"CVE-2025-62964","affectedVersions":"<=1.3.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/fcaeae5b-4047-4f09-8197-6ce2c21cc812/wp-meta-data-filter-and-taxonomy-filter","title":"MDTF – Meta Data and Taxonomies Filter <= 1.3.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-22 21:28:11","sources":[{"name":"Wordfence","remoteId":"fcaeae5b-4047-4f09-8197-6ce2c21cc812"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fcaeae5b-4047-4f09-8197-6ce2c21cc812?source=api-prod","cve":"CVE-2024-13340","affectedVersions":"<=1.3.3.6","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77702d7061796d656e742d666f726d811c9dc5_gen.json b/internal/data/assets/plugin_77702d7061796d656e742d666f726d811c9dc5_gen.json index cc2931e9..0b3d06f4 100644 --- a/internal/data/assets/plugin_77702d7061796d656e742d666f726d811c9dc5_gen.json +++ b/internal/data/assets/plugin_77702d7061796d656e742d666f726d811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/a453a38f-0ef5-446b-886f-c208c1baa648/wp-payment-form","title":"Simple Payment Donations <= 4.2.0 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"a453a38f-0ef5-446b-886f-c208c1baa648"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a453a38f-0ef5-446b-886f-c208c1baa648?source=api-prod","cve":"CVE-2022-2565","affectedVersions":"<=4.2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/cffe745d-2fe2-4959-9641-9a0ae33bff4c/wp-payment-form","title":"Simple Payment Donations <= 4.2.0 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"cffe745d-2fe2-4959-9641-9a0ae33bff4c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cffe745d-2fe2-4959-9641-9a0ae33bff4c?source=api-prod","affectedVersions":"<=4.2.0","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/a453a38f-0ef5-446b-886f-c208c1baa648/wp-payment-form","title":"Simple Payment Donations <= 4.2.0 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"a453a38f-0ef5-446b-886f-c208c1baa648"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a453a38f-0ef5-446b-886f-c208c1baa648?source=api-prod","cve":"CVE-2022-2565","affectedVersions":"<=4.2.0","severity":"high"},{"advisoryId":"WPSECADV/WF/cffe745d-2fe2-4959-9641-9a0ae33bff4c/wp-payment-form","title":"Simple Payment Donations <= 4.2.0 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"cffe745d-2fe2-4959-9641-9a0ae33bff4c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cffe745d-2fe2-4959-9641-9a0ae33bff4c?source=api-prod","affectedVersions":"<=4.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e60cd9eb-5707-493d-8f3a-3d4160e14735/wp-payment-form","title":"Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management <= 4.6.19 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"e60cd9eb-5707-493d-8f3a-3d4160e14735"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e60cd9eb-5707-493d-8f3a-3d4160e14735?source=api-prod","cve":"CVE-2026-42655","affectedVersions":"<=4.6.19","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77702d726f636b6574811c9dc5_gen.json b/internal/data/assets/plugin_77702d726f636b6574811c9dc5_gen.json index e1c66e2e..dfb08eff 100644 --- a/internal/data/assets/plugin_77702d726f636b6574811c9dc5_gen.json +++ b/internal/data/assets/plugin_77702d726f636b6574811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/9167e4bd-74be-46c9-b06e-566c13c02c7d/wp-rocket","title":"WP Rocket <= 2.10.3 - Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-06-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"9167e4bd-74be-46c9-b06e-566c13c02c7d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9167e4bd-74be-46c9-b06e-566c13c02c7d?source=api-prod","cve":"CVE-2017-11658","affectedVersions":"<2.10.4","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/9167e4bd-74be-46c9-b06e-566c13c02c7d/wp-rocket","title":"WP Rocket <= 2.10.3 - Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-06-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"9167e4bd-74be-46c9-b06e-566c13c02c7d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9167e4bd-74be-46c9-b06e-566c13c02c7d?source=api-prod","cve":"CVE-2017-11658","affectedVersions":"<2.10.4","severity":"high"},{"advisoryId":"WPSECADV/WF/b258b76c-abb1-413e-a7b9-b9b0b71c1f82/wp-rocket","title":"Rocket <= 3.19.4 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"b258b76c-abb1-413e-a7b9-b9b0b71c1f82"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b258b76c-abb1-413e-a7b9-b9b0b71c1f82?source=api-prod","cve":"CVE-2026-28044","affectedVersions":"<=3.19.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7770626f6f6b69742d70726f811c9dc5_gen.json b/internal/data/assets/plugin_7770626f6f6b69742d70726f811c9dc5_gen.json index e6215b2e..d45b0236 100644 --- a/internal/data/assets/plugin_7770626f6f6b69742d70726f811c9dc5_gen.json +++ b/internal/data/assets/plugin_7770626f6f6b69742d70726f811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/553f2cd8-9868-4190-91ea-88e03b9ddc3d/wpbookit-pro","title":"WPBookit Pro <= 1.6.18 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"553f2cd8-9868-4190-91ea-88e03b9ddc3d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/553f2cd8-9868-4190-91ea-88e03b9ddc3d?source=api-prod","cve":"CVE-2026-25414","affectedVersions":"<=1.6.18","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/553f2cd8-9868-4190-91ea-88e03b9ddc3d/wpbookit-pro","title":"WPBookit Pro <= 1.6.18 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"553f2cd8-9868-4190-91ea-88e03b9ddc3d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/553f2cd8-9868-4190-91ea-88e03b9ddc3d?source=api-prod","cve":"CVE-2026-25414","affectedVersions":"<=1.6.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/91c79862-cf85-42ad-9996-f679edab678e/wpbookit-pro","title":"WPBookit Pro <= 1.6.18 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"91c79862-cf85-42ad-9996-f679edab678e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91c79862-cf85-42ad-9996-f679edab678e?source=api-prod","cve":"CVE-2026-25415","affectedVersions":"<=1.6.18","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_777070697a7a61811c9dc5_gen.json b/internal/data/assets/plugin_777070697a7a61811c9dc5_gen.json index 0b038214..360dbfdf 100644 --- a/internal/data/assets/plugin_777070697a7a61811c9dc5_gen.json +++ b/internal/data/assets/plugin_777070697a7a61811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/06efdaff-2a03-4a08-bb74-1fae183c5842/wppizza","title":"WPPizza <= 3.19.4 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"06efdaff-2a03-4a08-bb74-1fae183c5842"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/06efdaff-2a03-4a08-bb74-1fae183c5842?source=api-prod","cve":"CVE-2025-26991","affectedVersions":"<=3.19.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/1c3e1a05-ae8c-4438-afd9-d1d0a39484c2/wppizza","title":"WPPizza – A Restaurant Plugin <= 3.18.13 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c3e1a05-ae8c-4438-afd9-d1d0a39484c2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c3e1a05-ae8c-4438-afd9-d1d0a39484c2?source=api-prod","cve":"CVE-2024-35766","affectedVersions":"<=3.18.