diff --git a/internal/data/assets/plugin_31322d737465702d6d656574696e672d6c697374811c9dc5_gen.json b/internal/data/assets/plugin_31322d737465702d6d656574696e672d6c697374811c9dc5_gen.json index a3ff97ab..f13acf8a 100644 --- a/internal/data/assets/plugin_31322d737465702d6d656574696e672d6c697374811c9dc5_gen.json +++ b/internal/data/assets/plugin_31322d737465702d6d656574696e672d6c697374811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/19071f16-fa14-447c-ac71-73e1b4c783e1/12-step-meeting-list","title":"12 Step Meeting List <= 3.14.33 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"19071f16-fa14-447c-ac71-73e1b4c783e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/19071f16-fa14-447c-ac71-73e1b4c783e1?source=api-prod","cve":"CVE-2024-35693","affectedVersions":"<=3.14.33","severity":"medium"},{"advisoryId":"WPSECADV/WF/3e90a515-d164-4468-b2be-22c8f1039c4a/12-step-meeting-list","title":"12 Step Meeting List <= 3.16.5 - Missing Authorization to Unauthenticated Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"3e90a515-d164-4468-b2be-22c8f1039c4a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3e90a515-d164-4468-b2be-22c8f1039c4a?source=api-prod","cve":"CVE-2025-24583","affectedVersions":"<=3.16.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/43f34d3b-ed55-48d1-9074-b33f166e333e/12-step-meeting-list","title":"12 Step Meeting List <= 3.16.5 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"43f34d3b-ed55-48d1-9074-b33f166e333e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/43f34d3b-ed55-48d1-9074-b33f166e333e?source=api-prod","cve":"CVE-2025-24582","affectedVersions":"<=3.16.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/4d6e9cb0-6b90-4a5b-8626-0b3f378fbc92/12-step-meeting-list","title":"12 Step Meeting List <= 3.14.24 - Authenticated (Contributor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d6e9cb0-6b90-4a5b-8626-0b3f378fbc92"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d6e9cb0-6b90-4a5b-8626-0b3f378fbc92?source=api-prod","cve":"CVE-2023-46641","affectedVersions":"<=3.14.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/51296ab5-da96-4461-89f7-9e93f8032b03/12-step-meeting-list","title":"12 Step Meeting List <= 3.18.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"51296ab5-da96-4461-89f7-9e93f8032b03"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/51296ab5-da96-4461-89f7-9e93f8032b03?source=api-prod","cve":"CVE-2025-54054","affectedVersions":"<=3.18.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/5b82994c-c0bd-4e44-95a7-7480ffbb1aad/12-step-meeting-list","title":"12 Step Meeting List <= 3.19.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"5b82994c-c0bd-4e44-95a7-7480ffbb1aad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5b82994c-c0bd-4e44-95a7-7480ffbb1aad?source=api-prod","cve":"CVE-2026-39569","affectedVersions":"<=3.19.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/8269f83b-5d7d-4f01-85ee-fd7262fed5b1/12-step-meeting-list","title":"12 Step Meeting List <= 3.14.28 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"8269f83b-5d7d-4f01-85ee-fd7262fed5b1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8269f83b-5d7d-4f01-85ee-fd7262fed5b1?source=api-prod","cve":"CVE-2024-22296","affectedVersions":"<=3.14.28","severity":"medium"},{"advisoryId":"WPSECADV/WF/d504c2bd-d6a8-4a66-a650-4a18cb32c54a/12-step-meeting-list","title":"12 Step Meeting List <= 3.16.5 - Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"d504c2bd-d6a8-4a66-a650-4a18cb32c54a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d504c2bd-d6a8-4a66-a650-4a18cb32c54a?source=api-prod","cve":"CVE-2025-24580","affectedVersions":"<=3.16.5","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/19071f16-fa14-447c-ac71-73e1b4c783e1/12-step-meeting-list","title":"12 Step Meeting List <= 3.14.33 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"19071f16-fa14-447c-ac71-73e1b4c783e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/19071f16-fa14-447c-ac71-73e1b4c783e1?source=api-prod","cve":"CVE-2024-35693","affectedVersions":"<=3.14.33","severity":"medium"},{"advisoryId":"WPSECADV/WF/3e90a515-d164-4468-b2be-22c8f1039c4a/12-step-meeting-list","title":"12 Step Meeting List <= 3.16.5 - Missing Authorization to Unauthenticated Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"3e90a515-d164-4468-b2be-22c8f1039c4a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3e90a515-d164-4468-b2be-22c8f1039c4a?source=api-prod","cve":"CVE-2025-24583","affectedVersions":"<=3.16.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/43f34d3b-ed55-48d1-9074-b33f166e333e/12-step-meeting-list","title":"12 Step Meeting List <= 3.16.5 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"43f34d3b-ed55-48d1-9074-b33f166e333e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/43f34d3b-ed55-48d1-9074-b33f166e333e?source=api-prod","cve":"CVE-2025-24582","affectedVersions":"<=3.16.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/4d6e9cb0-6b90-4a5b-8626-0b3f378fbc92/12-step-meeting-list","title":"12 Step Meeting List <= 3.14.24 - Authenticated (Contributor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d6e9cb0-6b90-4a5b-8626-0b3f378fbc92"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d6e9cb0-6b90-4a5b-8626-0b3f378fbc92?source=api-prod","cve":"CVE-2023-46641","affectedVersions":"<=3.14.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/51296ab5-da96-4461-89f7-9e93f8032b03/12-step-meeting-list","title":"12 Step Meeting List <= 3.18.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"51296ab5-da96-4461-89f7-9e93f8032b03"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/51296ab5-da96-4461-89f7-9e93f8032b03?source=api-prod","cve":"CVE-2025-54054","affectedVersions":"<=3.18.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/5b82994c-c0bd-4e44-95a7-7480ffbb1aad/12-step-meeting-list","title":"12 Step Meeting List <= 3.19.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"5b82994c-c0bd-4e44-95a7-7480ffbb1aad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5b82994c-c0bd-4e44-95a7-7480ffbb1aad?source=api-prod","cve":"CVE-2026-39569","affectedVersions":"<=3.19.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/8269f83b-5d7d-4f01-85ee-fd7262fed5b1/12-step-meeting-list","title":"12 Step Meeting List <= 3.14.28 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"8269f83b-5d7d-4f01-85ee-fd7262fed5b1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8269f83b-5d7d-4f01-85ee-fd7262fed5b1?source=api-prod","cve":"CVE-2024-22296","affectedVersions":"<=3.14.28","severity":"medium"},{"advisoryId":"WPSECADV/WF/af97a8aa-f42b-46c8-b79b-d1c3220fdf58/12-step-meeting-list","title":"12 Step Meeting List <= 3.19.9 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"af97a8aa-f42b-46c8-b79b-d1c3220fdf58"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af97a8aa-f42b-46c8-b79b-d1c3220fdf58?source=api-prod","cve":"CVE-2026-39570","affectedVersions":"<=3.19.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/d504c2bd-d6a8-4a66-a650-4a18cb32c54a/12-step-meeting-list","title":"12 Step Meeting List <= 3.16.5 - Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"d504c2bd-d6a8-4a66-a650-4a18cb32c54a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d504c2bd-d6a8-4a66-a650-4a18cb32c54a?source=api-prod","cve":"CVE-2025-24580","affectedVersions":"<=3.16.5","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6164646f6e2d656c656d656e74732d666f722d656c656d656e746f722d706167652d6275696c646572811c9dc5_gen.json b/internal/data/assets/plugin_6164646f6e2d656c656d656e74732d666f722d656c656d656e746f722d706167652d6275696c646572811c9dc5_gen.json index 257ce0c8..e8e9e5bd 100644 --- a/internal/data/assets/plugin_6164646f6e2d656c656d656e74732d666f722d656c656d656e746f722d706167652d6275696c646572811c9dc5_gen.json +++ b/internal/data/assets/plugin_6164646f6e2d656c656d656e74732d666f722d656c656d656e746f722d706167652d6275696c646572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/11e97adc-b402-4d82-ae39-4dccbd70bcf2/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.11.7 - Cross-Site Request Forgery\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"11e97adc-b402-4d82-ae39-4dccbd70bcf2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/11e97adc-b402-4d82-ae39-4dccbd70bcf2?source=api-prod","affectedVersions":"<=1.11.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/18e2e0e5-495f-4f55-b7d8-94193fc2ad12/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"18e2e0e5-495f-4f55-b7d8-94193fc2ad12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/18e2e0e5-495f-4f55-b7d8-94193fc2ad12?source=api-prod","cve":"CVE-2024-2091","affectedVersions":"<=1.13.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/20cd3fff-0488-4bc2-961b-2427925e6a96/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.12 - Directory Traversal to Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"20cd3fff-0488-4bc2-961b-2427925e6a96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/20cd3fff-0488-4bc2-961b-2427925e6a96?source=api-prod","cve":"CVE-2024-1358","affectedVersions":"<=1.12.12","severity":"high"},{"advisoryId":"WPSECADV/WF/33d7dc4d-bb41-456a-bd1a-37d8f2aada30/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Dual Button Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"33d7dc4d-bb41-456a-bd1a-37d8f2aada30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/33d7dc4d-bb41-456a-bd1a-37d8f2aada30?source=api-prod","cve":"CVE-2024-1392","affectedVersions":"<=1.12.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42/addon-elements-for-elementor-page-builder","title":"Freemius SDK <= 2.4.2 - Missing Authorization Checks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"39fb0499-9ab4-4a2f-b0db-ece86bcf4d42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=api-prod","cve":"CVE-2022-4974","affectedVersions":"<1.11.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/472cdbc4-3bfa-4254-b35a-be7ae10782e6/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.7 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"472cdbc4-3bfa-4254-b35a-be7ae10782e6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/472cdbc4-3bfa-4254-b35a-be7ae10782e6?source=api-prod","cve":"CVE-2023-4689","affectedVersions":"<=1.12.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/4ba28184-b5c3-4a5c-a376-29b3c6a2aa20/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Modal Popup effet\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"4ba28184-b5c3-4a5c-a376-29b3c6a2aa20"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ba28184-b5c3-4a5c-a376-29b3c6a2aa20?source=api-prod","cve":"CVE-2024-1422","affectedVersions":"<=1.12.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/4feacb75-0533-4f53-8ce9-3e45ee8336e2/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure via Modal Popup\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"4feacb75-0533-4f53-8ce9-3e45ee8336e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4feacb75-0533-4f53-8ce9-3e45ee8336e2?source=api-prod","cve":"CVE-2024-13215","affectedVersions":"<=1.13.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/5253fe2b-040b-417c-b257-0cb59ee5aa6e/addon-elements-for-elementor-page-builder","title":"Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"5253fe2b-040b-417c-b257-0cb59ee5aa6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5253fe2b-040b-417c-b257-0cb59ee5aa6e?source=api-prod","cve":"CVE-2023-33999","affectedVersions":"<=1.11.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/63ef7383-d684-473b-aa0f-45027ef245f6/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"63ef7383-d684-473b-aa0f-45027ef245f6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63ef7383-d684-473b-aa0f-45027ef245f6?source=api-prod","cve":"CVE-2024-4569","affectedVersions":"<=1.13.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/668621b0-67ef-44fc-a126-e8c4e372666e/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-29 20:31:53","sources":[{"name":"Wordfence","remoteId":"668621b0-67ef-44fc-a126-e8c4e372666e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/668621b0-67ef-44fc-a126-e8c4e372666e?source=api-prod","cve":"CVE-2024-7122","affectedVersions":"<=1.13.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/67790c0b-c078-4955-a175-977a695392fc/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-11 20:53:36","sources":[{"name":"Wordfence","remoteId":"67790c0b-c078-4955-a175-977a695392fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/67790c0b-c078-4955-a175-977a695392fc?source=api-prod","cve":"CVE-2024-2092","affectedVersions":"<=1.13.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/6ebb5654-ba3e-4f18-8720-a6595a771964/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.11 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"6ebb5654-ba3e-4f18-8720-a6595a771964"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6ebb5654-ba3e-4f18-8720-a6595a771964?source=api-prod","cve":"CVE-2024-0834","affectedVersions":"=1.12.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/6f8814b0-6818-47c2-9f2a-8fe12485bd33/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f8814b0-6818-47c2-9f2a-8fe12485bd33"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f8814b0-6818-47c2-9f2a-8fe12485bd33?source=api-prod","cve":"CVE-2024-47361","affectedVersions":"<=1.13.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/7317ecf5-d43d-4080-ad2a-7644764dd41e/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.8 - Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sections\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"7317ecf5-d43d-4080-ad2a-7644764dd41e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7317ecf5-d43d-4080-ad2a-7644764dd41e?source=api-prod","cve":"CVE-2024-8902","affectedVersions":"<=1.13.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/7c6fe986-df68-4a62-9a43-5632c622b5fc/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.11.1 - Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-04-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"7c6fe986-df68-4a62-9a43-5632c622b5fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c6fe986-df68-4a62-9a43-5632c622b5fc?source=api-prod","cve":"CVE-2021-24259","affectedVersions":"<1.11.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/89489218-263f-4157-a5cd-a12bc6a0dfe6/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.7 - Missing Authorization to Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"89489218-263f-4157-a5cd-a12bc6a0dfe6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/89489218-263f-4157-a5cd-a12bc6a0dfe6?source=api-prod","cve":"CVE-2023-4723","affectedVersions":"<=1.12.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/8cb6639d-06ba-4bad-af73-d387a7e3f6b5/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.10 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"8cb6639d-06ba-4bad-af73-d387a7e3f6b5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8cb6639d-06ba-4bad-af73-d387a7e3f6b5?source=api-prod","cve":"CVE-2024-29107","affectedVersions":"<=1.12.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/94217d06-21c2-443d-ae2c-a2dbd65b7908/addon-elements-for-elementor-page-builder","title":"Addon Elements for Elementor <= 1.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-13 16:57:04","sources":[{"name":"Wordfence","remoteId":"94217d06-21c2-443d-ae2c-a2dbd65b7908"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/94217d06-21c2-443d-ae2c-a2dbd65b7908?source=api-prod","cve":"CVE-2025-12537","affectedVersions":"<=1.14.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/977bab12-969d-4b15-9942-2b17c8541f61/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Thumbnail Slider Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"977bab12-969d-4b15-9942-2b17c8541f61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/977bab12-969d-4b15-9942-2b17c8541f61?source=api-prod","cve":"CVE-2024-1391","affectedVersions":"<=1.12.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/a0297cab-8b6f-4e09-b552-4772c6f72c04/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.6.3 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-09-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"a0297cab-8b6f-4e09-b552-4772c6f72c04"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a0297cab-8b6f-4e09-b552-4772c6f72c04?source=api-prod","affectedVersions":"<1.6.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/ab5f43c0-83d3-4d09-becd-a3552bebd609/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"ab5f43c0-83d3-4d09-becd-a3552bebd609"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ab5f43c0-83d3-4d09-becd-a3552bebd609?source=api-prod","cve":"CVE-2024-4570","affectedVersions":"<=1.13.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/abe3cedb-53f3-48ff-a731-df6a83f0da1a/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"abe3cedb-53f3-48ff-a731-df6a83f0da1a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/abe3cedb-53f3-48ff-a731-df6a83f0da1a?source=api-prod","cve":"CVE-2024-30422","affectedVersions":"<=1.13.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/bb0888d6-30e6-4957-b270-1968eace462e/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Switcher Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"bb0888d6-30e6-4957-b270-1968eace462e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bb0888d6-30e6-4957-b270-1968eace462e?source=api-prod","cve":"CVE-2024-1393","affectedVersions":"<=1.12.