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/225ac126-7448-4faf-92c7-ee96831b272e/wppizza","title":"WPPizza <= 3.17.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"225ac126-7448-4faf-92c7-ee96831b272e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/225ac126-7448-4faf-92c7-ee96831b272e?source=api-prod","cve":"CVE-2023-32105","affectedVersions":"<=3.17.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/2cc5962f-4d3c-43ea-996b-a5bb3d0dccef/wppizza","title":"PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"2cc5962f-4d3c-43ea-996b-a5bb3d0dccef"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2cc5962f-4d3c-43ea-996b-a5bb3d0dccef?source=api-prod","cve":"CVE-2013-6837","affectedVersions":"<2.11.8.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/6f8437a8-a034-40b8-bc61-d5c495865cbd/wppizza","title":"WPPizza <= 3.19.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f8437a8-a034-40b8-bc61-d5c495865cbd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f8437a8-a034-40b8-bc61-d5c495865cbd?source=api-prod","cve":"CVE-2025-57894","affectedVersions":"<=3.19.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/ccfdb5f5-8417-44a3-a27c-157a9619c68b/wppizza","title":"WPPizza <= 3.18.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"ccfdb5f5-8417-44a3-a27c-157a9619c68b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ccfdb5f5-8417-44a3-a27c-157a9619c68b?source=api-prod","cve":"CVE-2023-46622","affectedVersions":"<=3.18.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/ecc00cbc-ec65-4664-8ec6-8cfb47196ec1/wppizza","title":"WPPizza <= 3.18.10 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"ecc00cbc-ec65-4664-8ec6-8cfb47196ec1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ecc00cbc-ec65-4664-8ec6-8cfb47196ec1?source=api-prod","cve":"CVE-2024-33576","affectedVersions":"<=3.18.10","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/06efdaff-2a03-4a08-bb74-1fae183c5842/wppizza","title":"WPPizza <= 3.19.4 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"06efdaff-2a03-4a08-bb74-1fae183c5842"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/06efdaff-2a03-4a08-bb74-1fae183c5842?source=api-prod","cve":"CVE-2025-26991","affectedVersions":"<=3.19.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/1c3e1a05-ae8c-4438-afd9-d1d0a39484c2/wppizza","title":"WPPizza – A Restaurant Plugin <= 3.18.13 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c3e1a05-ae8c-4438-afd9-d1d0a39484c2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c3e1a05-ae8c-4438-afd9-d1d0a39484c2?source=api-prod","cve":"CVE-2024-35766","affectedVersions":"<=3.18.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/225ac126-7448-4faf-92c7-ee96831b272e/wppizza","title":"WPPizza <= 3.17.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"225ac126-7448-4faf-92c7-ee96831b272e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/225ac126-7448-4faf-92c7-ee96831b272e?source=api-prod","cve":"CVE-2023-32105","affectedVersions":"<=3.17.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/2cc5962f-4d3c-43ea-996b-a5bb3d0dccef/wppizza","title":"PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"2cc5962f-4d3c-43ea-996b-a5bb3d0dccef"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2cc5962f-4d3c-43ea-996b-a5bb3d0dccef?source=api-prod","cve":"CVE-2013-6837","affectedVersions":"<2.11.8.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/6f8437a8-a034-40b8-bc61-d5c495865cbd/wppizza","title":"WPPizza <= 3.19.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f8437a8-a034-40b8-bc61-d5c495865cbd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f8437a8-a034-40b8-bc61-d5c495865cbd?source=api-prod","cve":"CVE-2025-57894","affectedVersions":"<=3.19.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/ccfdb5f5-8417-44a3-a27c-157a9619c68b/wppizza","title":"WPPizza <= 3.18.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"ccfdb5f5-8417-44a3-a27c-157a9619c68b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ccfdb5f5-8417-44a3-a27c-157a9619c68b?source=api-prod","cve":"CVE-2023-46622","affectedVersions":"<=3.18.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/ecc00cbc-ec65-4664-8ec6-8cfb47196ec1/wppizza","title":"WPPizza <= 3.18.10 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"ecc00cbc-ec65-4664-8ec6-8cfb47196ec1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ecc00cbc-ec65-4664-8ec6-8cfb47196ec1?source=api-prod","cve":"CVE-2024-33576","affectedVersions":"<=3.18.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/eda25531-3f5f-4f66-8c6a-fcb17342eac0/wppizza","title":"WPPizza – A Restaurant Plugin <= 3.19.9 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"eda25531-3f5f-4f66-8c6a-fcb17342eac0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eda25531-3f5f-4f66-8c6a-fcb17342eac0?source=api-prod","cve":"CVE-2026-40796","affectedVersions":"<=3.19.9","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77707265736964656e63652d636f7265811c9dc5_gen.json b/internal/data/assets/plugin_77707265736964656e63652d636f7265811c9dc5_gen.json new file mode 100644 index 00000000..29ec52e1 --- /dev/null +++ b/internal/data/assets/plugin_77707265736964656e63652d636f7265811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/52eddb68-7b72-4c47-a365-0676970b5207/wpresidence-core","title":"Wpresidence Core <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"52eddb68-7b72-4c47-a365-0676970b5207"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/52eddb68-7b72-4c47-a365-0676970b5207?source=api-prod","cve":"CVE-2026-25463","affectedVersions":"<=5.4.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7961796d61696c811c9dc5_gen.json b/internal/data/assets/plugin_7961796d61696c811c9dc5_gen.json index bbe66125..16af04ef 100644 --- a/internal/data/assets/plugin_7961796d61696c811c9dc5_gen.json +++ b/internal/data/assets/plugin_7961796d61696c811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/5a17ded3-340d-494f-be7e-2550dab360bc/yaymail","title":"YayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update via 'yaymail_import_state' AJAX Action\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 18:41:54","sources":[{"name":"Wordfence","remoteId":"5a17ded3-340d-494f-be7e-2550dab360bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5a17ded3-340d-494f-be7e-2550dab360bc?source=api-prod","cve":"CVE-2026-1937","affectedVersions":"<=4.3.2","severity":"high"},{"advisoryId":"WPSECADV/WF/689878cd-3e25-49e9-9e85-28ecf5ed2e94/yaymail","title":"YayMail – WooCommerce Email Customizer <= 4.3.3 - Authenticated (Shop manager+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"689878cd-3e25-49e9-9e85-28ecf5ed2e94"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/689878cd-3e25-49e9-9e85-28ecf5ed2e94?source=api-prod","cve":"CVE-2026-39498","affectedVersions":"<=4.