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/bd2bc2e7-960e-40db-9dcc-a6a60117bd83/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.7 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"bd2bc2e7-960e-40db-9dcc-a6a60117bd83"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bd2bc2e7-960e-40db-9dcc-a6a60117bd83?source=api-prod","cve":"CVE-2023-5381","affectedVersions":"<=1.12.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/dcc5a611-23bf-499e-8141-684458d9ce3b/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Text Separator' and 'Image Compare' Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"dcc5a611-23bf-499e-8141-684458d9ce3b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dcc5a611-23bf-499e-8141-684458d9ce3b?source=api-prod","cve":"CVE-2024-2792","affectedVersions":"<=1.13.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/ecfc1466-41d2-498b-8210-c67e8550f5b8/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via id and eae_slider_animation Parameters\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-29 14:38:46","sources":[{"name":"Wordfence","remoteId":"ecfc1466-41d2-498b-8210-c67e8550f5b8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ecfc1466-41d2-498b-8210-c67e8550f5b8?source=api-prod","cve":"CVE-2024-4401","affectedVersions":"<=1.13.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/ef847b12-a380-410a-9368-6b2751d1836e/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"ef847b12-a380-410a-9368-6b2751d1836e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ef847b12-a380-410a-9368-6b2751d1836e?source=api-prod","cve":"CVE-2024-47366","affectedVersions":"<=1.13.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/f36fea15-0475-45ee-b913-790db6373aef/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"f36fea15-0475-45ee-b913-790db6373aef"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f36fea15-0475-45ee-b913-790db6373aef?source=api-prod","cve":"CVE-2024-3743","affectedVersions":"<=1.13.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/fd53b4e1-c6b7-4111-911a-04b14c7a9c4e/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.7 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd53b4e1-c6b7-4111-911a-04b14c7a9c4e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd53b4e1-c6b7-4111-911a-04b14c7a9c4e?source=api-prod","cve":"CVE-2023-4690","affectedVersions":"<=1.12.7","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/11e97adc-b402-4d82-ae39-4dccbd70bcf2/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.11.7 - Cross-Site Request Forgery\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-07-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"11e97adc-b402-4d82-ae39-4dccbd70bcf2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/11e97adc-b402-4d82-ae39-4dccbd70bcf2?source=api-prod","affectedVersions":"<=1.11.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/18e2e0e5-495f-4f55-b7d8-94193fc2ad12/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"18e2e0e5-495f-4f55-b7d8-94193fc2ad12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/18e2e0e5-495f-4f55-b7d8-94193fc2ad12?source=api-prod","cve":"CVE-2024-2091","affectedVersions":"<=1.13.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/20cd3fff-0488-4bc2-961b-2427925e6a96/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.12 - Directory Traversal to Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"20cd3fff-0488-4bc2-961b-2427925e6a96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/20cd3fff-0488-4bc2-961b-2427925e6a96?source=api-prod","cve":"CVE-2024-1358","affectedVersions":"<=1.12.12","severity":"high"},{"advisoryId":"WPSECADV/WF/33d7dc4d-bb41-456a-bd1a-37d8f2aada30/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Dual Button Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"33d7dc4d-bb41-456a-bd1a-37d8f2aada30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/33d7dc4d-bb41-456a-bd1a-37d8f2aada30?source=api-prod","cve":"CVE-2024-1392","affectedVersions":"<=1.12.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42/addon-elements-for-elementor-page-builder","title":"Freemius SDK <= 2.4.2 - Missing Authorization Checks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"39fb0499-9ab4-4a2f-b0db-ece86bcf4d42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=api-prod","cve":"CVE-2022-4974","affectedVersions":"<1.11.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/472cdbc4-3bfa-4254-b35a-be7ae10782e6/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.7 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"472cdbc4-3bfa-4254-b35a-be7ae10782e6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/472cdbc4-3bfa-4254-b35a-be7ae10782e6?source=api-prod","cve":"CVE-2023-4689","affectedVersions":"<=1.12.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/49690143-93c9-4d54-b98c-6f874f818175/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.14.4 - Authenticated (Contributor+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"49690143-93c9-4d54-b98c-6f874f818175"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/49690143-93c9-4d54-b98c-6f874f818175?source=api-prod","cve":"CVE-2026-28131","affectedVersions":"<=1.14.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/4ba28184-b5c3-4a5c-a376-29b3c6a2aa20/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Modal Popup effet\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"4ba28184-b5c3-4a5c-a376-29b3c6a2aa20"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ba28184-b5c3-4a5c-a376-29b3c6a2aa20?source=api-prod","cve":"CVE-2024-1422","affectedVersions":"<=1.12.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/4feacb75-0533-4f53-8ce9-3e45ee8336e2/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure via Modal Popup\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"4feacb75-0533-4f53-8ce9-3e45ee8336e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4feacb75-0533-4f53-8ce9-3e45ee8336e2?source=api-prod","cve":"CVE-2024-13215","affectedVersions":"<=1.13.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/5253fe2b-040b-417c-b257-0cb59ee5aa6e/addon-elements-for-elementor-page-builder","title":"Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"5253fe2b-040b-417c-b257-0cb59ee5aa6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5253fe2b-040b-417c-b257-0cb59ee5aa6e?source=api-prod","cve":"CVE-2023-33999","affectedVersions":"<=1.11.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/63ef7383-d684-473b-aa0f-45027ef245f6/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"63ef7383-d684-473b-aa0f-45027ef245f6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63ef7383-d684-473b-aa0f-45027ef245f6?source=api-prod","cve":"CVE-2024-4569","affectedVersions":"<=1.13.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/668621b0-67ef-44fc-a126-e8c4e372666e/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-29 20:31:53","sources":[{"name":"Wordfence","remoteId":"668621b0-67ef-44fc-a126-e8c4e372666e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/668621b0-67ef-44fc-a126-e8c4e372666e?source=api-prod","cve":"CVE-2024-7122","affectedVersions":"<=1.13.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/67790c0b-c078-4955-a175-977a695392fc/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-11 20:53:36","sources":[{"name":"Wordfence","remoteId":"67790c0b-c078-4955-a175-977a695392fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/67790c0b-c078-4955-a175-977a695392fc?source=api-prod","cve":"CVE-2024-2092","affectedVersions":"<=1.13.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/6ebb5654-ba3e-4f18-8720-a6595a771964/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.11 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"6ebb5654-ba3e-4f18-8720-a6595a771964"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6ebb5654-ba3e-4f18-8720-a6595a771964?source=api-prod","cve":"CVE-2024-0834","affectedVersions":"=1.12.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/6f8814b0-6818-47c2-9f2a-8fe12485bd33/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f8814b0-6818-47c2-9f2a-8fe12485bd33"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f8814b0-6818-47c2-9f2a-8fe12485bd33?source=api-prod","cve":"CVE-2024-47361","affectedVersions":"<=1.13.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/7317ecf5-d43d-4080-ad2a-7644764dd41e/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.8 - Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sections\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"7317ecf5-d43d-4080-ad2a-7644764dd41e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7317ecf5-d43d-4080-ad2a-7644764dd41e?source=api-prod","cve":"CVE-2024-8902","affectedVersions":"<=1.13.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/7c6fe986-df68-4a62-9a43-5632c622b5fc/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.11.1 - Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-04-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"7c6fe986-df68-4a62-9a43-5632c622b5fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7c6fe986-df68-4a62-9a43-5632c622b5fc?source=api-prod","cve":"CVE-2021-24259","affectedVersions":"<1.11.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/89489218-263f-4157-a5cd-a12bc6a0dfe6/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.7 - Missing Authorization to Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"89489218-263f-4157-a5cd-a12bc6a0dfe6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/89489218-263f-4157-a5cd-a12bc6a0dfe6?source=api-prod","cve":"CVE-2023-4723","affectedVersions":"<=1.12.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/8cb6639d-06ba-4bad-af73-d387a7e3f6b5/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.10 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"8cb6639d-06ba-4bad-af73-d387a7e3f6b5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8cb6639d-06ba-4bad-af73-d387a7e3f6b5?source=api-prod","cve":"CVE-2024-29107","affectedVersions":"<=1.12.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/94217d06-21c2-443d-ae2c-a2dbd65b7908/addon-elements-for-elementor-page-builder","title":"Addon Elements for Elementor <= 1.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-13 16:57:04","sources":[{"name":"Wordfence","remoteId":"94217d06-21c2-443d-ae2c-a2dbd65b7908"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/94217d06-21c2-443d-ae2c-a2dbd65b7908?source=api-prod","cve":"CVE-2025-12537","affectedVersions":"<=1.14.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/977bab12-969d-4b15-9942-2b17c8541f61/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Thumbnail Slider Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"977bab12-969d-4b15-9942-2b17c8541f61"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/977bab12-969d-4b15-9942-2b17c8541f61?source=api-prod","cve":"CVE-2024-1391","affectedVersions":"<=1.12.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/a0297cab-8b6f-4e09-b552-4772c6f72c04/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.6.3 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-09-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"a0297cab-8b6f-4e09-b552-4772c6f72c04"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a0297cab-8b6f-4e09-b552-4772c6f72c04?source=api-prod","affectedVersions":"<1.6.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/ab5f43c0-83d3-4d09-becd-a3552bebd609/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"ab5f43c0-83d3-4d09-becd-a3552bebd609"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ab5f43c0-83d3-4d09-becd-a3552bebd609?source=api-prod","cve":"CVE-2024-4570","affectedVersions":"<=1.13.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/abe3cedb-53f3-48ff-a731-df6a83f0da1a/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"abe3cedb-53f3-48ff-a731-df6a83f0da1a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/abe3cedb-53f3-48ff-a731-df6a83f0da1a?source=api-prod","cve":"CVE-2024-30422","affectedVersions":"<=1.13.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/bb0888d6-30e6-4957-b270-1968eace462e/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Switcher Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"bb0888d6-30e6-4957-b270-1968eace462e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bb0888d6-30e6-4957-b270-1968eace462e?source=api-prod","cve":"CVE-2024-1393","affectedVersions":"<=1.12.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/bd2bc2e7-960e-40db-9dcc-a6a60117bd83/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.7 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"bd2bc2e7-960e-40db-9dcc-a6a60117bd83"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bd2bc2e7-960e-40db-9dcc-a6a60117bd83?source=api-prod","cve":"CVE-2023-5381","affectedVersions":"<=1.12.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/dcc5a611-23bf-499e-8141-684458d9ce3b/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Text Separator' and 'Image Compare' Widget\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"dcc5a611-23bf-499e-8141-684458d9ce3b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dcc5a611-23bf-499e-8141-684458d9ce3b?source=api-prod","cve":"CVE-2024-2792","affectedVersions":"<=1.13.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/ecfc1466-41d2-498b-8210-c67e8550f5b8/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via id and eae_slider_animation Parameters\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-29 14:38:46","sources":[{"name":"Wordfence","remoteId":"ecfc1466-41d2-498b-8210-c67e8550f5b8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ecfc1466-41d2-498b-8210-c67e8550f5b8?source=api-prod","cve":"CVE-2024-4401","affectedVersions":"<=1.13.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/ef847b12-a380-410a-9368-6b2751d1836e/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"ef847b12-a380-410a-9368-6b2751d1836e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ef847b12-a380-410a-9368-6b2751d1836e?source=api-prod","cve":"CVE-2024-47366","affectedVersions":"<=1.13.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/f36fea15-0475-45ee-b913-790db6373aef/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.13.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"f36fea15-0475-45ee-b913-790db6373aef"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f36fea15-0475-45ee-b913-790db6373aef?source=api-prod","cve":"CVE-2024-3743","affectedVersions":"<=1.13.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/fd53b4e1-c6b7-4111-911a-04b14c7a9c4e/addon-elements-for-elementor-page-builder","title":"Elementor Addon Elements <= 1.12.7 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd53b4e1-c6b7-4111-911a-04b14c7a9c4e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd53b4e1-c6b7-4111-911a-04b14c7a9c4e?source=api-prod","cve":"CVE-2023-4690","affectedVersions":"<=1.12.7","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_616476616e6365642d776f6f2d6c6162656c73811c9dc5_gen.json b/internal/data/assets/plugin_616476616e6365642d776f6f2d6c6162656c73811c9dc5_gen.json index 70d43082..c0ed12d8 100644 --- a/internal/data/assets/plugin_616476616e6365642d776f6f2d6c6162656c73811c9dc5_gen.json +++ b/internal/data/assets/plugin_616476616e6365642d776f6f2d6c6162656c73811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/03fa3a62-c5b7-4772-b8fe-26ae476b4ae4/advanced-woo-labels","title":"Advanced Woo Labels <= 2.15 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"03fa3a62-c5b7-4772-b8fe-26ae476b4ae4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/03fa3a62-c5b7-4772-b8fe-26ae476b4ae4?source=api-prod","cve":"CVE-2025-32188","affectedVersions":"<=2.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/4bfde95b-70bf-4445-a8b0-53dbdc5d2334/advanced-woo-labels","title":"Advanced Woo Labels <= 2.01 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"4bfde95b-70bf-4445-a8b0-53dbdc5d2334"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4bfde95b-70bf-4445-a8b0-53dbdc5d2334?source=api-prod","cve":"CVE-2024-47622","affectedVersions":"<=2.01","severity":"medium"},{"advisoryId":"WPSECADV/WF/bbae9c33-becb-4c9d-917f-0d8fe8312d0c/advanced-woo-labels","title":"Advanced Woo Labels <= 2.37 - Authenticated (Contributor+) Remote Code Execution via 'callback' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-24 19:54:05","sources":[{"name":"Wordfence","remoteId":"bbae9c33-becb-4c9d-917f-0d8fe8312d0c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bbae9c33-becb-4c9d-917f-0d8fe8312d0c?source=api-prod","cve":"CVE-2026-1929","affectedVersions":"<=2.36","severity":"high"},{"advisoryId":"WPSECADV/WF/cc9d8d04-78af-4e43-8a51-89ece1d80336/advanced-woo-labels","title":"Advanced Woo Labels – Product Labels for WooCommerce <= 1.93 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"cc9d8d04-78af-4e43-8a51-89ece1d80336"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc9d8d04-78af-4e43-8a51-89ece1d80336?source=api-prod","cve":"CVE-2024-35675","affectedVersions":"<=1.93","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/03fa3a62-c5b7-4772-b8fe-26ae476b4ae4/advanced-woo-labels","title":"Advanced Woo Labels <= 2.15 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"03fa3a62-c5b7-4772-b8fe-26ae476b4ae4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/03fa3a62-c5b7-4772-b8fe-26ae476b4ae4?source=api-prod","cve":"CVE-2025-32188","affectedVersions":"<=2.