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/6ce57b12-2241-416b-b466-aa06ca8c7551/yaymail","title":"YayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) License Key Deletion via '/yaymail-license/v1/license/delete' Endpoint\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 19:00:00","sources":[{"name":"Wordfence","remoteId":"6ce57b12-2241-416b-b466-aa06ca8c7551"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6ce57b12-2241-416b-b466-aa06ca8c7551?source=api-prod","cve":"CVE-2026-1938","affectedVersions":"<=4.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/73b4e5a2-bf75-4df9-a816-2cc858947c39/yaymail","title":"YayMail <= 4.3.2 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via Template Elements\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 18:44:08","sources":[{"name":"Wordfence","remoteId":"73b4e5a2-bf75-4df9-a816-2cc858947c39"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/73b4e5a2-bf75-4df9-a816-2cc858947c39?source=api-prod","cve":"CVE-2026-1943","affectedVersions":"<=4.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/83c97e9b-a5bc-4059-8355-f93a7a36037c/yaymail","title":"YayMail <= 4.3.3 - Authenticated (Shop manager+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"83c97e9b-a5bc-4059-8355-f93a7a36037c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/83c97e9b-a5bc-4059-8355-f93a7a36037c?source=api-prod","cve":"CVE-2026-39496","affectedVersions":"<=4.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/a568162a-5a2d-47ab-9dfe-2f2f5f324f0d/yaymail","title":"YayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) Plugin Installation and Activation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 18:55:15","sources":[{"name":"Wordfence","remoteId":"a568162a-5a2d-47ab-9dfe-2f2f5f324f0d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a568162a-5a2d-47ab-9dfe-2f2f5f324f0d?source=api-prod","cve":"CVE-2026-1831","affectedVersions":"<=4.3.2","severity":"low"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/5a17ded3-340d-494f-be7e-2550dab360bc/yaymail","title":"YayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update via 'yaymail_import_state' AJAX Action\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 18:41:54","sources":[{"name":"Wordfence","remoteId":"5a17ded3-340d-494f-be7e-2550dab360bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5a17ded3-340d-494f-be7e-2550dab360bc?source=api-prod","cve":"CVE-2026-1937","affectedVersions":"<=4.3.2","severity":"high"},{"advisoryId":"WPSECADV/WF/689878cd-3e25-49e9-9e85-28ecf5ed2e94/yaymail","title":"YayMail – WooCommerce Email Customizer <= 4.3.3 - Authenticated (Shop manager+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"689878cd-3e25-49e9-9e85-28ecf5ed2e94"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/689878cd-3e25-49e9-9e85-28ecf5ed2e94?source=api-prod","cve":"CVE-2026-39498","affectedVersions":"<=4.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/6ce57b12-2241-416b-b466-aa06ca8c7551/yaymail","title":"YayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) License Key Deletion via '/yaymail-license/v1/license/delete' Endpoint\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 19:00:00","sources":[{"name":"Wordfence","remoteId":"6ce57b12-2241-416b-b466-aa06ca8c7551"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6ce57b12-2241-416b-b466-aa06ca8c7551?source=api-prod","cve":"CVE-2026-1938","affectedVersions":"<=4.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/73b4e5a2-bf75-4df9-a816-2cc858947c39/yaymail","title":"YayMail <= 4.3.2 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via Template Elements\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 18:44:08","sources":[{"name":"Wordfence","remoteId":"73b4e5a2-bf75-4df9-a816-2cc858947c39"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/73b4e5a2-bf75-4df9-a816-2cc858947c39?source=api-prod","cve":"CVE-2026-1943","affectedVersions":"<=4.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/83c97e9b-a5bc-4059-8355-f93a7a36037c/yaymail","title":"YayMail <= 4.3.3 - Authenticated (Shop manager+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"83c97e9b-a5bc-4059-8355-f93a7a36037c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/83c97e9b-a5bc-4059-8355-f93a7a36037c?source=api-prod","cve":"CVE-2026-39496","affectedVersions":"<=4.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/8c057b43-a544-4448-8370-697ad12b5e4b/yaymail","title":"YayMail – WooCommerce Email Customizer <= 4.3.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"8c057b43-a544-4448-8370-697ad12b5e4b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c057b43-a544-4448-8370-697ad12b5e4b?source=api-prod","cve":"CVE-2026-27327","affectedVersions":"<=4.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/a568162a-5a2d-47ab-9dfe-2f2f5f324f0d/yaymail","title":"YayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) Plugin Installation and Activation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-17 18:55:15","sources":[{"name":"Wordfence","remoteId":"a568162a-5a2d-47ab-9dfe-2f2f5f324f0d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a568162a-5a2d-47ab-9dfe-2f2f5f324f0d?source=api-prod","cve":"CVE-2026-1831","affectedVersions":"<=4.3.2","severity":"low"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_796974682d776f6f636f6d6d657263652d636f6d70617265811c9dc5_gen.json b/internal/data/assets/plugin_796974682d776f6f636f6d6d657263652d636f6d70617265811c9dc5_gen.json index 19fbdd88..4cb0a7e7 100644 --- a/internal/data/assets/plugin_796974682d776f6f636f6d6d657263652d636f6d70617265811c9dc5_gen.json +++ b/internal/data/assets/plugin_796974682d776f6f636f6d6d657263652d636f6d70617265811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/3b34a0c6-3573-48c7-8edb-c9cf9503da06/yith-woocommerce-compare","title":"YIT Plugin Framework <= 3.3.8 - Authenticated Settings Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-10-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"3b34a0c6-3573-48c7-8edb-c9cf9503da06"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3b34a0c6-3573-48c7-8edb-c9cf9503da06?source=api-prod","cve":"CVE-2019-16251","affectedVersions":"<=2.3.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/b948574a-0aab-4596-83e6-04be21f78bc1/yith-woocommerce-compare","title":"YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"b948574a-0aab-4596-83e6-04be21f78bc1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b948574a-0aab-4596-83e6-04be21f78bc1?source=api-prod","affectedVersions":"<=2.20.0","severity":"high"},{"advisoryId":"WPSECADV/WF/f002d061-4e9d-49be-9d4c-c470ec97f653/yith-woocommerce-compare","title":"YITH plugins by YITHEMES <= (Various Versions) - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"f002d061-4e9d-49be-9d4c-c470ec97f653"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f002d061-4e9d-49be-9d4c-c470ec97f653?source=api-prod","cve":"CVE-2022-44630","affectedVersions":"<=2.20.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/f822d5b9-46fb-4910-8d92-8c73e01d7e50/yith-woocommerce-compare","title":"YITH WooCommerce Compare <= 2.37.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"f822d5b9-46fb-4910-8d92-8c73e01d7e50"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f822d5b9-46fb-4910-8d92-8c73e01d7e50?source=api-prod","cve":"CVE-2024-32699","affectedVersions":"<=2.37.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/fe02377a-8d09-4d86-a049-3002516cf933/yith-woocommerce-compare","title":"YITH WooCommerce Compare <= 2.0.9 - Unauthenticated PHP Object Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"fe02377a-8d09-4d86-a049-3002516cf933"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fe02377a-8d09-4d86-a049-3002516cf933?source=api-prod","affectedVersions":"<=2.0.9","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/3b34a0c6-3573-48c7-8edb-c9cf9503da06/yith-woocommerce-compare","title":"YIT Plugin Framework <= 3.3.8 - Authenticated Settings Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-10-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"3b34a0c6-3573-48c7-8edb-c9cf9503da06"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3b34a0c6-3573-48c7-8edb-c9cf9503da06?source=api-prod","cve":"CVE-2019-16251","affectedVersions":"<=2.3.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/84467bda-aaf8-45df-b4cc-f7e08d0c3848/yith-woocommerce-compare","title":"YITH WooCommerce Compare <= 3.6.0 - Authenticated (Admin+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"84467bda-aaf8-45df-b4cc-f7e08d0c3848"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/84467bda-aaf8-45df-b4cc-f7e08d0c3848?source=api-prod","cve":"CVE-2026-22333","affectedVersions":"<=3.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/b948574a-0aab-4596-83e6-04be21f78bc1/yith-woocommerce-compare","title":"YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"b948574a-0aab-4596-83e6-04be21f78bc1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b948574a-0aab-4596-83e6-04be21f78bc1?source=api-prod","affectedVersions":"<=2.20.0","severity":"high"},{"advisoryId":"WPSECADV/WF/f002d061-4e9d-49be-9d4c-c470ec97f653/yith-woocommerce-compare","title":"YITH plugins by YITHEMES <= (Various Versions) - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"f002d061-4e9d-49be-9d4c-c470ec97f653"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f002d061-4e9d-49be-9d4c-c470ec97f653?source=api-prod","cve":"CVE-2022-44630","affectedVersions":"<=2.20.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/f822d5b9-46fb-4910-8d92-8c73e01d7e50/yith-woocommerce-compare","title":"YITH WooCommerce Compare <= 2.37.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"f822d5b9-46fb-4910-8d92-8c73e01d7e50"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f822d5b9-46fb-4910-8d92-8c73e01d7e50?source=api-prod","cve":"CVE-2024-32699","affectedVersions":"<=2.37.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/fe02377a-8d09-4d86-a049-3002516cf933/yith-woocommerce-compare","title":"YITH WooCommerce Compare <= 2.0.9 - Unauthenticated PHP Object Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"fe02377a-8d09-4d86-a049-3002516cf933"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fe02377a-8d09-4d86-a049-3002516cf933?source=api-prod","affectedVersions":"<=2.0.9","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7a696e676179612d636c69636b2d746f2d63616c6c811c9dc5_gen.json b/internal/data/assets/plugin_7a696e676179612d636c69636b2d746f2d63616c6c811c9dc5_gen.json new file mode 100644 index 00000000..01c284a1 --- /dev/null +++ b/internal/data/assets/plugin_7a696e676179612d636c69636b2d746f2d63616c6c811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/5bdd515c-6b52-467c-9446-6ae9b3b75e50/zingaya-click-to-call","title":"Zingaya Click-to-Call <= 1.0 - Reflected Cross-Site Scripting via 'email' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 14:07:29","sources":[{"name":"Wordfence","remoteId":"5bdd515c-6b52-467c-9446-6ae9b3b75e50"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5bdd515c-6b52-467c-9446-6ae9b3b75e50?source=api-prod","cve":"CVE-2026-6696","affectedVersions":"<=1.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7a6974612d736974652d6c696272617279811c9dc5_gen.json b/internal/data/assets/plugin_7a6974612d736974652d6c696272617279811c9dc5_gen.json index ddd1c4f2..d594738f 100644 --- a/internal/data/assets/plugin_7a6974612d736974652d6c696272617279811c9dc5_gen.json +++ b/internal/data/assets/plugin_7a6974612d736974652d6c696272617279811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/62bc3794-a2c2-4c1a-b1c9-2be6e2526635/zita-site-library","title":"Zita Elementor Site Library <= 1.6.2 - Missing Authorization to Page Creation and Options Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"62bc3794-a2c2-4c1a-b1c9-2be6e2526635"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62bc3794-a2c2-4c1a-b1c9-2be6e2526635?source=api-prod","cve":"CVE-2024-3249","affectedVersions":"<=1.6.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/6d9f5901-dc11-4877-b753-deb9c03f4a4e/zita-site-library","title":"Zita Elementor Site Library <= 1.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"6d9f5901-dc11-4877-b753-deb9c03f4a4e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6d9f5901-dc11-4877-b753-deb9c03f4a4e?source=api-prod","cve":"CVE-2024-37420","affectedVersions":"<=1.6.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/cc1c76ee-078d-4c9a-a4d3-063d9147d7e8/zita-site-library","title":"Zita Elementor Site Library <= 1.6.3 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-15 21:49:51","sources":[{"name":"Wordfence","remoteId":"cc1c76ee-078d-4c9a-a4d3-063d9147d7e8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc1c76ee-078d-4c9a-a4d3-063d9147d7e8?source=api-prod","cve":"CVE-2024-8921","affectedVersions":"<=1.6.3","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/3936dfb4-4f0f-4f97-bd66-df43dae93b5e/zita-site-library","title":"Zita Site Library for Elementor <= 1.6.6 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"3936dfb4-4f0f-4f97-bd66-df43dae93b5e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3936dfb4-4f0f-4f97-bd66-df43dae93b5e?source=api-prod","cve":"CVE-2026-25319","affectedVersions":"<=1.6.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/62bc3794-a2c2-4c1a-b1c9-2be6e2526635/zita-site-library","title":"Zita Elementor Site Library <= 1.6.2 - Missing Authorization to Page Creation and Options Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"62bc3794-a2c2-4c1a-b1c9-2be6e2526635"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62bc3794-a2c2-4c1a-b1c9-2be6e2526635?source=api-prod","cve":"CVE-2024-3249","affectedVersions":"<=1.6.