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/4bfde95b-70bf-4445-a8b0-53dbdc5d2334/advanced-woo-labels","title":"Advanced Woo Labels <= 2.01 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"4bfde95b-70bf-4445-a8b0-53dbdc5d2334"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4bfde95b-70bf-4445-a8b0-53dbdc5d2334?source=api-prod","cve":"CVE-2024-47622","affectedVersions":"<=2.01","severity":"medium"},{"advisoryId":"WPSECADV/WF/b591b7df-8492-4f66-8884-b4b27c0f0a11/advanced-woo-labels","title":"Advanced Woo Labels <= 2.36 - Authenticated (Admin+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"b591b7df-8492-4f66-8884-b4b27c0f0a11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b591b7df-8492-4f66-8884-b4b27c0f0a11?source=api-prod","cve":"CVE-2026-32414","affectedVersions":"<=2.36","severity":"high"},{"advisoryId":"WPSECADV/WF/bbae9c33-becb-4c9d-917f-0d8fe8312d0c/advanced-woo-labels","title":"Advanced Woo Labels <= 2.37 - Authenticated (Contributor+) Remote Code Execution via 'callback' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-24 19:54:05","sources":[{"name":"Wordfence","remoteId":"bbae9c33-becb-4c9d-917f-0d8fe8312d0c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bbae9c33-becb-4c9d-917f-0d8fe8312d0c?source=api-prod","cve":"CVE-2026-1929","affectedVersions":"<=2.36","severity":"high"},{"advisoryId":"WPSECADV/WF/cc9d8d04-78af-4e43-8a51-89ece1d80336/advanced-woo-labels","title":"Advanced Woo Labels – Product Labels for WooCommerce <= 1.93 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"cc9d8d04-78af-4e43-8a51-89ece1d80336"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc9d8d04-78af-4e43-8a51-89ece1d80336?source=api-prod","cve":"CVE-2024-35675","affectedVersions":"<=1.93","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_61692d656e67696e652d70726f811c9dc5_gen.json b/internal/data/assets/plugin_61692d656e67696e652d70726f811c9dc5_gen.json new file mode 100644 index 00000000..fc123c0e --- /dev/null +++ b/internal/data/assets/plugin_61692d656e67696e652d70726f811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/5da8a4d4-9c98-4ee1-affd-105c88528c56/ai-engine-pro","title":"AI Engine (Pro) < 3.4.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"5da8a4d4-9c98-4ee1-affd-105c88528c56"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5da8a4d4-9c98-4ee1-affd-105c88528c56?source=api-prod","cve":"CVE-2026-39506","affectedVersions":"<3.4.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_616c6c2d696e2d6f6e652d77702d6d6967726174696f6e2d756e6c696d697465642d657874656e73696f6e811c9dc5_gen.json b/internal/data/assets/plugin_616c6c2d696e2d6f6e652d77702d6d6967726174696f6e2d756e6c696d697465642d657874656e73696f6e811c9dc5_gen.json new file mode 100644 index 00000000..0b1d786c --- /dev/null +++ b/internal/data/assets/plugin_616c6c2d696e2d6f6e652d77702d6d6967726174696f6e2d756e6c696d697465642d657874656e73696f6e811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/a8a31080-c124-49be-b9d1-7bc5abe7cbda/all-in-one-wp-migration-unlimited-extension","title":"All-in-One WP Migration Unlimited Extension <= 2.83 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Backup Schedule Creation and Backup File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-05 14:37:19","sources":[{"name":"Wordfence","remoteId":"a8a31080-c124-49be-b9d1-7bc5abe7cbda"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a8a31080-c124-49be-b9d1-7bc5abe7cbda?source=api-prod","cve":"CVE-2026-5753","affectedVersions":"<=2.83","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_622d626c6f636b73811c9dc5_gen.json b/internal/data/assets/plugin_622d626c6f636b73811c9dc5_gen.json index 9dc1fdaf..c2341c42 100644 --- a/internal/data/assets/plugin_622d626c6f636b73811c9dc5_gen.json +++ b/internal/data/assets/plugin_622d626c6f636b73811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0ee3b389-60c9-4f8e-9428-a71a6d9b20aa/b-blocks","title":"B Blocks <= 2.0.6 - Missing Authorization to Unauthenticated Privilege Escalation via rgfr_registration Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-11 16:24:23","sources":[{"name":"Wordfence","remoteId":"0ee3b389-60c9-4f8e-9428-a71a6d9b20aa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0ee3b389-60c9-4f8e-9428-a71a6d9b20aa?source=api-prod","cve":"CVE-2025-8059","affectedVersions":"<=2.0.6","severity":"critical"},{"advisoryId":"WPSECADV/WF/89218de3-7bb9-42f5-86d8-48d28c380231/b-blocks","title":"bBlocks – Essential Gutenberg Blocks & Patterns Collection <= 2.0.31 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"89218de3-7bb9-42f5-86d8-48d28c380231"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/89218de3-7bb9-42f5-86d8-48d28c380231?source=api-prod","cve":"CVE-2026-39579","affectedVersions":"<=2.0.31","severity":"high"},{"advisoryId":"WPSECADV/WF/a49eaeb9-1395-4ec3-b030-1de898ad0769/b-blocks","title":"B Blocks <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"a49eaeb9-1395-4ec3-b030-1de898ad0769"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a49eaeb9-1395-4ec3-b030-1de898ad0769?source=api-prod","cve":"CVE-2025-54708","affectedVersions":"<=2.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/b120d99e-5906-4c7f-b10a-1f915a8ff6d6/b-blocks","title":"B Blocks - The ultimate block collection <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"b120d99e-5906-4c7f-b10a-1f915a8ff6d6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b120d99e-5906-4c7f-b10a-1f915a8ff6d6?source=api-prod","cve":"CVE-2025-32173","affectedVersions":"<=2.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/d694491c-c0f5-4418-805a-db792ea4f712/b-blocks","title":"Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-30 17:17:30","sources":[{"name":"Wordfence","remoteId":"d694491c-c0f5-4418-805a-db792ea4f712"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d694491c-c0f5-4418-805a-db792ea4f712?source=api-prod","cve":"CVE-2024-13362","affectedVersions":"<=1.9.8","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0ee3b389-60c9-4f8e-9428-a71a6d9b20aa/b-blocks","title":"B Blocks <= 2.0.6 - Missing Authorization to Unauthenticated Privilege Escalation via rgfr_registration Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-11 16:24:23","sources":[{"name":"Wordfence","remoteId":"0ee3b389-60c9-4f8e-9428-a71a6d9b20aa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0ee3b389-60c9-4f8e-9428-a71a6d9b20aa?source=api-prod","cve":"CVE-2025-8059","affectedVersions":"<=2.0.6","severity":"critical"},{"advisoryId":"WPSECADV/WF/78c3c57f-9e52-42c4-9e94-806fe5fb75f9/b-blocks","title":"bBlocks – Essential Gutenberg Blocks & Patterns Collection < 2.0.30 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"78c3c57f-9e52-42c4-9e94-806fe5fb75f9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/78c3c57f-9e52-42c4-9e94-806fe5fb75f9?source=api-prod","cve":"CVE-2026-32489","affectedVersions":"<2.0.30","severity":"medium"},{"advisoryId":"WPSECADV/WF/89218de3-7bb9-42f5-86d8-48d28c380231/b-blocks","title":"bBlocks – Essential Gutenberg Blocks & Patterns Collection <= 2.0.31 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"89218de3-7bb9-42f5-86d8-48d28c380231"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/89218de3-7bb9-42f5-86d8-48d28c380231?source=api-prod","cve":"CVE-2026-39579","affectedVersions":"<=2.0.31","severity":"high"},{"advisoryId":"WPSECADV/WF/a49eaeb9-1395-4ec3-b030-1de898ad0769/b-blocks","title":"B Blocks <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"a49eaeb9-1395-4ec3-b030-1de898ad0769"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a49eaeb9-1395-4ec3-b030-1de898ad0769?source=api-prod","cve":"CVE-2025-54708","affectedVersions":"<=2.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/b120d99e-5906-4c7f-b10a-1f915a8ff6d6/b-blocks","title":"B Blocks - The ultimate block collection <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"b120d99e-5906-4c7f-b10a-1f915a8ff6d6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b120d99e-5906-4c7f-b10a-1f915a8ff6d6?source=api-prod","cve":"CVE-2025-32173","affectedVersions":"<=2.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/d694491c-c0f5-4418-805a-db792ea4f712/b-blocks","title":"Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-30 17:17:30","sources":[{"name":"Wordfence","remoteId":"d694491c-c0f5-4418-805a-db792ea4f712"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d694491c-c0f5-4418-805a-db792ea4f712?source=api-prod","cve":"CVE-2024-13362","affectedVersions":"<=1.9.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6232626b696e67811c9dc5_gen.json b/internal/data/assets/plugin_6232626b696e67811c9dc5_gen.json new file mode 100644 index 00000000..66943034 --- /dev/null +++ b/internal/data/assets/plugin_6232626b696e67811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/69a6d8a5-0325-4436-8034-8353d2a68831/b2bking","title":"B2BKing Premium < 5.4.20 - Unauthenticated Open Redirect\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"69a6d8a5-0325-4436-8034-8353d2a68831"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/69a6d8a5-0325-4436-8034-8353d2a68831?source=api-prod","cve":"CVE-2026-28106","affectedVersions":"<5.4.20","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_62736b2d7064662d6d616e61676572811c9dc5_gen.json b/internal/data/assets/plugin_62736b2d7064662d6d616e61676572811c9dc5_gen.json index b7ed11b2..4037bf22 100644 --- a/internal/data/assets/plugin_62736b2d7064662d6d616e61676572811c9dc5_gen.json +++ b/internal/data/assets/plugin_62736b2d7064662d6d616e61676572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0b748dc9-4d44-41dd-b159-380214e7646a/bsk-pdf-manager","title":"BSK PDF Manager <= 1.4 - Authenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"0b748dc9-4d44-41dd-b159-380214e7646a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0b748dc9-4d44-41dd-b159-380214e7646a?source=api-prod","cve":"CVE-2014-4944","affectedVersions":"<1.5","severity":"critical"},{"advisoryId":"WPSECADV/WF/37506a9e-a225-4519-a24e-8678c31cc106/bsk-pdf-manager","title":"BSK PDF Manager <= 3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"37506a9e-a225-4519-a24e-8678c31cc106"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/37506a9e-a225-4519-a24e-8678c31cc106?source=api-prod","cve":"CVE-2024-38767","affectedVersions":"<=3.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/3cf1983b-4cb7-4738-9f19-2c530a9939e0/bsk-pdf-manager","title":"BSK PDF Manager <= 3.7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"3cf1983b-4cb7-4738-9f19-2c530a9939e0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3cf1983b-4cb7-4738-9f19-2c530a9939e0?source=api-prod","cve":"CVE-2025-4970","affectedVersions":"<=3.7.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/60de55c6-e4fa-453e-84bd-309f2887e3cb/bsk-pdf-manager","title":"BSK PDF Manager <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"60de55c6-e4fa-453e-84bd-309f2887e3cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/60de55c6-e4fa-453e-84bd-309f2887e3cb?source=api-prod","cve":"CVE-2023-5110","affectedVersions":"<=3.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/667d964a-dba6-424a-b3f5-af433616c132/bsk-pdf-manager","title":"BSK PDF Manager 1.3 - 2.9 - Authenticated Stored Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"667d964a-dba6-424a-b3f5-af433616c132"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/667d964a-dba6-424a-b3f5-af433616c132?source=api-prod","affectedVersions":">=1.3,<=2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/8ce7aa01-7e79-4048-a84d-fcb9541d5f8b/bsk-pdf-manager","title":"PDF.js < 4.2.67 - Arbitrary JavaScript Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ce7aa01-7e79-4048-a84d-fcb9541d5f8b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ce7aa01-7e79-4048-a84d-fcb9541d5f8b?source=api-prod","cve":"CVE-2024-4367","affectedVersions":"<=3.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/9a2ee9bb-ae20-47ae-b792-438bf7be6cc4/bsk-pdf-manager","title":"BSK PDF Manager <= 3.1.1 - Admin+ SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"9a2ee9bb-ae20-47ae-b792-438bf7be6cc4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9a2ee9bb-ae20-47ae-b792-438bf7be6cc4?source=api-prod","cve":"CVE-2021-24860","affectedVersions":"<3.1.2","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0b748dc9-4d44-41dd-b159-380214e7646a/bsk-pdf-manager","title":"BSK PDF Manager <= 1.4 - Authenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"0b748dc9-4d44-41dd-b159-380214e7646a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0b748dc9-4d44-41dd-b159-380214e7646a?source=api-prod","cve":"CVE-2014-4944","affectedVersions":"<1.5","severity":"critical"},{"advisoryId":"WPSECADV/WF/336f4272-135c-4601-84fe-087390dbf5ef/bsk-pdf-manager","title":"BSK PDF Manager <= 3.7.2 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"336f4272-135c-4601-84fe-087390dbf5ef"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/336f4272-135c-4601-84fe-087390dbf5ef?source=api-prod","cve":"CVE-2026-39686","affectedVersions":"<=3.7.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/37506a9e-a225-4519-a24e-8678c31cc106/bsk-pdf-manager","title":"BSK PDF Manager <= 3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"37506a9e-a225-4519-a24e-8678c31cc106"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/37506a9e-a225-4519-a24e-8678c31cc106?source=api-prod","cve":"CVE-2024-38767","affectedVersions":"<=3.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/3cf1983b-4cb7-4738-9f19-2c530a9939e0/bsk-pdf-manager","title":"BSK PDF Manager <= 3.7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"3cf1983b-4cb7-4738-9f19-2c530a9939e0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3cf1983b-4cb7-4738-9f19-2c530a9939e0?source=api-prod","cve":"CVE-2025-4970","affectedVersions":"<=3.7.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/60de55c6-e4fa-453e-84bd-309f2887e3cb/bsk-pdf-manager","title":"BSK PDF Manager <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"60de55c6-e4fa-453e-84bd-309f2887e3cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/60de55c6-e4fa-453e-84bd-309f2887e3cb?source=api-prod","cve":"CVE-2023-5110","affectedVersions":"<=3.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/667d964a-dba6-424a-b3f5-af433616c132/bsk-pdf-manager","title":"BSK PDF Manager 1.3 - 2.9 - Authenticated Stored Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"667d964a-dba6-424a-b3f5-af433616c132"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/667d964a-dba6-424a-b3f5-af433616c132?source=api-prod","affectedVersions":">=1.3,<=2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/8ce7aa01-7e79-4048-a84d-fcb9541d5f8b/bsk-pdf-manager","title":"PDF.js < 4.2.67 - Arbitrary JavaScript Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ce7aa01-7e79-4048-a84d-fcb9541d5f8b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ce7aa01-7e79-4048-a84d-fcb9541d5f8b?source=api-prod","cve":"CVE-2024-4367","affectedVersions":"<=3.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/9a2ee9bb-ae20-47ae-b792-438bf7be6cc4/bsk-pdf-manager","title":"BSK PDF Manager <= 3.1.1 - Admin+ SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"9a2ee9bb-ae20-47ae-b792-438bf7be6cc4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9a2ee9bb-ae20-47ae-b792-438bf7be6cc4?source=api-prod","cve":"CVE-2021-24860","affectedVersions":"<3.1.2","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6275732d7469636b65742d626f6f6b696e672d776974682d736561742d7265736572766174696f6e811c9dc5_gen.json b/internal/data/assets/plugin_6275732d7469636b65742d626f6f6b696e672d776974682d736561742d7265736572766174696f6e811c9dc5_gen.json index 8e1ed293..ecc269d2 100644 --- a/internal/data/assets/plugin_6275732d7469636b65742d626f6f6b696e672d776974682d736561742d7265736572766174696f6e811c9dc5_gen.json +++ b/internal/data/assets/plugin_6275732d7469636b65742d626f6f6b696e672d776974682d736561742d7265736572766174696f6e811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/bbe5d631-8f2a-49a9-aeb8-b9965a5875ca/bus-ticket-booking-with-seat-reservation","title":"Bus Ticket Booking with Seat Reservation <= 5.6.2 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"bbe5d631-8f2a-49a9-aeb8-b9965a5875ca"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bbe5d631-8f2a-49a9-aeb8-b9965a5875ca?source=api-prod","cve":"CVE-2026-27095","affectedVersions":"<=5.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/e9960282-4730-4ee8-b338-adcc57f01cc6/bus-ticket-booking-with-seat-reservation","title":"Bus Ticket Booking with Seat Reservation <= 5.2.5 - Unauthenticated Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"e9960282-4730-4ee8-b338-adcc57f01cc6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e9960282-4730-4ee8-b338-adcc57f01cc6?source=api-prod","cve":"CVE-2023-30496","affectedVersions":"<=5.