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/6d9f5901-dc11-4877-b753-deb9c03f4a4e/zita-site-library","title":"Zita Elementor Site Library <= 1.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"6d9f5901-dc11-4877-b753-deb9c03f4a4e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6d9f5901-dc11-4877-b753-deb9c03f4a4e?source=api-prod","cve":"CVE-2024-37420","affectedVersions":"<=1.6.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/cc1c76ee-078d-4c9a-a4d3-063d9147d7e8/zita-site-library","title":"Zita Elementor Site Library <= 1.6.3 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-15 21:49:51","sources":[{"name":"Wordfence","remoteId":"cc1c76ee-078d-4c9a-a4d3-063d9147d7e8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc1c76ee-078d-4c9a-a4d3-063d9147d7e8?source=api-prod","cve":"CVE-2024-8921","affectedVersions":"<=1.6.3","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_616972746966616374811c9dc5_gen.json b/internal/data/assets/theme_616972746966616374811c9dc5_gen.json new file mode 100644 index 00000000..ec642e9e --- /dev/null +++ b/internal/data/assets/theme_616972746966616374811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/5367ca36-e3e0-4bb3-8148-4e7623d35315/airtifact","title":"Airtifact <= 1.2.91 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"5367ca36-e3e0-4bb3-8148-4e7623d35315"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5367ca36-e3e0-4bb3-8148-4e7623d35315?source=api-prod","cve":"CVE-2026-27343","affectedVersions":"<=1.2.91","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_63657261746f811c9dc5_gen.json b/internal/data/assets/theme_63657261746f811c9dc5_gen.json new file mode 100644 index 00000000..1d25fe98 --- /dev/null +++ b/internal/data/assets/theme_63657261746f811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/59391c74-0287-4375-8215-388cc918ea3c/cerato","title":"Cerato <= 2.2.18 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"59391c74-0287-4375-8215-388cc918ea3c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/59391c74-0287-4375-8215-388cc918ea3c?source=api-prod","cve":"CVE-2025-58920","affectedVersions":"<=2.2.18","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_636f616368696679811c9dc5_gen.json b/internal/data/assets/theme_636f616368696679811c9dc5_gen.json index 4817658e..0d52cab7 100644 --- a/internal/data/assets/theme_636f616368696679811c9dc5_gen.json +++ b/internal/data/assets/theme_636f616368696679811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/9528d0d8-9f56-43e4-9b86-92e54ea38013/coachify","title":"Coachify <= 1.0.7 - Cross-Site Request Forgery to Notice Dismissal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"9528d0d8-9f56-43e4-9b86-92e54ea38013"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9528d0d8-9f56-43e4-9b86-92e54ea38013?source=api-prod","cve":"CVE-2024-37417","affectedVersions":"<=1.0.7","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/40725a33-353e-443a-b1f1-ac7c3e4a1323/coachify","title":"Coachify <= 1.1.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"40725a33-353e-443a-b1f1-ac7c3e4a1323"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/40725a33-353e-443a-b1f1-ac7c3e4a1323?source=api-prod","cve":"CVE-2026-25336","affectedVersions":"<=1.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/6670b07e-c9ff-468c-8bfe-603d21bb9afb/coachify","title":"Coachify <= 1.1.5 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"6670b07e-c9ff-468c-8bfe-603d21bb9afb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6670b07e-c9ff-468c-8bfe-603d21bb9afb?source=api-prod","cve":"CVE-2026-25337","affectedVersions":"<=1.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/9528d0d8-9f56-43e4-9b86-92e54ea38013/coachify","title":"Coachify <= 1.0.7 - Cross-Site Request Forgery to Notice Dismissal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"9528d0d8-9f56-43e4-9b86-92e54ea38013"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9528d0d8-9f56-43e4-9b86-92e54ea38013?source=api-prod","cve":"CVE-2024-37417","affectedVersions":"<=1.0.7","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_656475626c696e6b811c9dc5_gen.json b/internal/data/assets/theme_656475626c696e6b811c9dc5_gen.json new file mode 100644 index 00000000..85afd285 --- /dev/null +++ b/internal/data/assets/theme_656475626c696e6b811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/1b693646-efdb-44c7-a8d8-48315d19fe23/edublink","title":"EduBlink <= 2.0.7 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"1b693646-efdb-44c7-a8d8-48315d19fe23"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b693646-efdb-44c7-a8d8-48315d19fe23?source=api-prod","cve":"CVE-2026-27328","affectedVersions":"<=2.0.7","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_66696e6167811c9dc5_gen.json b/internal/data/assets/theme_66696e6167811c9dc5_gen.json new file mode 100644 index 00000000..709a771e --- /dev/null +++ b/internal/data/assets/theme_66696e6167811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/72a5bbcf-94ef-4c73-8275-7609cc36e5f4/finag","title":"Finag <= 1.5.0 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"72a5bbcf-94ef-4c73-8275-7609cc36e5f4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/72a5bbcf-94ef-4c73-8275-7609cc36e5f4?source=api-prod","cve":"CVE-2025-60237","affectedVersions":"<=1.5.0","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_72657374617572616e742d636166657465726961811c9dc5_gen.json b/internal/data/assets/theme_72657374617572616e742d636166657465726961811c9dc5_gen.json new file mode 100644 index 00000000..ed378a59 --- /dev/null +++ b/internal/data/assets/theme_72657374617572616e742d636166657465726961811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/16d0c7ad-e9d3-42c9-ac73-cc8184c9d60d/restaurant-cafeteria","title":"Restaurant Cafeteria <= 0.4.6 - Missing Authorization to (Subscriber+) Arbitrary Plugin Installation/Activation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"16d0c7ad-e9d3-42c9-ac73-cc8184c9d60d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/16d0c7ad-e9d3-42c9-ac73-cc8184c9d60d?source=api-prod","cve":"CVE-2025-15445","affectedVersions":"<=0.4.6","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_73686f7077656c6c811c9dc5_gen.json b/internal/data/assets/theme_73686f7077656c6c811c9dc5_gen.json new file mode 100644 index 00000000..26948136 --- /dev/null +++ b/internal/data/assets/theme_73686f7077656c6c811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/99778d0b-1909-4075-8b80-531b67e7ed79/shopwell","title":"Shopwell <= 1.0.11 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"99778d0b-1909-4075-8b80-531b67e7ed79"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/99778d0b-1909-4075-8b80-531b67e7ed79?source=api-prod","cve":"CVE-2026-25333","affectedVersions":"<=1.0.11","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_7873746f7265811c9dc5_gen.json b/internal/data/assets/theme_7873746f7265811c9dc5_gen.json index 96c9d2b6..55b79e3f 100644 --- a/internal/data/assets/theme_7873746f7265811c9dc5_gen.json +++ b/internal/data/assets/theme_7873746f7265811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0f8cc16d-4e42-47b0-8ba0-df3252071826/xstore","title":"XStore <= 9.3.