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/f75c3ed0-3b05-4132-b102-ba64fb8c338d/bus-ticket-booking-with-seat-reservation","title":"Bus Ticket Booking with Seat Reservation <= 5.4.3 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"f75c3ed0-3b05-4132-b102-ba64fb8c338d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f75c3ed0-3b05-4132-b102-ba64fb8c338d?source=api-prod","cve":"CVE-2024-49294","affectedVersions":"<=5.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/ff2855cb-e4a8-4412-af24-4cee03ae2d43/bus-ticket-booking-with-seat-reservation","title":"Bus Ticket Booking with Seat Reservation <= 5.2.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"ff2855cb-e4a8-4412-af24-4cee03ae2d43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ff2855cb-e4a8-4412-af24-4cee03ae2d43?source=api-prod","cve":"CVE-2023-4067","affectedVersions":"<=5.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/ffc92f28-02bd-48b3-b803-b67feab74db2/bus-ticket-booking-with-seat-reservation","title":"Bus Ticket Booking with Seat Reservation <= 5.3.5 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"ffc92f28-02bd-48b3-b803-b67feab74db2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ffc92f28-02bd-48b3-b803-b67feab74db2?source=api-prod","cve":"CVE-2024-43985","affectedVersions":"<=5.3.5","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/8a3a1769-fda2-43ca-b201-35eaeda77c6d/bus-ticket-booking-with-seat-reservation","title":"Bus Ticket Booking with Seat Reservation < 5.6.5 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"8a3a1769-fda2-43ca-b201-35eaeda77c6d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8a3a1769-fda2-43ca-b201-35eaeda77c6d?source=api-prod","cve":"CVE-2026-39572","affectedVersions":"<5.6.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/bbe5d631-8f2a-49a9-aeb8-b9965a5875ca/bus-ticket-booking-with-seat-reservation","title":"Bus Ticket Booking with Seat Reservation <= 5.6.2 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"bbe5d631-8f2a-49a9-aeb8-b9965a5875ca"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bbe5d631-8f2a-49a9-aeb8-b9965a5875ca?source=api-prod","cve":"CVE-2026-27095","affectedVersions":"<=5.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/e9960282-4730-4ee8-b338-adcc57f01cc6/bus-ticket-booking-with-seat-reservation","title":"Bus Ticket Booking with Seat Reservation <= 5.2.5 - Unauthenticated Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"e9960282-4730-4ee8-b338-adcc57f01cc6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e9960282-4730-4ee8-b338-adcc57f01cc6?source=api-prod","cve":"CVE-2023-30496","affectedVersions":"<=5.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/f75c3ed0-3b05-4132-b102-ba64fb8c338d/bus-ticket-booking-with-seat-reservation","title":"Bus Ticket Booking with Seat Reservation <= 5.4.3 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"f75c3ed0-3b05-4132-b102-ba64fb8c338d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f75c3ed0-3b05-4132-b102-ba64fb8c338d?source=api-prod","cve":"CVE-2024-49294","affectedVersions":"<=5.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/ff2855cb-e4a8-4412-af24-4cee03ae2d43/bus-ticket-booking-with-seat-reservation","title":"Bus Ticket Booking with Seat Reservation <= 5.2.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"ff2855cb-e4a8-4412-af24-4cee03ae2d43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ff2855cb-e4a8-4412-af24-4cee03ae2d43?source=api-prod","cve":"CVE-2023-4067","affectedVersions":"<=5.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/ffc92f28-02bd-48b3-b803-b67feab74db2/bus-ticket-booking-with-seat-reservation","title":"Bus Ticket Booking with Seat Reservation <= 5.3.5 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"ffc92f28-02bd-48b3-b803-b67feab74db2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ffc92f28-02bd-48b3-b803-b67feab74db2?source=api-prod","cve":"CVE-2024-43985","affectedVersions":"<=5.3.5","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_636f6d696e672d736f6f6e811c9dc5_gen.json b/internal/data/assets/plugin_636f6d696e672d736f6f6e811c9dc5_gen.json index 414756d6..5f9ce799 100644 --- a/internal/data/assets/plugin_636f6d696e672d736f6f6e811c9dc5_gen.json +++ b/internal/data/assets/plugin_636f6d696e672d736f6f6e811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/2cb5370f-14aa-445d-bda3-62a0dd068fc5/coming-soon","title":"Website Builder by SeedProd <= 6.15.13.1 - Cross-Site Request Forgery to Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"2cb5370f-14aa-445d-bda3-62a0dd068fc5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2cb5370f-14aa-445d-bda3-62a0dd068fc5?source=api-prod","cve":"CVE-2023-4975","affectedVersions":"<=6.15.13.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/32ce92b9-8c9c-4a7e-9580-00a564500e30/coming-soon","title":"Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.19.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"32ce92b9-8c9c-4a7e-9580-00a564500e30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/32ce92b9-8c9c-4a7e-9580-00a564500e30?source=api-prod","cve":"CVE-2026-27368","affectedVersions":"<=6.19.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/4fe784a0-d466-4124-b712-18c19f9de53a/coming-soon","title":"Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.18.9 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"4fe784a0-d466-4124-b712-18c19f9de53a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4fe784a0-d466-4124-b712-18c19f9de53a?source=api-prod","cve":"CVE-2025-24540","affectedVersions":"<=6.18.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/60c6c9a8-e04d-49e2-96e8-16d7580a3e2c/coming-soon","title":"Coming Soon Page, Under Construction & Maintenance Mode by SeedProd <= 6.15.20 - Cross-Site Request Forgery to Notice Dismissal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"60c6c9a8-e04d-49e2-96e8-16d7580a3e2c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/60c6c9a8-e04d-49e2-96e8-16d7580a3e2c?source=api-prod","cve":"CVE-2024-32088","affectedVersions":"<=6.15.20","severity":"medium"},{"advisoryId":"WPSECADV/WF/669b0f30-8958-420c-93c5-0103b71967dd/coming-soon","title":"Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.18.15 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"669b0f30-8958-420c-93c5-0103b71967dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/669b0f30-8958-420c-93c5-0103b71967dd?source=api-prod","cve":"CVE-2025-3949","affectedVersions":"<=6.18.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/78d7920b-3e20-43c7-a522-72bac824c2cb/coming-soon","title":"Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.15.21 - Missing Authorization via seedprod_lite_new_lpage\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"78d7920b-3e20-43c7-a522-72bac824c2cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/78d7920b-3e20-43c7-a522-72bac824c2cb?source=api-prod","cve":"CVE-2024-1072","affectedVersions":"<=6.15.21","severity":"high"},{"advisoryId":"WPSECADV/WF/caa0f581-3fe8-4b9f-b69c-ec38ee25d697/coming-soon","title":"Coming Soon Page by SeedProd <= 5.1.1 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-06-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"caa0f581-3fe8-4b9f-b69c-ec38ee25d697"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/caa0f581-3fe8-4b9f-b69c-ec38ee25d697?source=api-prod","cve":"CVE-2020-15038","affectedVersions":"<5.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/dc4c4f01-cc48-47a3-a7b7-025b261ab54c/coming-soon","title":"Coming Soon Page, Under Construction & Maintenance Mode by SeedProd <= 6.17.4 - Authenticated (Editor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"dc4c4f01-cc48-47a3-a7b7-025b261ab54c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dc4c4f01-cc48-47a3-a7b7-025b261ab54c?source=api-prod","cve":"CVE-2024-47299","affectedVersions":"<=6.17.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/2cb5370f-14aa-445d-bda3-62a0dd068fc5/coming-soon","title":"Website Builder by SeedProd <= 6.15.13.1 - Cross-Site Request Forgery to Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"2cb5370f-14aa-445d-bda3-62a0dd068fc5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2cb5370f-14aa-445d-bda3-62a0dd068fc5?source=api-prod","cve":"CVE-2023-4975","affectedVersions":"<=6.15.13.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/32ce92b9-8c9c-4a7e-9580-00a564500e30/coming-soon","title":"Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.19.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"32ce92b9-8c9c-4a7e-9580-00a564500e30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/32ce92b9-8c9c-4a7e-9580-00a564500e30?source=api-prod","cve":"CVE-2026-27368","affectedVersions":"<=6.19.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/4fe784a0-d466-4124-b712-18c19f9de53a/coming-soon","title":"Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.18.9 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"4fe784a0-d466-4124-b712-18c19f9de53a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4fe784a0-d466-4124-b712-18c19f9de53a?source=api-prod","cve":"CVE-2025-24540","affectedVersions":"<=6.18.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/60c6c9a8-e04d-49e2-96e8-16d7580a3e2c/coming-soon","title":"Coming Soon Page, Under Construction & Maintenance Mode by SeedProd <= 6.15.20 - Cross-Site Request Forgery to Notice Dismissal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"60c6c9a8-e04d-49e2-96e8-16d7580a3e2c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/60c6c9a8-e04d-49e2-96e8-16d7580a3e2c?source=api-prod","cve":"CVE-2024-32088","affectedVersions":"<=6.15.20","severity":"medium"},{"advisoryId":"WPSECADV/WF/669b0f30-8958-420c-93c5-0103b71967dd/coming-soon","title":"Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.18.15 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"669b0f30-8958-420c-93c5-0103b71967dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/669b0f30-8958-420c-93c5-0103b71967dd?source=api-prod","cve":"CVE-2025-3949","affectedVersions":"<=6.18.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/78d7920b-3e20-43c7-a522-72bac824c2cb/coming-soon","title":"Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.15.21 - Missing Authorization via seedprod_lite_new_lpage\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"78d7920b-3e20-43c7-a522-72bac824c2cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/78d7920b-3e20-43c7-a522-72bac824c2cb?source=api-prod","cve":"CVE-2024-1072","affectedVersions":"<=6.15.21","severity":"high"},{"advisoryId":"WPSECADV/WF/87246b00-7a61-4ab4-90f1-2ac42f5b9f1d/coming-soon","title":"Coming Soon Page, Under Construction & Maintenance Mode by SeedProd <= 6.19.8 - Authenticated (Editor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"87246b00-7a61-4ab4-90f1-2ac42f5b9f1d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/87246b00-7a61-4ab4-90f1-2ac42f5b9f1d?source=api-prod","cve":"CVE-2026-39464","affectedVersions":"<=6.19.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/caa0f581-3fe8-4b9f-b69c-ec38ee25d697/coming-soon","title":"Coming Soon Page by SeedProd <= 5.1.1 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-06-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"caa0f581-3fe8-4b9f-b69c-ec38ee25d697"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/caa0f581-3fe8-4b9f-b69c-ec38ee25d697?source=api-prod","cve":"CVE-2020-15038","affectedVersions":"<5.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/dc4c4f01-cc48-47a3-a7b7-025b261ab54c/coming-soon","title":"Coming Soon Page, Under Construction & Maintenance Mode by SeedProd <= 6.17.4 - Authenticated (Editor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"dc4c4f01-cc48-47a3-a7b7-025b261ab54c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dc4c4f01-cc48-47a3-a7b7-025b261ab54c?source=api-prod","cve":"CVE-2024-47299","affectedVersions":"<=6.17.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_636f6d70757465722d7265706169722d73686f70811c9dc5_gen.json b/internal/data/assets/plugin_636f6d70757465722d7265706169722d73686f70811c9dc5_gen.json index 566374cd..dca2eb70 100644 --- a/internal/data/assets/plugin_636f6d70757465722d7265706169722d73686f70811c9dc5_gen.json +++ b/internal/data/assets/plugin_636f6d70757465722d7265706169722d73686f70811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/03b1376e-8ef3-4bd2-904b-6819aa21d144/computer-repair-shop","title":"Computer Repair Shop < 2.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-01-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"03b1376e-8ef3-4bd2-904b-6819aa21d144"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/03b1376e-8ef3-4bd2-904b-6819aa21d144?source=api-prod","affectedVersions":"<2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/1b2ad299-03b1-4b9e-a241-d2ad2d85c3ac/computer-repair-shop","title":"RepairBuddy <= 4.1116 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Signature Upload to Orders\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-16 14:36:16","sources":[{"name":"Wordfence","remoteId":"1b2ad299-03b1-4b9e-a241-d2ad2d85c3ac"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b2ad299-03b1-4b9e-a241-d2ad2d85c3ac?source=api-prod","cve":"CVE-2026-0820","affectedVersions":"<=4.1116","severity":"medium"},{"advisoryId":"WPSECADV/WF/52cdd3fe-9b53-4c7c-9538-e0c475d06ed3/computer-repair-shop","title":"CRM WordPress Plugin – RepairBuddy <= 3.8213 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"52cdd3fe-9b53-4c7c-9538-e0c475d06ed3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/52cdd3fe-9b53-4c7c-9538-e0c475d06ed3?source=api-prod","cve":"CVE-2025-32277","affectedVersions":"<=3.8213","severity":"medium"},{"advisoryId":"WPSECADV/WF/642a6d42-100f-4461-b568-35e089287902/computer-repair-shop","title":"CRM WordPress Plugin – RepairBuddy <= 3.72 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-05-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"642a6d42-100f-4461-b568-35e089287902"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/642a6d42-100f-4461-b568-35e089287902?source=api-prod","affectedVersions":"<=3.72","severity":"high"},{"advisoryId":"WPSECADV/WF/740ed055-8548-42fd-81e1-9f63dda85374/computer-repair-shop","title":"Computer Repair Shop <= 3.8119 - Authenticated (Customer+) Privilege Esclation via Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"740ed055-8548-42fd-81e1-9f63dda85374"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/740ed055-8548-42fd-81e1-9f63dda85374?source=api-prod","cve":"CVE-2024-56061","affectedVersions":"<=3.8119","severity":"critical"},{"advisoryId":"WPSECADV/WF/789670b1-8cc3-4b66-87e3-a0da6fbd2706/computer-repair-shop","title":"Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"789670b1-8cc3-4b66-87e3-a0da6fbd2706"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/789670b1-8cc3-4b66-87e3-a0da6fbd2706?source=api-prod","cve":"CVE-2024-51793","affectedVersions":"<=3.8115","severity":"critical"},{"advisoryId":"WPSECADV/WF/80997d2f-3e16-48f6-969b-58844cb83d53/computer-repair-shop","title":"CRM WordPress Plugin – RepairBuddy <= 3.8120 - Missing Authorization to Account Takeover/Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"80997d2f-3e16-48f6-969b-58844cb83d53"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/80997d2f-3e16-48f6-969b-58844cb83d53?source=api-prod","cve":"CVE-2024-12259","affectedVersions":"<=3.8120","severity":"high"},{"advisoryId":"WPSECADV/WF/bb4b3778-7211-4a56-a2e5-1f455f356dd5/computer-repair-shop","title":"RepairBuddy <= 4.1132 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification via wc_rep_shop_settings_submission AJAX Action\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"bb4b3778-7211-4a56-a2e5-1f455f356dd5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bb4b3778-7211-4a56-a2e5-1f455f356dd5?source=api-prod","cve":"CVE-2026-3567","affectedVersions":"<=4.1132","severity":"medium"},{"advisoryId":"WPSECADV/WF/f570a9d2-41d7-42f2-9f13-4cda97ea2219/computer-repair-shop","title":"RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1132 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"f570a9d2-41d7-42f2-9f13-4cda97ea2219"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f570a9d2-41d7-42f2-9f13-4cda97ea2219?source=api-prod","cve":"CVE-2026-39584","affectedVersions":"<=4.1132","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/03b1376e-8ef3-4bd2-904b-6819aa21d144/computer-repair-shop","title":"Computer Repair Shop < 2.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-01-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"03b1376e-8ef3-4bd2-904b-6819aa21d144"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/03b1376e-8ef3-4bd2-904b-6819aa21d144?source=api-prod","affectedVersions":"<2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/1b2ad299-03b1-4b9e-a241-d2ad2d85c3ac/computer-repair-shop","title":"RepairBuddy <= 4.1116 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Signature Upload to Orders\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-16 14:36:16","sources":[{"name":"Wordfence","remoteId":"1b2ad299-03b1-4b9e-a241-d2ad2d85c3ac"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b2ad299-03b1-4b9e-a241-d2ad2d85c3ac?source=api-prod","cve":"CVE-2026-0820","affectedVersions":"<=4.1116","severity":"medium"},{"advisoryId":"WPSECADV/WF/52cdd3fe-9b53-4c7c-9538-e0c475d06ed3/computer-repair-shop","title":"CRM WordPress Plugin – RepairBuddy <= 3.8213 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"52cdd3fe-9b53-4c7c-9538-e0c475d06ed3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/52cdd3fe-9b53-4c7c-9538-e0c475d06ed3?source=api-prod","cve":"CVE-2025-32277","affectedVersions":"<=3.8213","severity":"medium"},{"advisoryId":"WPSECADV/WF/642a6d42-100f-4461-b568-35e089287902/computer-repair-shop","title":"CRM WordPress Plugin – RepairBuddy <= 3.72 - SQL Injection\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-05-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"642a6d42-100f-4461-b568-35e089287902"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/642a6d42-100f-4461-b568-35e089287902?source=api-prod","affectedVersions":"<=3.72","severity":"high"},{"advisoryId":"WPSECADV/WF/740ed055-8548-42fd-81e1-9f63dda85374/computer-repair-shop","title":"Computer Repair Shop <= 3.8119 - Authenticated (Customer+) Privilege Esclation via Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"740ed055-8548-42fd-81e1-9f63dda85374"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/740ed055-8548-42fd-81e1-9f63dda85374?source=api-prod","cve":"CVE-2024-56061","affectedVersions":"<=3.8119","severity":"critical"},{"advisoryId":"WPSECADV/WF/789670b1-8cc3-4b66-87e3-a0da6fbd2706/computer-repair-shop","title":"Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"789670b1-8cc3-4b66-87e3-a0da6fbd2706"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/789670b1-8cc3-4b66-87e3-a0da6fbd2706?source=api-prod","cve":"CVE-2024-51793","affectedVersions":"<=3.8115","severity":"critical"},{"advisoryId":"WPSECADV/WF/7d2bfbce-8e50-415c-997e-881b240c5807/computer-repair-shop","title":"RepairBuddy <= 4.1132 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"7d2bfbce-8e50-415c-997e-881b240c5807"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7d2bfbce-8e50-415c-997e-881b240c5807?source=api-prod","cve":"CVE-2026-39586","affectedVersions":"<=4.1132","severity":"medium"},{"advisoryId":"WPSECADV/WF/80997d2f-3e16-48f6-969b-58844cb83d53/computer-repair-shop","title":"CRM WordPress Plugin – RepairBuddy <= 3.8120 - Missing Authorization to Account Takeover/Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"80997d2f-3e16-48f6-969b-58844cb83d53"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/80997d2f-3e16-48f6-969b-58844cb83d53?source=api-prod","cve":"CVE-2024-12259","affectedVersions":"<=3.8120","severity":"high"},{"advisoryId":"WPSECADV/WF/bb4b3778-7211-4a56-a2e5-1f455f356dd5/computer-repair-shop","title":"RepairBuddy <= 4.1132 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification via wc_rep_shop_settings_submission AJAX Action\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"bb4b3778-7211-4a56-a2e5-1f455f356dd5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bb4b3778-7211-4a56-a2e5-1f455f356dd5?source=api-prod","cve":"CVE-2026-3567","affectedVersions":"<=4.1132","severity":"medium"},{"advisoryId":"WPSECADV/WF/f570a9d2-41d7-42f2-9f13-4cda97ea2219/computer-repair-shop","title":"RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1132 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"f570a9d2-41d7-42f2-9f13-4cda97ea2219"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f570a9d2-41d7-42f2-9f13-4cda97ea2219?source=api-prod","cve":"CVE-2026-39584","affectedVersions":"<=4.1132","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_636f6e746163742d666f726d2d746f2d656d61696c811c9dc5_gen.json b/internal/data/assets/plugin_636f6e746163742d666f726d2d746f2d656d61696c811c9dc5_gen.json index 5ed76630..4aeae19c 100644 --- a/internal/data/assets/plugin_636f6e746163742d666f726d2d746f2d656d61696c811c9dc5_gen.json +++ b/internal/data/assets/plugin_636f6e746163742d666f726d2d746f2d656d61696c811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/071cbf50-3af4-4d61-8f49-e967e30294be/contact-form-to-email","title":"Contact Form Email <= 1.3.58 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"071cbf50-3af4-4d61-8f49-e967e30294be"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/071cbf50-3af4-4d61-8f49-e967e30294be?source=api-prod","cve":"CVE-2025-64369","affectedVersions":"<=1.3.58","severity":"medium"},{"advisoryId":"WPSECADV/WF/1a331934-3bf2-4406-bc45-a897a3da5d90/contact-form-to-email","title":"Contact Form Email <= 1.3.52 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1a331934-3bf2-4406-bc45-a897a3da5d90"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1a331934-3bf2-4406-bc45-a897a3da5d90?source=api-prod","cve":"CVE-2025-24727","affectedVersions":"<=1.3.52","severity":"medium"},{"advisoryId":"WPSECADV/WF/1daaab1a-ce0e-461d-940e-27b5b3f60e32/contact-form-to-email","title":"Contact Form Email <= 1.3.44 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"1daaab1a-ce0e-461d-940e-27b5b3f60e32"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1daaab1a-ce0e-461d-940e-27b5b3f60e32?source=api-prod","cve":"CVE-2024-31302","affectedVersions":"<=1.3.44","severity":"medium"},{"advisoryId":"WPSECADV/WF/2d5c6566-a890-4b95-b349-3874eb57b45a/contact-form-to-email","title":"Contact Form Email <= 1.3.37 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"2d5c6566-a890-4b95-b349-3874eb57b45a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2d5c6566-a890-4b95-b349-3874eb57b45a?source=api-prod","cve":"CVE-2023-2718","affectedVersions":"<=1.3.37","severity":"high"},{"advisoryId":"WPSECADV/WF/4515507c-a0a4-4e45-8112-fedd117e425f/contact-form-to-email","title":"Contact Form Email <= 1.2.65 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-02-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"4515507c-a0a4-4e45-8112-fedd117e425f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4515507c-a0a4-4e45-8112-fedd117e425f?source=api-prod","cve":"CVE-2019-9646","affectedVersions":"<1.2.66","severity":"medium"},{"advisoryId":"WPSECADV/WF/52ac7ccf-89fd-47d3-ba61-7bcf84908a57/contact-form-to-email","title":"Contact Form Email <= 1.2.65 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-08-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"52ac7ccf-89fd-47d3-ba61-7bcf84908a57"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/52ac7ccf-89fd-47d3-ba61-7bcf84908a57?source=api-prod","cve":"CVE-2018-20963","affectedVersions":"<=1.2.65","severity":"medium"},{"advisoryId":"WPSECADV/WF/7399f8f3-70ee-44ed-b8c8-211ae22aa86b/contact-form-to-email","title":"Contact Form Email <= 1.3.60 - Unauthenticated Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"7399f8f3-70ee-44ed-b8c8-211ae22aa86b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7399f8f3-70ee-44ed-b8c8-211ae22aa86b?source=api-prod","cve":"CVE-2025-10019","affectedVersions":"<=1.3.60","severity":"medium"},{"advisoryId":"WPSECADV/WF/86f67129-2042-4dff-85de-e189e9f6b53d/contact-form-to-email","title":"Contact Form Email <= 1.3.43 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"86f67129-2042-4dff-85de-e189e9f6b53d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/86f67129-2042-4dff-85de-e189e9f6b53d?source=api-prod","cve":"CVE-2023-5955","affectedVersions":"<=1.3.43","severity":"medium"},{"advisoryId":"WPSECADV/WF/9596c243-4099-420a-aa2a-381b6299f927/contact-form-to-email","title":"Contact Form Email <= 1.3.31 - Missing Authorization to Feedback Submission\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"9596c243-4099-420a-aa2a-381b6299f927"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9596c243-4099-420a-aa2a-381b6299f927?source=api-prod","cve":"CVE-2023-28494","affectedVersions":"<=1.3.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/96b58c2c-f292-4a48-bd1e-c33cf464c1ce/contact-form-to-email","title":"Contact Form Email <= 1.3.24 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-11 14:20:00","sources":[{"name":"Wordfence","remoteId":"96b58c2c-f292-4a48-bd1e-c33cf464c1ce"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/96b58c2c-f292-4a48-bd1e-c33cf464c1ce?source=api-prod","cve":"CVE-2021-42361","affectedVersions":"<=1.3.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/a0850b88-09f0-4da8-a9be-1b4aacf610e0/contact-form-to-email","title":"Contact Form Email < 1.0.1 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-11-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"a0850b88-09f0-4da8-a9be-1b4aacf610e0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a0850b88-09f0-4da8-a9be-1b4aacf610e0?source=api-prod","affectedVersions":"<1.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/b637ebfd-c273-428b-985c-6f5b6a03f263/contact-form-to-email","title":"Contact Form Email <= 1.3.41 - Captcha Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"b637ebfd-c273-428b-985c-6f5b6a03f263"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b637ebfd-c273-428b-985c-6f5b6a03f263?source=api-prod","cve":"CVE-2023-48318","affectedVersions":"<=1.3.41","severity":"medium"},{"advisoryId":"WPSECADV/WF/c77295f3-0a37-4fa8-a375-b4bd3dc55945/contact-form-to-email","title":"Contact Form Email < 1.1.48 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"c77295f3-0a37-4fa8-a375-b4bd3dc55945"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c77295f3-0a37-4fa8-a375-b4bd3dc55945?source=api-prod","affectedVersions":"<1.1.48","severity":"high"},{"advisoryId":"WPSECADV/WF/cab2f0d7-f288-4462-b2a7-7a999cd47466/contact-form-to-email","title":"Contact Form Email <= 1.2.65 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-08-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"cab2f0d7-f288-4462-b2a7-7a999cd47466"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cab2f0d7-f288-4462-b2a7-7a999cd47466?source=api-prod","cve":"CVE-2018-20964","affectedVersions":"<=1.2.65","severity":"high"},{"advisoryId":"WPSECADV/WF/ce6ea115-941e-482f-a2a4-95293ff10a69/contact-form-to-email","title":"Contact Form Email <= 1.3.31 - Cross-Site Request Forgery to Feedback Submission\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"ce6ea115-941e-482f-a2a4-95293ff10a69"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ce6ea115-941e-482f-a2a4-95293ff10a69?source=api-prod","affectedVersions":"<=1.3.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/fa9450a4-2b96-45e4-b2dc-9a4b26449d19/contact-form-to-email","title":"Contact Form Email <= 1.3.11 - Cross-Site Request Forgery to Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-05-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"fa9450a4-2b96-45e4-b2dc-9a4b26449d19"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fa9450a4-2b96-45e4-b2dc-9a4b26449d19?source=api-prod","affectedVersions":"<1.3.12","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/071cbf50-3af4-4d61-8f49-e967e30294be/contact-form-to-email","title":"Contact Form Email <= 1.3.58 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"071cbf50-3af4-4d61-8f49-e967e30294be"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/071cbf50-3af4-4d61-8f49-e967e30294be?source=api-prod","cve":"CVE-2025-64369","affectedVersions":"<=1.3.58","severity":"medium"},{"advisoryId":"WPSECADV/WF/1a331934-3bf2-4406-bc45-a897a3da5d90/contact-form-to-email","title":"Contact Form Email <= 1.3.52 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1a331934-3bf2-4406-bc45-a897a3da5d90"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1a331934-3bf2-4406-bc45-a897a3da5d90?source=api-prod","cve":"CVE-2025-24727","affectedVersions":"<=1.3.52","severity":"medium"},{"advisoryId":"WPSECADV/WF/1daaab1a-ce0e-461d-940e-27b5b3f60e32/contact-form-to-email","title":"Contact Form Email <= 1.3.44 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"1daaab1a-ce0e-461d-940e-27b5b3f60e32"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1daaab1a-ce0e-461d-940e-27b5b3f60e32?source=api-prod","cve":"CVE-2024-31302","affectedVersions":"<=1.3.44","severity":"medium"},{"advisoryId":"WPSECADV/WF/2d5c6566-a890-4b95-b349-3874eb57b45a/contact-form-to-email","title":"Contact Form Email <= 1.3.37 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"2d5c6566-a890-4b95-b349-3874eb57b45a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2d5c6566-a890-4b95-b349-3874eb57b45a?source=api-prod","cve":"CVE-2023-2718","affectedVersions":"<=1.3.37","severity":"high"},{"advisoryId":"WPSECADV/WF/4515507c-a0a4-4e45-8112-fedd117e425f/contact-form-to-email","title":"Contact Form Email <= 1.2.65 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-02-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"4515507c-a0a4-4e45-8112-fedd117e425f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4515507c-a0a4-4e45-8112-fedd117e425f?source=api-prod","cve":"CVE-2019-9646","affectedVersions":"<1.2.66","severity":"medium"},{"advisoryId":"WPSECADV/WF/4c44e858-7028-495e-b6c7-8b7712e00eaf/contact-form-to-email","title":"Contact Form Email <= 1.3.63 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"4c44e858-7028-495e-b6c7-8b7712e00eaf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4c44e858-7028-495e-b6c7-8b7712e00eaf?source=api-prod","cve":"CVE-2026-32483","affectedVersions":"<=1.3.63","severity":"medium"},{"advisoryId":"WPSECADV/WF/52ac7ccf-89fd-47d3-ba61-7bcf84908a57/contact-form-to-email","title":"Contact Form Email <= 1.2.65 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-08-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"52ac7ccf-89fd-47d3-ba61-7bcf84908a57"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/52ac7ccf-89fd-47d3-ba61-7bcf84908a57?source=api-prod","cve":"CVE-2018-20963","affectedVersions":"<=1.2.65","severity":"medium"},{"advisoryId":"WPSECADV/WF/7399f8f3-70ee-44ed-b8c8-211ae22aa86b/contact-form-to-email","title":"Contact Form Email <= 1.3.60 - Unauthenticated Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"7399f8f3-70ee-44ed-b8c8-211ae22aa86b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7399f8f3-70ee-44ed-b8c8-211ae22aa86b?source=api-prod","cve":"CVE-2025-10019","affectedVersions":"<=1.3.60","severity":"medium"},{"advisoryId":"WPSECADV/WF/86f67129-2042-4dff-85de-e189e9f6b53d/contact-form-to-email","title":"Contact Form Email <= 1.3.43 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"86f67129-2042-4dff-85de-e189e9f6b53d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/86f67129-2042-4dff-85de-e189e9f6b53d?source=api-prod","cve":"CVE-2023-5955","affectedVersions":"<=1.3.43","severity":"medium"},{"advisoryId":"WPSECADV/WF/9596c243-4099-420a-aa2a-381b6299f927/contact-form-to-email","title":"Contact Form Email <= 1.3.31 - Missing Authorization to Feedback Submission\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"9596c243-4099-420a-aa2a-381b6299f927"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9596c243-4099-420a-aa2a-381b6299f927?source=api-prod","cve":"CVE-2023-28494","affectedVersions":"<=1.3.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/96b58c2c-f292-4a48-bd1e-c33cf464c1ce/contact-form-to-email","title":"Contact Form Email <= 1.3.24 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-11 14:20:00","sources":[{"name":"Wordfence","remoteId":"96b58c2c-f292-4a48-bd1e-c33cf464c1ce"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/96b58c2c-f292-4a48-bd1e-c33cf464c1ce?source=api-prod","cve":"CVE-2021-42361","affectedVersions":"<=1.3.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/a0850b88-09f0-4da8-a9be-1b4aacf610e0/contact-form-to-email","title":"Contact Form Email < 1.0.1 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-11-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"a0850b88-09f0-4da8-a9be-1b4aacf610e0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a0850b88-09f0-4da8-a9be-1b4aacf610e0?source=api-prod","affectedVersions":"<1.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/b637ebfd-c273-428b-985c-6f5b6a03f263/contact-form-to-email","title":"Contact Form Email <= 1.3.41 - Captcha Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"b637ebfd-c273-428b-985c-6f5b6a03f263"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b637ebfd-c273-428b-985c-6f5b6a03f263?source=api-prod","cve":"CVE-2023-48318","affectedVersions":"<=1.3.41","severity":"medium"},{"advisoryId":"WPSECADV/WF/c77295f3-0a37-4fa8-a375-b4bd3dc55945/contact-form-to-email","title":"Contact Form Email < 1.1.48 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"c77295f3-0a37-4fa8-a375-b4bd3dc55945"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c77295f3-0a37-4fa8-a375-b4bd3dc55945?source=api-prod","affectedVersions":"<1.1.48","severity":"high"},{"advisoryId":"WPSECADV/WF/cab2f0d7-f288-4462-b2a7-7a999cd47466/contact-form-to-email","title":"Contact Form Email <= 1.2.65 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-08-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"cab2f0d7-f288-4462-b2a7-7a999cd47466"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cab2f0d7-f288-4462-b2a7-7a999cd47466?source=api-prod","cve":"CVE-2018-20964","affectedVersions":"<=1.2.65","severity":"high"},{"advisoryId":"WPSECADV/WF/ce6ea115-941e-482f-a2a4-95293ff10a69/contact-form-to-email","title":"Contact Form Email <= 1.3.31 - Cross-Site Request Forgery to Feedback Submission\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"ce6ea115-941e-482f-a2a4-95293ff10a69"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ce6ea115-941e-482f-a2a4-95293ff10a69?source=api-prod","affectedVersions":"<=1.3.