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"0f8cc16d-4e42-47b0-8ba0-df3252071826"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f8cc16d-4e42-47b0-8ba0-df3252071826?source=api-prod","cve":"CVE-2024-33561","affectedVersions":"<=9.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/19fe28c0-c0ef-49aa-91c1-2e273201babd/xstore","title":"XStore <= 9.3.8 - Authenticated (Subscriber+) Arbitrary Options Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"19fe28c0-c0ef-49aa-91c1-2e273201babd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/19fe28c0-c0ef-49aa-91c1-2e273201babd?source=api-prod","cve":"CVE-2024-33564","affectedVersions":"<=9.3.8","severity":"high"},{"advisoryId":"WPSECADV/WF/2a49db7f-62fc-472d-9edf-de5edbe48219/xstore","title":"XStore | Multipurpose WooCommerce Theme <= 9.5.4 - Authenticated (Subscriber+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-14 14:24:23","sources":[{"name":"Wordfence","remoteId":"2a49db7f-62fc-472d-9edf-de5edbe48219"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2a49db7f-62fc-472d-9edf-de5edbe48219?source=api-prod","cve":"CVE-2025-11746","affectedVersions":"<=9.5.4","severity":"high"},{"advisoryId":"WPSECADV/WF/415d69d9-2afd-41f8-8339-ea32fac3aa48/xstore","title":"XStore <= 9.3.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"415d69d9-2afd-41f8-8339-ea32fac3aa48"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/415d69d9-2afd-41f8-8339-ea32fac3aa48?source=api-prod","cve":"CVE-2024-33563","affectedVersions":"<=9.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/50d1b8f6-8b60-4c49-a41c-4d5e0df2e7e2/xstore","title":"XStore < 9.6.1 - Authenticated (Subscriber+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"50d1b8f6-8b60-4c49-a41c-4d5e0df2e7e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/50d1b8f6-8b60-4c49-a41c-4d5e0df2e7e2?source=api-prod","cve":"CVE-2025-64193","affectedVersions":"<9.6.1","severity":"high"},{"advisoryId":"WPSECADV/WF/683cc327-e17e-49f6-a903-f8a40bb832d1/xstore","title":"XStore <= 9.3.8 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"683cc327-e17e-49f6-a903-f8a40bb832d1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/683cc327-e17e-49f6-a903-f8a40bb832d1?source=api-prod","cve":"CVE-2024-33559","affectedVersions":"<=9.3.8","severity":"critical"},{"advisoryId":"WPSECADV/WF/73897594-d25c-410e-81b1-70b6a8136aee/xstore","title":"XStore < 9.6 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"73897594-d25c-410e-81b1-70b6a8136aee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/73897594-d25c-410e-81b1-70b6a8136aee?source=api-prod","cve":"CVE-2025-60100","affectedVersions":"<9.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/76f549ff-4c96-4cb4-a8c7-4967ec79727e/xstore","title":"XStore < 9.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"76f549ff-4c96-4cb4-a8c7-4967ec79727e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/76f549ff-4c96-4cb4-a8c7-4967ec79727e?source=api-prod","cve":"CVE-2025-64192","affectedVersions":"<9.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/9fb4c58d-321d-453f-92b9-ae409541911b/xstore","title":"XStore <= 9.3.8 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"9fb4c58d-321d-453f-92b9-ae409541911b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9fb4c58d-321d-453f-92b9-ae409541911b?source=api-prod","cve":"CVE-2024-33560","affectedVersions":"<=9.3.8","severity":"critical"},{"advisoryId":"WPSECADV/WF/aa197b6b-be18-48c2-a7e3-d921b4ef1c54/xstore","title":"XStore <= 9.3.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"aa197b6b-be18-48c2-a7e3-d921b4ef1c54"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa197b6b-be18-48c2-a7e3-d921b4ef1c54?source=api-prod","cve":"CVE-2024-33562","affectedVersions":"<=9.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/dd1335cd-dc12-4699-9c57-900ba50aeef5/xstore","title":"XStore < 9.6.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"dd1335cd-dc12-4699-9c57-900ba50aeef5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dd1335cd-dc12-4699-9c57-900ba50aeef5?source=api-prod","cve":"CVE-2025-64191","affectedVersions":"<9.6.1","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0f8cc16d-4e42-47b0-8ba0-df3252071826/xstore","title":"XStore <= 9.3.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"0f8cc16d-4e42-47b0-8ba0-df3252071826"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f8cc16d-4e42-47b0-8ba0-df3252071826?source=api-prod","cve":"CVE-2024-33561","affectedVersions":"<=9.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/19fe28c0-c0ef-49aa-91c1-2e273201babd/xstore","title":"XStore <= 9.3.8 - Authenticated (Subscriber+) Arbitrary Options Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"19fe28c0-c0ef-49aa-91c1-2e273201babd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/19fe28c0-c0ef-49aa-91c1-2e273201babd?source=api-prod","cve":"CVE-2024-33564","affectedVersions":"<=9.3.8","severity":"high"},{"advisoryId":"WPSECADV/WF/2a49db7f-62fc-472d-9edf-de5edbe48219/xstore","title":"XStore | Multipurpose WooCommerce Theme <= 9.5.4 - Authenticated (Subscriber+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-14 14:24:23","sources":[{"name":"Wordfence","remoteId":"2a49db7f-62fc-472d-9edf-de5edbe48219"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2a49db7f-62fc-472d-9edf-de5edbe48219?source=api-prod","cve":"CVE-2025-11746","affectedVersions":"<=9.5.4","severity":"high"},{"advisoryId":"WPSECADV/WF/415d69d9-2afd-41f8-8339-ea32fac3aa48/xstore","title":"XStore <= 9.3.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"415d69d9-2afd-41f8-8339-ea32fac3aa48"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/415d69d9-2afd-41f8-8339-ea32fac3aa48?source=api-prod","cve":"CVE-2024-33563","affectedVersions":"<=9.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/50d1b8f6-8b60-4c49-a41c-4d5e0df2e7e2/xstore","title":"XStore < 9.6.1 - Authenticated (Subscriber+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"50d1b8f6-8b60-4c49-a41c-4d5e0df2e7e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/50d1b8f6-8b60-4c49-a41c-4d5e0df2e7e2?source=api-prod","cve":"CVE-2025-64193","affectedVersions":"<9.6.1","severity":"high"},{"advisoryId":"WPSECADV/WF/683cc327-e17e-49f6-a903-f8a40bb832d1/xstore","title":"XStore <= 9.3.8 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"683cc327-e17e-49f6-a903-f8a40bb832d1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/683cc327-e17e-49f6-a903-f8a40bb832d1?source=api-prod","cve":"CVE-2024-33559","affectedVersions":"<=9.3.8","severity":"critical"},{"advisoryId":"WPSECADV/WF/73897594-d25c-410e-81b1-70b6a8136aee/xstore","title":"XStore < 9.6 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"73897594-d25c-410e-81b1-70b6a8136aee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/73897594-d25c-410e-81b1-70b6a8136aee?source=api-prod","cve":"CVE-2025-60100","affectedVersions":"<9.