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/fa9450a4-2b96-45e4-b2dc-9a4b26449d19/contact-form-to-email","title":"Contact Form Email <= 1.3.11 - Cross-Site Request Forgery to Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2015-05-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"fa9450a4-2b96-45e4-b2dc-9a4b26449d19"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fa9450a4-2b96-45e4-b2dc-9a4b26449d19?source=api-prod","affectedVersions":"<1.3.12","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6469726563746f72797072657373811c9dc5_gen.json b/internal/data/assets/plugin_6469726563746f72797072657373811c9dc5_gen.json index 23f6b4d3..9ea6eda3 100644 --- a/internal/data/assets/plugin_6469726563746f72797072657373811c9dc5_gen.json +++ b/internal/data/assets/plugin_6469726563746f72797072657373811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/14acb770-9a32-4308-993d-a3d3dec91f78/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.7 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"14acb770-9a32-4308-993d-a3d3dec91f78"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/14acb770-9a32-4308-993d-a3d3dec91f78?source=api-prod","cve":"CVE-2024-32567","affectedVersions":"<=3.6.7","severity":"high"},{"advisoryId":"WPSECADV/WF/2e602223-8571-42e1-9b3f-e7cc51f8fa58/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.26 - Unauthenticated SQL Injection via 'packages'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-15 21:35:44","sources":[{"name":"Wordfence","remoteId":"2e602223-8571-42e1-9b3f-e7cc51f8fa58"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2e602223-8571-42e1-9b3f-e7cc51f8fa58?source=api-prod","cve":"CVE-2026-3489","affectedVersions":"<=3.6.26","severity":"high"},{"advisoryId":"WPSECADV/WF/4625072b-815d-41d2-bf8f-ac290efde369/directorypress","title":"DirectoryPress <= 3.6.16 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"4625072b-815d-41d2-bf8f-ac290efde369"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4625072b-815d-41d2-bf8f-ac290efde369?source=api-prod","cve":"CVE-2024-10584","affectedVersions":"<=3.6.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd/directorypress","title":"DirectoryPress <= 3.6.10 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd?source=api-prod","cve":"CVE-2024-38755","affectedVersions":"<=3.6.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/86b0558b-74ed-4ddd-9b18-e7795cefc00e/directorypress","title":"DirectoryPress <= 3.6.19 - Cross-Site Request Forgery to Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"86b0558b-74ed-4ddd-9b18-e7795cefc00e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/86b0558b-74ed-4ddd-9b18-e7795cefc00e?source=api-prod","cve":"CVE-2024-49633","affectedVersions":"<=3.6.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/8875d2d5-1de0-4a8c-8acb-69c8095effe5/directorypress","title":"DirectoryPress <= 3.6.25 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"8875d2d5-1de0-4a8c-8acb-69c8095effe5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8875d2d5-1de0-4a8c-8acb-69c8095effe5?source=api-prod","cve":"CVE-2025-62967","affectedVersions":"<=3.6.25","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6bd6979-858a-446b-a8d9-d30869e73ed5/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.26 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"b6bd6979-858a-446b-a8d9-d30869e73ed5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6bd6979-858a-446b-a8d9-d30869e73ed5?source=api-prod","cve":"CVE-2026-27387","affectedVersions":"<=3.6.26","severity":"medium"},{"advisoryId":"WPSECADV/WF/dc9602fb-59d0-43bb-aa13-adfc2319db8e/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.25 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"dc9602fb-59d0-43bb-aa13-adfc2319db8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dc9602fb-59d0-43bb-aa13-adfc2319db8e?source=api-prod","cve":"CVE-2026-23548","affectedVersions":"<=3.6.25","severity":"medium"},{"advisoryId":"WPSECADV/WF/f75f83bf-3c86-44e9-b535-cd721061ee93/directorypress","title":"DirectoryPress <= 3.6.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"f75f83bf-3c86-44e9-b535-cd721061ee93"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f75f83bf-3c86-44e9-b535-cd721061ee93?source=api-prod","cve":"CVE-2023-37967","affectedVersions":"<=3.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/fa32f55a-f9e4-4129-add0-39d9e4eb1bee/directorypress","title":"DirectoryPress <= 3.6.22 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"fa32f55a-f9e4-4129-add0-39d9e4eb1bee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fa32f55a-f9e4-4129-add0-39d9e4eb1bee?source=api-prod","cve":"CVE-2025-32249","affectedVersions":"<=3.6.22","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/14acb770-9a32-4308-993d-a3d3dec91f78/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.7 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"14acb770-9a32-4308-993d-a3d3dec91f78"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/14acb770-9a32-4308-993d-a3d3dec91f78?source=api-prod","cve":"CVE-2024-32567","affectedVersions":"<=3.6.7","severity":"high"},{"advisoryId":"WPSECADV/WF/2e602223-8571-42e1-9b3f-e7cc51f8fa58/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.26 - Unauthenticated SQL Injection via 'packages'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-15 21:35:44","sources":[{"name":"Wordfence","remoteId":"2e602223-8571-42e1-9b3f-e7cc51f8fa58"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2e602223-8571-42e1-9b3f-e7cc51f8fa58?source=api-prod","cve":"CVE-2026-3489","affectedVersions":"<=3.6.26","severity":"high"},{"advisoryId":"WPSECADV/WF/4625072b-815d-41d2-bf8f-ac290efde369/directorypress","title":"DirectoryPress <= 3.6.16 - Authenticated (Author+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"4625072b-815d-41d2-bf8f-ac290efde369"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4625072b-815d-41d2-bf8f-ac290efde369?source=api-prod","cve":"CVE-2024-10584","affectedVersions":"<=3.6.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd/directorypress","title":"DirectoryPress <= 3.6.10 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63d0cb9b-e6ac-474e-ac6b-c0cbd14a19bd?source=api-prod","cve":"CVE-2024-38755","affectedVersions":"<=3.6.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/86b0558b-74ed-4ddd-9b18-e7795cefc00e/directorypress","title":"DirectoryPress <= 3.6.19 - Cross-Site Request Forgery to Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"86b0558b-74ed-4ddd-9b18-e7795cefc00e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/86b0558b-74ed-4ddd-9b18-e7795cefc00e?source=api-prod","cve":"CVE-2024-49633","affectedVersions":"<=3.6.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/8765b075-a2db-4423-a449-d7aa0c15db74/directorypress","title":"DirectoryPress <= 3.6.26 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"8765b075-a2db-4423-a449-d7aa0c15db74"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8765b075-a2db-4423-a449-d7aa0c15db74?source=api-prod","cve":"CVE-2026-39566","affectedVersions":"<=3.6.26","severity":"medium"},{"advisoryId":"WPSECADV/WF/8875d2d5-1de0-4a8c-8acb-69c8095effe5/directorypress","title":"DirectoryPress <= 3.6.25 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"8875d2d5-1de0-4a8c-8acb-69c8095effe5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8875d2d5-1de0-4a8c-8acb-69c8095effe5?source=api-prod","cve":"CVE-2025-62967","affectedVersions":"<=3.6.25","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6bd6979-858a-446b-a8d9-d30869e73ed5/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.26 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"b6bd6979-858a-446b-a8d9-d30869e73ed5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6bd6979-858a-446b-a8d9-d30869e73ed5?source=api-prod","cve":"CVE-2026-27387","affectedVersions":"<=3.6.26","severity":"medium"},{"advisoryId":"WPSECADV/WF/dc9602fb-59d0-43bb-aa13-adfc2319db8e/directorypress","title":"DirectoryPress – Business Directory And Classified Ad Listing <= 3.6.25 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"dc9602fb-59d0-43bb-aa13-adfc2319db8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dc9602fb-59d0-43bb-aa13-adfc2319db8e?source=api-prod","cve":"CVE-2026-23548","affectedVersions":"<=3.6.25","severity":"medium"},{"advisoryId":"WPSECADV/WF/f75f83bf-3c86-44e9-b535-cd721061ee93/directorypress","title":"DirectoryPress <= 3.6.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"f75f83bf-3c86-44e9-b535-cd721061ee93"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f75f83bf-3c86-44e9-b535-cd721061ee93?source=api-prod","cve":"CVE-2023-37967","affectedVersions":"<=3.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/fa32f55a-f9e4-4129-add0-39d9e4eb1bee/directorypress","title":"DirectoryPress <= 3.6.22 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"fa32f55a-f9e4-4129-add0-39d9e4eb1bee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fa32f55a-f9e4-4129-add0-39d9e4eb1bee?source=api-prod","cve":"CVE-2025-32249","affectedVersions":"<=3.6.22","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_646f6f66696e6465722d666f722d776f6f636f6d6d65726365811c9dc5_gen.json b/internal/data/assets/plugin_646f6f66696e6465722d666f722d776f6f636f6d6d65726365811c9dc5_gen.json index bf2f87c7..38d93527 100644 --- a/internal/data/assets/plugin_646f6f66696e6465722d666f722d776f6f636f6d6d65726365811c9dc5_gen.json +++ b/internal/data/assets/plugin_646f6f66696e6465722d666f722d776f6f636f6d6d65726365811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/13159a71-c183-4fc2-98af-8b9e60508a1c/doofinder-for-woocommerce","title":"Doofinder for WooCommerce <= 2.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"13159a71-c183-4fc2-98af-8b9e60508a1c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/13159a71-c183-4fc2-98af-8b9e60508a1c?source=api-prod","cve":"CVE-2024-25596","affectedVersions":"<=2.1.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/7414779e-7241-4ab2-9b1f-34c3e1acc66b/doofinder-for-woocommerce","title":"Doofinder for WooCommerce <= 1.5.49 - Unauthenticated Open Redirect\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"7414779e-7241-4ab2-9b1f-34c3e1acc66b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7414779e-7241-4ab2-9b1f-34c3e1acc66b?source=api-prod","cve":"CVE-2023-40602","affectedVersions":"<=1.5.49","severity":"medium"},{"advisoryId":"WPSECADV/WF/ad50e216-f522-4294-a4dc-7f3bd52820b3/doofinder-for-woocommerce","title":"Doofinder for WooCommerce <= 2.0.33 - Missing Authorization via multiple AJAX actions\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad50e216-f522-4294-a4dc-7f3bd52820b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad50e216-f522-4294-a4dc-7f3bd52820b3?source=api-prod","cve":"CVE-2023-51678","affectedVersions":"<=2.0.33","severity":"medium"},{"advisoryId":"WPSECADV/WF/e46a2031-e304-43fb-85bf-ec9abf0b2f90/doofinder-for-woocommerce","title":"Doofinder for WooCommerce <= 2.1.7 - Reflected Cross-Site Scripting via tab\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"e46a2031-e304-43fb-85bf-ec9abf0b2f90"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e46a2031-e304-43fb-85bf-ec9abf0b2f90?source=api-prod","cve":"CVE-2023-49185","affectedVersions":"<=2.1.7","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/13159a71-c183-4fc2-98af-8b9e60508a1c/doofinder-for-woocommerce","title":"Doofinder for WooCommerce <= 2.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"13159a71-c183-4fc2-98af-8b9e60508a1c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/13159a71-c183-4fc2-98af-8b9e60508a1c?source=api-prod","cve":"CVE-2024-25596","affectedVersions":"<=2.1.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/438e36ba-fd0e-4c98-814b-95f3d5f60d2f/doofinder-for-woocommerce","title":"Doofinder for WooCommerce <= 2.10.13 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"438e36ba-fd0e-4c98-814b-95f3d5f60d2f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/438e36ba-fd0e-4c98-814b-95f3d5f60d2f?source=api-prod","cve":"CVE-2026-39542","affectedVersions":"<=2.10.13","severity":"low"},{"advisoryId":"WPSECADV/WF/7414779e-7241-4ab2-9b1f-34c3e1acc66b/doofinder-for-woocommerce","title":"Doofinder for WooCommerce <= 1.5.49 - Unauthenticated Open Redirect\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"7414779e-7241-4ab2-9b1f-34c3e1acc66b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7414779e-7241-4ab2-9b1f-34c3e1acc66b?source=api-prod","cve":"CVE-2023-40602","affectedVersions":"<=1.5.49","severity":"medium"},{"advisoryId":"WPSECADV/WF/ad50e216-f522-4294-a4dc-7f3bd52820b3/doofinder-for-woocommerce","title":"Doofinder for WooCommerce <= 2.0.33 - Missing Authorization via multiple AJAX actions\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad50e216-f522-4294-a4dc-7f3bd52820b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad50e216-f522-4294-a4dc-7f3bd52820b3?source=api-prod","cve":"CVE-2023-51678","affectedVersions":"<=2.0.33","severity":"medium"},{"advisoryId":"WPSECADV/WF/e46a2031-e304-43fb-85bf-ec9abf0b2f90/doofinder-for-woocommerce","title":"Doofinder for WooCommerce <= 2.1.7 - Reflected Cross-Site Scripting via tab\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"e46a2031-e304-43fb-85bf-ec9abf0b2f90"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e46a2031-e304-43fb-85bf-ec9abf0b2f90?source=api-prod","cve":"CVE-2023-49185","affectedVersions":"<=2.1.7","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_646f776e6c6f61642d6174746163686d656e7473811c9dc5_gen.json b/internal/data/assets/plugin_646f776e6c6f61642d6174746163686d656e7473811c9dc5_gen.json index a6a47288..5158f44f 100644 --- a/internal/data/assets/plugin_646f776e6c6f61642d6174746163686d656e7473811c9dc5_gen.json +++ b/internal/data/assets/plugin_646f776e6c6f61642d6174746163686d656e7473811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/62475d8f-a0f6-45ab-abd0-ad24e1887c91/download-attachments","title":"Download Attachments <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-03 16:38:52","sources":[{"name":"Wordfence","remoteId":"62475d8f-a0f6-45ab-abd0-ad24e1887c91"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62475d8f-a0f6-45ab-abd0-ad24e1887c91?source=api-prod","cve":"CVE-2024-3230","affectedVersions":"<=1.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/7e977be1-d346-4fcc-89a5-332cbd010d18/download-attachments","title":"Download Attachments <= 1.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"7e977be1-d346-4fcc-89a5-332cbd010d18"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7e977be1-d346-4fcc-89a5-332cbd010d18?source=api-prod","cve":"CVE-2023-0076","affectedVersions":"<=1.2.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/dc18a5c4-6e63-4ad1-a90e-8337b5a86c48/download-attachments","title":"Download Attachments <= 1.3.1 - Unauthenticated Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"dc18a5c4-6e63-4ad1-a90e-8337b5a86c48"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dc18a5c4-6e63-4ad1-a90e-8337b5a86c48?source=api-prod","cve":"CVE-2025-49995","affectedVersions":"<=1.3.1","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/3d492fcd-5138-44e8-816b-295ec219fd0d/download-attachments","title":"Download Attachments <= 1.4.0 - Unauthenticated Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"3d492fcd-5138-44e8-816b-295ec219fd0d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3d492fcd-5138-44e8-816b-295ec219fd0d?source=api-prod","cve":"CVE-2026-39616","affectedVersions":"<=1.4.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/62475d8f-a0f6-45ab-abd0-ad24e1887c91/download-attachments","title":"Download Attachments <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-03 16:38:52","sources":[{"name":"Wordfence","remoteId":"62475d8f-a0f6-45ab-abd0-ad24e1887c91"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62475d8f-a0f6-45ab-abd0-ad24e1887c91?source=api-prod","cve":"CVE-2024-3230","affectedVersions":"<=1.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/7e977be1-d346-4fcc-89a5-332cbd010d18/download-attachments","title":"Download Attachments <= 1.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"7e977be1-d346-4fcc-89a5-332cbd010d18"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7e977be1-d346-4fcc-89a5-332cbd010d18?source=api-prod","cve":"CVE-2023-0076","affectedVersions":"<=1.2.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/dc18a5c4-6e63-4ad1-a90e-8337b5a86c48/download-attachments","title":"Download Attachments <= 1.3.1 - Unauthenticated Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"dc18a5c4-6e63-4ad1-a90e-8337b5a86c48"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dc18a5c4-6e63-4ad1-a90e-8337b5a86c48?source=api-prod","cve":"CVE-2025-49995","affectedVersions":"<=1.3.