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/76f549ff-4c96-4cb4-a8c7-4967ec79727e/xstore","title":"XStore < 9.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"76f549ff-4c96-4cb4-a8c7-4967ec79727e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/76f549ff-4c96-4cb4-a8c7-4967ec79727e?source=api-prod","cve":"CVE-2025-64192","affectedVersions":"<9.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/9fb4c58d-321d-453f-92b9-ae409541911b/xstore","title":"XStore <= 9.3.8 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"9fb4c58d-321d-453f-92b9-ae409541911b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9fb4c58d-321d-453f-92b9-ae409541911b?source=api-prod","cve":"CVE-2024-33560","affectedVersions":"<=9.3.8","severity":"critical"},{"advisoryId":"WPSECADV/WF/aa197b6b-be18-48c2-a7e3-d921b4ef1c54/xstore","title":"XStore <= 9.3.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"aa197b6b-be18-48c2-a7e3-d921b4ef1c54"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa197b6b-be18-48c2-a7e3-d921b4ef1c54?source=api-prod","cve":"CVE-2024-33562","affectedVersions":"<=9.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/aa30b959-cdf2-4b3b-9c65-d52e1d839a79/xstore","title":"XStore <= 9.6.4 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"aa30b959-cdf2-4b3b-9c65-d52e1d839a79"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa30b959-cdf2-4b3b-9c65-d52e1d839a79?source=api-prod","cve":"CVE-2026-25006","affectedVersions":"<=9.6.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/af0e3e7c-580c-4367-bda5-e94c1f7e8e65/xstore","title":"XStore <= 9.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"af0e3e7c-580c-4367-bda5-e94c1f7e8e65"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af0e3e7c-580c-4367-bda5-e94c1f7e8e65?source=api-prod","cve":"CVE-2026-25305","affectedVersions":"<=9.6.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/dd1335cd-dc12-4699-9c57-900ba50aeef5/xstore","title":"XStore < 9.6.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"dd1335cd-dc12-4699-9c57-900ba50aeef5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dd1335cd-dc12-4699-9c57-900ba50aeef5?source=api-prod","cve":"CVE-2025-64191","affectedVersions":"<9.6.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_7a757574811c9dc5_gen.json b/internal/data/assets/theme_7a757574811c9dc5_gen.json new file mode 100644 index 00000000..970681eb --- /dev/null +++ b/internal/data/assets/theme_7a757574811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/3d94ffdb-d5e1-4125-b499-5e47f9f67069/zuut","title":"Zuut <= 1.4.2 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"3d94ffdb-d5e1-4125-b499-5e47f9f67069"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3d94ffdb-d5e1-4125-b499-5e47f9f67069?source=api-prod","cve":"CVE-2025-60233","affectedVersions":"<=1.4.2","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets_gen.go b/internal/data/assets_gen.go index 1d4f171b..a270ddf1 100644 --- a/internal/data/assets_gen.go +++ b/internal/data/assets_gen.go @@ -92,6 +92,8 @@ var ( theme_61696c6162811c9dc5 []byte //go:embed assets/theme_616972696e2d626c6f67811c9dc5_gen.json theme_616972696e2d626c6f67811c9dc5 []byte + //go:embed assets/theme_616972746966616374811c9dc5_gen.json + theme_616972746966616374811c9dc5 []byte //go:embed assets/theme_616b616c811c9dc5_gen.json theme_616b616c811c9dc5 []byte //go:embed assets/theme_616b697461811c9dc5_gen.json @@ -672,6 +674,8 @@ var ( theme_63656c65737469616c2d61757261811c9dc5 []byte //go:embed assets/theme_63656e61811c9dc5_gen.json theme_63656e61811c9dc5 []byte + //go:embed assets/theme_63657261746f811c9dc5_gen.json + theme_63657261746f811c9dc5 []byte //go:embed assets/theme_636572656272756d811c9dc5_gen.json theme_636572656272756d811c9dc5 []byte //go:embed assets/theme_636861696e6564811c9dc5_gen.json @@ -1114,6 +1118,8 @@ var ( theme_656469746f7269616c6d6167811c9dc5 []byte //go:embed assets/theme_65646d696e811c9dc5_gen.json theme_65646d696e811c9dc5 []byte + //go:embed assets/theme_656475626c696e6b811c9dc5_gen.json + theme_656475626c696e6b811c9dc5 []byte //go:embed assets/theme_656475636174696f6e811c9dc5_gen.json theme_656475636174696f6e811c9dc5 []byte //go:embed assets/theme_656475636174696f6e2d62617365811c9dc5_gen.json @@ -1320,6 +1326,8 @@ var ( theme_66696c6d6178811c9dc5 []byte //go:embed assets/theme_66696c6d6978811c9dc5_gen.json theme_66696c6d6978811c9dc5 []byte + //go:embed assets/theme_66696e6167811c9dc5_gen.json + theme_66696e6167811c9dc5 []byte //go:embed assets/theme_66696e616e6365811c9dc5_gen.json theme_66696e616e6365811c9dc5 []byte //go:embed assets/theme_66696e616e63696f811c9dc5_gen.json @@ -2954,6 +2962,8 @@ var ( theme_726573706f6e736976652d6d6f62696c65811c9dc5 []byte //go:embed assets/theme_72657374617572616e742d616e642d63616665811c9dc5_gen.json theme_72657374617572616e742d616e642d63616665811c9dc5 []byte + //go:embed assets/theme_72657374617572616e742d636166657465726961811c9dc5_gen.json + theme_72657374617572616e742d636166657465726961811c9dc5 []byte //go:embed assets/theme_72657374617572616e742d7a6f6e65811c9dc5_gen.json theme_72657374617572616e742d7a6f6e65811c9dc5 []byte //go:embed assets/theme_72657374617572616e7465811c9dc5_gen.json @@ -3150,6 +3160,8 @@ var ( theme_73686f707065747465811c9dc5 []byte //go:embed assets/theme_73686f7073746172811c9dc5_gen.json theme_73686f7073746172811c9dc5 []byte + //go:embed assets/theme_73686f7077656c6c811c9dc5_gen.json + theme_73686f7077656c6c811c9dc5 []byte //go:embed assets/theme_73686f7274811c9dc5_gen.json theme_73686f7274811c9dc5 []byte //go:embed assets/theme_73686f7574626f78811c9dc5_gen.json @@ -4014,6 +4026,8 @@ var ( theme_7a6f787072657373811c9dc5 []byte //go:embed assets/theme_7a6f7961811c9dc5_gen.json theme_7a6f7961811c9dc5 []byte + //go:embed assets/theme_7a757574811c9dc5_gen.json + theme_7a757574811c9dc5 []byte ) func themeAdvisories(slug string) ([]byte, error) { @@ -4096,6 +4110,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_61696c6162811c9dc5, nil case "airin-blog": return theme_616972696e2d626c6f67811c9dc5, nil + case "airtifact": + return theme_616972746966616374811c9dc5, nil case "akal": return theme_616b616c811c9dc5, nil case "akita": @@ -4676,6 +4692,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_63656c65737469616c2d61757261811c9dc5, nil case "cena": return theme_63656e61811c9dc5, nil + case "cerato": + return theme_63657261746f811c9dc5, nil case "cerebrum": return theme_636572656272756d811c9dc5, nil case "chained": @@ -5118,6 +5136,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_656469746f7269616c6d6167811c9dc5, nil case "edmin": return theme_65646d696e811c9dc5, nil + case "edublink": + return theme_656475626c696e6b811c9dc5, nil case "education": return theme_656475636174696f6e811c9dc5, nil case "education-base": @@ -5324,6 +5344,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_66696c6d6178811c9dc5, nil case "filmix": return theme_66696c6d6978811c9dc5, nil + case "finag": + return theme_66696e6167811c9dc5, nil case "finance": return theme_66696e616e6365811c9dc5, nil case "financio": @@ -6958,6 +6980,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_726573706f6e736976652d6d6f62696c65811c9dc5, nil case "restaurant-and-cafe": return theme_72657374617572616e742d616e642d63616665811c9dc5, nil + case "restaurant-cafeteria": + return theme_72657374617572616e742d636166657465726961811c9dc5, nil case "restaurant-zone": return theme_72657374617572616e742d7a6f6e65811c9dc5, nil case "restaurante": @@ -7154,6 +7178,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_73686f707065747465811c9dc5, nil case "shopstar": return theme_73686f7073746172811c9dc5, nil + case "shopwell": + return theme_73686f7077656c6c811c9dc5, nil case "short": return theme_73686f7274811c9dc5, nil case "shoutbox": @@ -8018,6 +8044,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_7a6f787072657373811c9dc5, nil case "zoya": return theme_7a6f7961811c9dc5, nil + case "zuut": + return theme_7a757574811c9dc5, nil default: return nil, errPackageNotFound } diff --git a/internal/data/assets_gen_test.go b/internal/data/assets_gen_test.go index b7c37314..659bde4d 100644 --- a/internal/data/assets_gen_test.go +++ b/internal/data/assets_gen_test.go @@ -298,6 +298,7 @@ func plugins() []string { "add2fav", "addblockblocker", "addendio", + "addfreespace", "addfreestats", "addfunc-head-footer-code", "addfunc-mobile-detect", @@ -1550,6 +1551,7 @@ func plugins() []string { "blog-manager-light", "blog-manager-wp", "blog-posts-and-category-for-elementor", + "blog-settings", "blog-sidebar-widget", "blog-stats-by-w3counter", "blog2social", @@ -2226,6 +2228,7 @@ func plugins() []string { "chart-builder", "chart-expert", "chartbeat", + "charts-ninja-graphs-and-charts", "chat-bee", "chat-bubble", "chat-help", @@ -3585,6 +3588,7 @@ func plugins() []string { "drag-and-drop-custom-sidebar", "drag-and-drop-file-upload-for-contact-form-7", "drag-and-drop-file-upload-for-elementor-forms", + "drag-and-drop-file-upload-wc-pro", "drag-and-drop-file-uploads-wc-pro", "drag-and-drop-form-builder-for-contact-form-7", "drag-and-drop-multiple-file-upload-contact-form-7", @@ -3672,6 +3676,7 @@ func plugins() []string { "dx-delete-attached-media", "dx-sales-crm", "dx-share-selection", + "dx-sources", "dx-unanswered-comments", "dx-watermark", "dyapress", @@ -4403,6 +4408,7 @@ func plugins() []string { "exquisite-paypal-donation", "exs-widgets", "extend-filter-products-by-price-widget", + "extend-link", "extended-evaluation-for-statify", "extended-post-status", "extended-random-number-generator", @@ -6944,6 +6950,7 @@ func plugins() []string { "login-with-azure", "login-with-cognito", "login-with-phone-number", + "login-with-salesforce", "login-with-vipps", "login-with-yourmembership", "loginizer", @@ -7367,6 +7374,7 @@ func plugins() []string { "memphis-documents-library", "memsource-connector", "mendeleyplugin", + "mentoring", "menu-card", "menu-icons", "menu-image", @@ -8518,6 +8526,7 @@ func plugins() []string { "peepso-photos", "peer-publish", "pegapoll", + "penci-ai", "penci-bookmark-follow", "penci-data-migrator", "penci-filter-everything", @@ -8956,6 +8965,7 @@ func plugins() []string { "powerkit", "powerpack-addon-for-beaver-builder", "powerpack-elements", + "powerpack-for-learndash", "powerpack-lite-for-elementor", "powerpress", "powerpress-multisite", @@ -9208,6 +9218,7 @@ func plugins() []string { "ptengine-real-time-web-analytics-and-heatmap", "ptoffice-sign-ups", "ptypeconverter", + "publish-2-pingfm", "publish-approval", "publish-confirm-message", "publish-post-email-notification", @@ -10024,6 +10035,7 @@ func plugins() []string { "scrollup", "scss-library", "scss-wp-editor", + "sctv-sales-countdown-timer", "scw-bus-seat-reservation", "scw-seat-reservation", "se-html5-album-audio-player", @@ -10533,6 +10545,7 @@ func plugins() []string { "simple-optimizer", "simple-org-chart", "simple-owl-carousel", + "simple-owl-shortcodes", "simple-page-access-restriction", "simple-page-ordering", "simple-page-transition", @@ -10859,6 +10872,7 @@ func plugins() []string { "smart-variations-images", "smart-wetransfer", "smart-wishlist-for-more-convert", + "smart-wishlist-for-more-convert-premium", "smart-woocommerce-search", "smart-youtube", "smartarget-contact-us", @@ -12971,6 +12985,7 @@ func plugins() []string { "wise-forms", "wiseagentleadform", "wiser-notify", + "wiser-review", "wish-list-for-woocommerce", "wish-list-for-woocommerce-pro", "wish-to-go", @@ -13699,6 +13714,7 @@ func plugins() []string { "wp-client-logo-carousel", "wp-client-reports", "wp-client-testimonial", + "wp-clippy", "wp-clone-any-post-type", "wp-clone-by-wp-academy", "wp-cloud-server", @@ -13744,6 +13760,7 @@ func plugins() []string { "wp-content-security-policy", "wp-contest", "wp-cookie", + "wp-cookie-allow", "wp-cookie-consent", "wp-cookie-law-info", "wp-cookie-user-info", @@ -15013,6 +15030,7 @@ func plugins() []string { "wprecovery", "wpremote", "wprequal", + "wpresidence-core", "wps-bidouille", "wps-child-theme-generator", "wps-cleaner", @@ -15370,6 +15388,7 @@ func plugins() []string { "ziggeo", "zij-kart", "zikzag-core", + "zingaya-click-to-call", "zingiri-forum", "zingiri-tickets", "zingiri-web-shop", @@ -15453,6 +15472,7 @@ func themes() []string { "aihub", "ailab", "airin-blog", + "airtifact", "akal", "akita", "alanzo", @@ -15743,6 +15763,7 @@ func themes() []string { "celeste", "celestial-aura", "cena", + "cerato", "cerebrum", "chained", "chainpress", @@ -15964,6 +15985,7 @@ func themes() []string { "edifice", "editorialmag", "edmin", + "edublink", "education", "education-base", "education-lms", @@ -16067,6 +16089,7 @@ func themes() []string { "fifteen", "filmax", "filmix", + "finag", "finance", "financio", "findall", @@ -16884,6 +16907,7 @@ func themes() []string { "responsive", "responsive-mobile", "restaurant-and-cafe", + "restaurant-cafeteria", "restaurant-zone", "restaurante", "restaurt", @@ -16982,6 +17006,7 @@ func themes() []string { "shopo", "shoppette", "shopstar", + "shopwell", "short", "shoutbox", "shuban", @@ -17414,5 +17439,6 @@ func themes() []string { "zox-news", "zoxpress", "zoya", + "zuut", } }