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_656361622d746178692d626f6f6b696e672d6d616e61676572811c9dc5_gen.json b/internal/data/assets/plugin_656361622d746178692d626f6f6b696e672d6d616e61676572811c9dc5_gen.json index 9829e6a2..ea205f8d 100644 --- a/internal/data/assets/plugin_656361622d746178692d626f6f6b696e672d6d616e61676572811c9dc5_gen.json +++ b/internal/data/assets/plugin_656361622d746178692d626f6f6b696e672d6d616e61676572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0e8f2dba-9108-4531-8428-e66b406349b6/ecab-taxi-booking-manager","title":"Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab <= 1.1.8 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"0e8f2dba-9108-4531-8428-e66b406349b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e8f2dba-9108-4531-8428-e66b406349b6?source=api-prod","cve":"CVE-2025-24661","affectedVersions":"<=1.1.8","severity":"high"},{"advisoryId":"WPSECADV/WF/9ca2c966-cea4-426b-9c70-5cb98fc1d125/ecab-taxi-booking-manager","title":"E-cab Taxi Booking Manager for Woocommerce <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"9ca2c966-cea4-426b-9c70-5cb98fc1d125"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9ca2c966-cea4-426b-9c70-5cb98fc1d125?source=api-prod","cve":"CVE-2026-28040","affectedVersions":"<=2.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/cc8147ae-fb6c-444c-9113-98bdeff3a4dd/ecab-taxi-booking-manager","title":"Taxi Booking Manager for WooCommerce <= 1.2.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"cc8147ae-fb6c-444c-9113-98bdeff3a4dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc8147ae-fb6c-444c-9113-98bdeff3a4dd?source=api-prod","cve":"CVE-2025-30839","affectedVersions":"<=1.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f24b3afe-5de3-464c-92af-a654e97f0945/ecab-taxi-booking-manager","title":"Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab <= 1.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"f24b3afe-5de3-464c-92af-a654e97f0945"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f24b3afe-5de3-464c-92af-a654e97f0945?source=api-prod","cve":"CVE-2024-43986","affectedVersions":"<=1.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/fd50ac2c-3049-4a44-b7f8-a5f87c42555c/ecab-taxi-booking-manager","title":"Taxi Booking Manager for Woocommerce | E-cab <= 1.3.0 - Missing Authorization to Unauthenticated Privilege Escalation via Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd50ac2c-3049-4a44-b7f8-a5f87c42555c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd50ac2c-3049-4a44-b7f8-a5f87c42555c?source=api-prod","cve":"CVE-2025-8898","affectedVersions":"<=1.3.0","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0e8f2dba-9108-4531-8428-e66b406349b6/ecab-taxi-booking-manager","title":"Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab <= 1.1.8 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"0e8f2dba-9108-4531-8428-e66b406349b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e8f2dba-9108-4531-8428-e66b406349b6?source=api-prod","cve":"CVE-2025-24661","affectedVersions":"<=1.1.8","severity":"high"},{"advisoryId":"WPSECADV/WF/9ca2c966-cea4-426b-9c70-5cb98fc1d125/ecab-taxi-booking-manager","title":"E-cab Taxi Booking Manager for Woocommerce <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"9ca2c966-cea4-426b-9c70-5cb98fc1d125"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9ca2c966-cea4-426b-9c70-5cb98fc1d125?source=api-prod","cve":"CVE-2026-28040","affectedVersions":"<=2.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/cc8147ae-fb6c-444c-9113-98bdeff3a4dd/ecab-taxi-booking-manager","title":"Taxi Booking Manager for WooCommerce <= 1.2.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"cc8147ae-fb6c-444c-9113-98bdeff3a4dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc8147ae-fb6c-444c-9113-98bdeff3a4dd?source=api-prod","cve":"CVE-2025-30839","affectedVersions":"<=1.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/e59928f6-7527-4810-8aab-2a71d348dd9e/ecab-taxi-booking-manager","title":"Taxi Booking Manager for WooCommerce <= 1.3.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"e59928f6-7527-4810-8aab-2a71d348dd9e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e59928f6-7527-4810-8aab-2a71d348dd9e?source=api-prod","cve":"CVE-2025-54713","affectedVersions":"<=1.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/f24b3afe-5de3-464c-92af-a654e97f0945/ecab-taxi-booking-manager","title":"Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab <= 1.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"f24b3afe-5de3-464c-92af-a654e97f0945"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f24b3afe-5de3-464c-92af-a654e97f0945?source=api-prod","cve":"CVE-2024-43986","affectedVersions":"<=1.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/fd50ac2c-3049-4a44-b7f8-a5f87c42555c/ecab-taxi-booking-manager","title":"Taxi Booking Manager for Woocommerce | E-cab <= 1.3.0 - Missing Authorization to Unauthenticated Privilege Escalation via Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd50ac2c-3049-4a44-b7f8-a5f87c42555c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd50ac2c-3049-4a44-b7f8-a5f87c42555c?source=api-prod","cve":"CVE-2025-8898","affectedVersions":"<=1.3.0","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_656c6673696768742d77686174736170702d63686174811c9dc5_gen.json b/internal/data/assets/plugin_656c6673696768742d77686174736170702d63686174811c9dc5_gen.json new file mode 100644 index 00000000..ab1eee65 --- /dev/null +++ b/internal/data/assets/plugin_656c6673696768742d77686174736170702d63686174811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/09463140-2edc-4458-900b-a898d115f34d/elfsight-whatsapp-chat","title":"Elfsight WhatsApp Chat CC <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"09463140-2edc-4458-900b-a898d115f34d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/09463140-2edc-4458-900b-a898d115f34d?source=api-prod","cve":"CVE-2026-39696","affectedVersions":"<=1.2.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_656c74642d6c697374696e67811c9dc5_gen.json b/internal/data/assets/plugin_656c74642d6c697374696e67811c9dc5_gen.json new file mode 100644 index 00000000..54cde1f9 --- /dev/null +++ b/internal/data/assets/plugin_656c74642d6c697374696e67811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/51ca835f-97cd-4711-b2a5-6090bd844b10/eltd-listing","title":"Elated Listing <= 1.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"51ca835f-97cd-4711-b2a5-6090bd844b10"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/51ca835f-97cd-4711-b2a5-6090bd844b10?source=api-prod","cve":"CVE-2026-24972","affectedVersions":"<=1.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_656d6265642d7064662d766965776572811c9dc5_gen.json b/internal/data/assets/plugin_656d6265642d7064662d766965776572811c9dc5_gen.json index 08c7bef1..0285c5d3 100644 --- a/internal/data/assets/plugin_656d6265642d7064662d766965776572811c9dc5_gen.json +++ b/internal/data/assets/plugin_656d6265642d7064662d766965776572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/31064f51-3765-403d-b07d-dc2bb286b82d/embed-pdf-viewer","title":"Embed PDF Viewer <= 2.3.1 - Authenticated (Editor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"31064f51-3765-403d-b07d-dc2bb286b82d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/31064f51-3765-403d-b07d-dc2bb286b82d?source=api-prod","cve":"CVE-2024-56256","affectedVersions":"<=2.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/b616e275-855d-461e-8fcb-c96098e41dfd/embed-pdf-viewer","title":"Embed PDF Viewer <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via height and width Parameters\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-08 18:54:11","sources":[{"name":"Wordfence","remoteId":"b616e275-855d-461e-8fcb-c96098e41dfd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b616e275-855d-461e-8fcb-c96098e41dfd?source=api-prod","cve":"CVE-2024-9451","affectedVersions":"<=2.4.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/31064f51-3765-403d-b07d-dc2bb286b82d/embed-pdf-viewer","title":"Embed PDF Viewer <= 2.3.1 - Authenticated (Editor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"31064f51-3765-403d-b07d-dc2bb286b82d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/31064f51-3765-403d-b07d-dc2bb286b82d?source=api-prod","cve":"CVE-2024-56256","affectedVersions":"<=2.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/9e105e89-3884-465e-8565-2fec7cc894da/embed-pdf-viewer","title":"Embed PDF Viewer <= 2.4.7 - Authenticated (Contributor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"9e105e89-3884-465e-8565-2fec7cc894da"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9e105e89-3884-465e-8565-2fec7cc894da?source=api-prod","cve":"CVE-2026-32349","affectedVersions":"<=2.4.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/b616e275-855d-461e-8fcb-c96098e41dfd/embed-pdf-viewer","title":"Embed PDF Viewer <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via height and width Parameters\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-08 18:54:11","sources":[{"name":"Wordfence","remoteId":"b616e275-855d-461e-8fcb-c96098e41dfd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b616e275-855d-461e-8fcb-c96098e41dfd?source=api-prod","cve":"CVE-2024-9451","affectedVersions":"<=2.4.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_66696e616c2d74696c65732d677269642d67616c6c6572792d6c697465811c9dc5_gen.json b/internal/data/assets/plugin_66696e616c2d74696c65732d677269642d67616c6c6572792d6c697465811c9dc5_gen.json index ca183acd..85e26215 100644 --- a/internal/data/assets/plugin_66696e616c2d74696c65732d677269642d67616c6c6572792d6c697465811c9dc5_gen.json +++ b/internal/data/assets/plugin_66696e616c2d74696c65732d677269642d67616c6c6572792d6c697465811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0afcfe15-2d7d-4c96-a408-28f35577a927/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.6.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Gallery Management\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-19 10:31:17","sources":[{"name":"Wordfence","remoteId":"0afcfe15-2d7d-4c96-a408-28f35577a927"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0afcfe15-2d7d-4c96-a408-28f35577a927?source=api-prod","cve":"CVE-2025-15466","affectedVersions":"<=3.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42/final-tiles-grid-gallery-lite","title":"Freemius SDK <= 2.4.2 - Missing Authorization Checks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"39fb0499-9ab4-4a2f-b0db-ece86bcf4d42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=api-prod","cve":"CVE-2022-4974","affectedVersions":"<3.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/3fda31fa-efc9-44b9-99ba-9e3e23aa2ee0/final-tiles-grid-gallery-lite","title":"Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-02-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"3fda31fa-efc9-44b9-99ba-9e3e23aa2ee0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3fda31fa-efc9-44b9-99ba-9e3e23aa2ee0?source=api-prod","affectedVersions":"<3.3.57","severity":"high"},{"advisoryId":"WPSECADV/WF/625d2b09-a6b9-4c0c-8c36-3c565e688aac/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'Custom Scripts' Setting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-20 14:53:25","sources":[{"name":"Wordfence","remoteId":"625d2b09-a6b9-4c0c-8c36-3c565e688aac"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/625d2b09-a6b9-4c0c-8c36-3c565e688aac?source=api-prod","cve":"CVE-2025-13693","affectedVersions":"<=3.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/656bf2b4-1930-4e96-b92b-01593889a43f/final-tiles-grid-gallery-lite","title":"Final Tiles Gallery <= 3.4.18 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-05-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"656bf2b4-1930-4e96-b92b-01593889a43f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/656bf2b4-1930-4e96-b92b-01593889a43f?source=api-prod","cve":"CVE-2020-14962","affectedVersions":"<=3.4.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/72af8a37-f6c0-4353-ab27-1b671158ef5a/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.6.10 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"72af8a37-f6c0-4353-ab27-1b671158ef5a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/72af8a37-f6c0-4353-ab27-1b671158ef5a?source=api-prod","cve":"CVE-2026-25375","affectedVersions":"<=3.6.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/830663b6-0786-48c7-9ffd-ac3ba2bd3e0c/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.6.7 - Missing Authorization to Authenticated (Contributor+) Gallery Management\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-18 20:29:17","sources":[{"name":"Wordfence","remoteId":"830663b6-0786-48c7-9ffd-ac3ba2bd3e0c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/830663b6-0786-48c7-9ffd-ac3ba2bd3e0c?source=api-prod","cve":"CVE-2025-14455","affectedVersions":"<=3.6.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/8d945c4b-3eb1-4bab-b355-117b7fd06553/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.6.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-26 17:00:16","sources":[{"name":"Wordfence","remoteId":"8d945c4b-3eb1-4bab-b355-117b7fd06553"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8d945c4b-3eb1-4bab-b355-117b7fd06553?source=api-prod","cve":"CVE-2024-6261","affectedVersions":"<=3.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/ae920b3b-6c6f-46c5-b64f-c075a53b4c39/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 2.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"ae920b3b-6c6f-46c5-b64f-c075a53b4c39"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ae920b3b-6c6f-46c5-b64f-c075a53b4c39?source=api-prod","cve":"CVE-2024-3710","affectedVersions":"<=2.5.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/ba44ec7c-7c71-4c19-8b1e-5d78bb3a3a03/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.5.2 - Contributor+ Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"ba44ec7c-7c71-4c19-8b1e-5d78bb3a3a03"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ba44ec7c-7c71-4c19-8b1e-5d78bb3a3a03?source=api-prod","cve":"CVE-2022-0186","affectedVersions":"<=3.5.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0afcfe15-2d7d-4c96-a408-28f35577a927/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.6.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Gallery Management\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-19 10:31:17","sources":[{"name":"Wordfence","remoteId":"0afcfe15-2d7d-4c96-a408-28f35577a927"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0afcfe15-2d7d-4c96-a408-28f35577a927?source=api-prod","cve":"CVE-2025-15466","affectedVersions":"<=3.6.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42/final-tiles-grid-gallery-lite","title":"Freemius SDK <= 2.4.2 - Missing Authorization Checks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"39fb0499-9ab4-4a2f-b0db-ece86bcf4d42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=api-prod","cve":"CVE-2022-4974","affectedVersions":"<3.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/3fda31fa-efc9-44b9-99ba-9e3e23aa2ee0/final-tiles-grid-gallery-lite","title":"Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-02-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"3fda31fa-efc9-44b9-99ba-9e3e23aa2ee0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3fda31fa-efc9-44b9-99ba-9e3e23aa2ee0?source=api-prod","affectedVersions":"<3.3.57","severity":"high"},{"advisoryId":"WPSECADV/WF/625d2b09-a6b9-4c0c-8c36-3c565e688aac/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'Custom Scripts' Setting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-20 14:53:25","sources":[{"name":"Wordfence","remoteId":"625d2b09-a6b9-4c0c-8c36-3c565e688aac"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/625d2b09-a6b9-4c0c-8c36-3c565e688aac?source=api-prod","cve":"CVE-2025-13693","affectedVersions":"<=3.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/656bf2b4-1930-4e96-b92b-01593889a43f/final-tiles-grid-gallery-lite","title":"Final Tiles Gallery <= 3.4.18 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-05-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"656bf2b4-1930-4e96-b92b-01593889a43f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/656bf2b4-1930-4e96-b92b-01593889a43f?source=api-prod","cve":"CVE-2020-14962","affectedVersions":"<=3.4.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/72af8a37-f6c0-4353-ab27-1b671158ef5a/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.6.10 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"72af8a37-f6c0-4353-ab27-1b671158ef5a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/72af8a37-f6c0-4353-ab27-1b671158ef5a?source=api-prod","cve":"CVE-2026-25375","affectedVersions":"<=3.6.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/830663b6-0786-48c7-9ffd-ac3ba2bd3e0c/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.6.7 - Missing Authorization to Authenticated (Contributor+) Gallery Management\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-18 20:29:17","sources":[{"name":"Wordfence","remoteId":"830663b6-0786-48c7-9ffd-ac3ba2bd3e0c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/830663b6-0786-48c7-9ffd-ac3ba2bd3e0c?source=api-prod","cve":"CVE-2025-14455","affectedVersions":"<=3.6.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/8d945c4b-3eb1-4bab-b355-117b7fd06553/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.6.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-26 17:00:16","sources":[{"name":"Wordfence","remoteId":"8d945c4b-3eb1-4bab-b355-117b7fd06553"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8d945c4b-3eb1-4bab-b355-117b7fd06553?source=api-prod","cve":"CVE-2024-6261","affectedVersions":"<=3.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/ae920b3b-6c6f-46c5-b64f-c075a53b4c39/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 2.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"ae920b3b-6c6f-46c5-b64f-c075a53b4c39"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ae920b3b-6c6f-46c5-b64f-c075a53b4c39?source=api-prod","cve":"CVE-2024-3710","affectedVersions":"<=2.5.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/af7dc118-775f-471a-a2f9-49d6d77bd84c/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.6.11 - Authenticated (Author+) Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"af7dc118-775f-471a-a2f9-49d6d77bd84c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af7dc118-775f-471a-a2f9-49d6d77bd84c?source=api-prod","cve":"CVE-2026-39510","affectedVersions":"<=3.6.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/ba44ec7c-7c71-4c19-8b1e-5d78bb3a3a03/final-tiles-grid-gallery-lite","title":"Image Photo Gallery Final Tiles Grid <= 3.5.2 - Contributor+ Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"ba44ec7c-7c71-4c19-8b1e-5d78bb3a3a03"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ba44ec7c-7c71-4c19-8b1e-5d78bb3a3a03?source=api-prod","cve":"CVE-2022-0186","affectedVersions":"<=3.5.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_666c75656e74666f726d811c9dc5_gen.json b/internal/data/assets/plugin_666c75656e74666f726d811c9dc5_gen.json index 2a9f822a..ba0e63cc 100644 --- a/internal/data/assets/plugin_666c75656e74666f726d811c9dc5_gen.json +++ b/internal/data/assets/plugin_666c75656e74666f726d811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/00192a36-4b75-4dae-9a6e-0afb02ed5bad/fluentform","title":"Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-09 17:19:48","sources":[{"name":"Wordfence","remoteId":"00192a36-4b75-4dae-9a6e-0afb02ed5bad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00192a36-4b75-4dae-9a6e-0afb02ed5bad?source=api-prod","cve":"CVE-2026-0996","affectedVersions":"<=6.1.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/0348d465-f351-4c52-b293-8b3b058292b9/fluentform","title":"Fluent Forms <= 5.1.5 - Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"0348d465-f351-4c52-b293-8b3b058292b9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0348d465-f351-4c52-b293-8b3b058292b9?source=api-prod","cve":"CVE-2024-0618","affectedVersions":"<=5.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/071195d6-3452-4241-a8d3-92efc84e4850/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 19:02:43","sources":[{"name":"Wordfence","remoteId":"071195d6-3452-4241-a8d3-92efc84e4850"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/071195d6-3452-4241-a8d3-92efc84e4850?source=api-prod","cve":"CVE-2024-2771","affectedVersions":"<=5.1.16","severity":"critical"},{"advisoryId":"WPSECADV/WF/0814e7b3-404a-4db5-b564-46c9086ec048/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 19:02:45","sources":[{"name":"Wordfence","remoteId":"0814e7b3-404a-4db5-b564-46c9086ec048"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0814e7b3-404a-4db5-b564-46c9086ec048?source=api-prod","cve":"CVE-2024-2782","affectedVersions":"<=5.1.16","severity":"high"},{"advisoryId":"WPSECADV/WF/0a30d35c-9883-4b0f-83a2-494401c45d8e/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 23:27:30","sources":[{"name":"Wordfence","remoteId":"0a30d35c-9883-4b0f-83a2-494401c45d8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0a30d35c-9883-4b0f-83a2-494401c45d8e?source=api-prod","cve":"CVE-2024-6520","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/0b79a851-1212-4a9c-89fe-b5f2d50ec18c/fluentform","title":"FluentForms <= 4.3.24 - Authenticated(Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"0b79a851-1212-4a9c-89fe-b5f2d50ec18c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0b79a851-1212-4a9c-89fe-b5f2d50ec18c?source=api-prod","cve":"CVE-2023-0546","affectedVersions":"<=4.3.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/154fc656-3a33-4783-a941-10bb848244b3/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-16 00:53:13","sources":[{"name":"Wordfence","remoteId":"154fc656-3a33-4783-a941-10bb848244b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/154fc656-3a33-4783-a941-10bb848244b3?source=api-prod","cve":"CVE-2026-4160","affectedVersions":"=6.1.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/20f31e48-0dbb-498a-a400-681cacea7c9c/fluentform","title":"Contact Form for Plugin by Fluent Forms <= 5.0.8 - Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"20f31e48-0dbb-498a-a400-681cacea7c9c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/20f31e48-0dbb-498a-a400-681cacea7c9c?source=api-prod","cve":"CVE-2023-41952","affectedVersions":"<5.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ccba77c-fb90-4906-b0fe-77607ec5df1f/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 19:02:47","sources":[{"name":"Wordfence","remoteId":"2ccba77c-fb90-4906-b0fe-77607ec5df1f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ccba77c-fb90-4906-b0fe-77607ec5df1f?source=api-prod","cve":"CVE-2024-2772","affectedVersions":"<=5.1.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f/fluentform","title":"FluentForm <= 6.1.11 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f?source=api-prod","cve":"CVE-2025-69001","affectedVersions":"<=6.1.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/41c2ec31-360d-4145-b0b4-77d4d1d4b8a1/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-13 16:24:44","sources":[{"name":"Wordfence","remoteId":"41c2ec31-360d-4145-b0b4-77d4d1d4b8a1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/41c2ec31-360d-4145-b0b4-77d4d1d4b8a1?source=api-prod","cve":"CVE-2024-10646","affectedVersions":"<=5.2.6","severity":"high"},{"advisoryId":"WPSECADV/WF/4ed4dfee-5f14-47ce-abed-cd226c110665/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"4ed4dfee-5f14-47ce-abed-cd226c110665"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ed4dfee-5f14-47ce-abed-cd226c110665?source=api-prod","cve":"CVE-2024-9528","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/5a85c367-99f5-4a46-94bc-ed6e6626514b/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.14 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"5a85c367-99f5-4a46-94bc-ed6e6626514b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5a85c367-99f5-4a46-94bc-ed6e6626514b?source=api-prod","cve":"CVE-2026-25313","affectedVersions":"<=6.1.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/5fe317a6-a391-441a-aac8-c8fa57e73169/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"5fe317a6-a391-441a-aac8-c8fa57e73169"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5fe317a6-a391-441a-aac8-c8fa57e73169?source=api-prod","cve":"CVE-2024-4709","affectedVersions":"<=5.1.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 23:26:31","sources":[{"name":"Wordfence","remoteId":"66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9?source=api-prod","cve":"CVE-2024-6518","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/69dc9236-8079-434f-b2b5-060a0c5eba46/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"69dc9236-8079-434f-b2b5-060a0c5eba46"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/69dc9236-8079-434f-b2b5-060a0c5eba46?source=api-prod","cve":"CVE-2024-6703","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/8242e0f0-b9c5-46fe-b691-3275cd0f9a43/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-31 21:37:21","sources":[{"name":"Wordfence","remoteId":"8242e0f0-b9c5-46fe-b691-3275cd0f9a43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8242e0f0-b9c5-46fe-b691-3275cd0f9a43?source=api-prod","cve":"CVE-2024-5053","affectedVersions":"<=5.1.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/8def156a-f2f2-4640-a1c9-c21c74e1f308/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValues\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"8def156a-f2f2-4640-a1c9-c21c74e1f308"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8def156a-f2f2-4640-a1c9-c21c74e1f308?source=api-prod","cve":"CVE-2024-4157","affectedVersions":"<=5.1.15","severity":"high"},{"advisoryId":"WPSECADV/WF/8e039295-2ccf-450c-8f2a-d113117b9dce/fluentform","title":"WP Fluent Forms < 3.6.67 - Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-06-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e039295-2ccf-450c-8f2a-d113117b9dce"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e039295-2ccf-450c-8f2a-d113117b9dce?source=api-prod","cve":"CVE-2021-34620","affectedVersions":"<3.6.67","severity":"high"},{"advisoryId":"WPSECADV/WF/938e5d6b-1ad6-4021-a148-1d1c9e8a0a83/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-02 10:27:32","sources":[{"name":"Wordfence","remoteId":"938e5d6b-1ad6-4021-a148-1d1c9e8a0a83"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/938e5d6b-1ad6-4021-a148-1d1c9e8a0a83?source=api-prod","cve":"CVE-2025-9260","affectedVersions":">=5.1.16,<=6.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/954e7509-3ebf-429a-8c65-9825ea190d53/fluentform","title":"FluentForm <= 4.3.25 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"954e7509-3ebf-429a-8c65-9825ea190d53"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/954e7509-3ebf-429a-8c65-9825ea190d53?source=api-prod","cve":"CVE-2023-24410","affectedVersions":"<=4.3.25","severity":"high"},{"advisoryId":"WPSECADV/WF/9e6a1af3-d53c-4e23-95d2-3b799bc10827/fluentform","title":"Contact Form Plugin by FluentForm <= 4.3.12 - CSV Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"9e6a1af3-d53c-4e23-95d2-3b799bc10827"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9e6a1af3-d53c-4e23-95d2-3b799bc10827?source=api-prod","cve":"CVE-2022-3463","affectedVersions":"<=4.3.12","severity":"high"},{"advisoryId":"WPSECADV/WF/be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 23:10:10","sources":[{"name":"Wordfence","remoteId":"be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7?source=api-prod","cve":"CVE-2024-6521","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/c2aee799-4e4c-4a41-8b76-e2ad576fe2e2/fluentform","title":"Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-05 18:10:08","sources":[{"name":"Wordfence","remoteId":"c2aee799-4e4c-4a41-8b76-e2ad576fe2e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c2aee799-4e4c-4a41-8b76-e2ad576fe2e2?source=api-prod","cve":"CVE-2025-13748","affectedVersions":"<=6.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca329b94-1d4c-439c-b45a-6b39ccf3d1eb/fluentform","title":"Fluent Forms <= 5.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca329b94-1d4c-439c-b45a-6b39ccf3d1eb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca329b94-1d4c-439c-b45a-6b39ccf3d1eb?source=api-prod","cve":"CVE-2024-9651","affectedVersions":"<=5.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e06fe8e4-e27a-4492-b175-3b0846e4cf10/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-21 19:39:05","sources":[{"name":"Wordfence","remoteId":"e06fe8e4-e27a-4492-b175-3b0846e4cf10"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e06fe8e4-e27a-4492-b175-3b0846e4cf10?source=api-prod","cve":"CVE-2024-13666","affectedVersions":"<=5.2.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/f31bd18e-57d4-4c87-8a7c-a168e7e70061/fluentform","title":"Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 19:17:45","sources":[{"name":"Wordfence","remoteId":"f31bd18e-57d4-4c87-8a7c-a168e7e70061"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f31bd18e-57d4-4c87-8a7c-a168e7e70061?source=api-prod","cve":"CVE-2025-3615","affectedVersions":"<=6.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f4050403-6b8c-4023-b170-39f3cb68583e/fluentform","title":"Fluent Forms <= 5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"f4050403-6b8c-4023-b170-39f3cb68583e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f4050403-6b8c-4023-b170-39f3cb68583e?source=api-prod","cve":"CVE-2023-6957","affectedVersions":"<=5.1.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/f7dbf179-7099-4dfb-8dad-780f996a7005/fluentform","title":"Fluent Forms <= 6.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 20:40:48","sources":[{"name":"Wordfence","remoteId":"f7dbf179-7099-4dfb-8dad-780f996a7005"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f7dbf179-7099-4dfb-8dad-780f996a7005?source=api-prod","cve":"CVE-2025-13722","affectedVersions":"<=6.1.7","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/00192a36-4b75-4dae-9a6e-0afb02ed5bad/fluentform","title":"Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-09 17:19:48","sources":[{"name":"Wordfence","remoteId":"00192a36-4b75-4dae-9a6e-0afb02ed5bad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00192a36-4b75-4dae-9a6e-0afb02ed5bad?source=api-prod","cve":"CVE-2026-0996","affectedVersions":"<=6.1.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/0101113b-70c2-4db4-b6b1-b2412f6e1214/fluentform","title":"Fluent Forms <= 6.2.1 - Authenticated (Administrator+) Arbitrary File Read via Path Traversal in Email Attachment\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-05 17:53:19","sources":[{"name":"Wordfence","remoteId":"0101113b-70c2-4db4-b6b1-b2412f6e1214"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0101113b-70c2-4db4-b6b1-b2412f6e1214?source=api-prod","cve":"CVE-2026-6344","affectedVersions":"<=6.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/0348d465-f351-4c52-b293-8b3b058292b9/fluentform","title":"Fluent Forms <= 5.1.5 - Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"0348d465-f351-4c52-b293-8b3b058292b9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0348d465-f351-4c52-b293-8b3b058292b9?source=api-prod","cve":"CVE-2024-0618","affectedVersions":"<=5.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/071195d6-3452-4241-a8d3-92efc84e4850/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 19:02:43","sources":[{"name":"Wordfence","remoteId":"071195d6-3452-4241-a8d3-92efc84e4850"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/071195d6-3452-4241-a8d3-92efc84e4850?source=api-prod","cve":"CVE-2024-2771","affectedVersions":"<=5.1.16","severity":"critical"},{"advisoryId":"WPSECADV/WF/0814e7b3-404a-4db5-b564-46c9086ec048/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 19:02:45","sources":[{"name":"Wordfence","remoteId":"0814e7b3-404a-4db5-b564-46c9086ec048"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0814e7b3-404a-4db5-b564-46c9086ec048?source=api-prod","cve":"CVE-2024-2782","affectedVersions":"<=5.1.16","severity":"high"},{"advisoryId":"WPSECADV/WF/0a30d35c-9883-4b0f-83a2-494401c45d8e/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 23:27:30","sources":[{"name":"Wordfence","remoteId":"0a30d35c-9883-4b0f-83a2-494401c45d8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0a30d35c-9883-4b0f-83a2-494401c45d8e?source=api-prod","cve":"CVE-2024-6520","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/0b79a851-1212-4a9c-89fe-b5f2d50ec18c/fluentform","title":"FluentForms <= 4.3.24 - Authenticated(Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"0b79a851-1212-4a9c-89fe-b5f2d50ec18c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0b79a851-1212-4a9c-89fe-b5f2d50ec18c?source=api-prod","cve":"CVE-2023-0546","affectedVersions":"<=4.3.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/154fc656-3a33-4783-a941-10bb848244b3/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-16 00:53:13","sources":[{"name":"Wordfence","remoteId":"154fc656-3a33-4783-a941-10bb848244b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/154fc656-3a33-4783-a941-10bb848244b3?source=api-prod","cve":"CVE-2026-4160","affectedVersions":"=6.1.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/20f31e48-0dbb-498a-a400-681cacea7c9c/fluentform","title":"Contact Form for Plugin by Fluent Forms <= 5.0.8 - Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"20f31e48-0dbb-498a-a400-681cacea7c9c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/20f31e48-0dbb-498a-a400-681cacea7c9c?source=api-prod","cve":"CVE-2023-41952","affectedVersions":"<5.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ccba77c-fb90-4906-b0fe-77607ec5df1f/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 19:02:47","sources":[{"name":"Wordfence","remoteId":"2ccba77c-fb90-4906-b0fe-77607ec5df1f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ccba77c-fb90-4906-b0fe-77607ec5df1f?source=api-prod","cve":"CVE-2024-2772","affectedVersions":"<=5.1.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f/fluentform","title":"FluentForm <= 6.1.11 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f?source=api-prod","cve":"CVE-2025-69001","affectedVersions":"<=6.1.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/41c2ec31-360d-4145-b0b4-77d4d1d4b8a1/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-13 16:24:44","sources":[{"name":"Wordfence","remoteId":"41c2ec31-360d-4145-b0b4-77d4d1d4b8a1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/41c2ec31-360d-4145-b0b4-77d4d1d4b8a1?source=api-prod","cve":"CVE-2024-10646","affectedVersions":"<=5.2.6","severity":"high"},{"advisoryId":"WPSECADV/WF/4ed4dfee-5f14-47ce-abed-cd226c110665/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"4ed4dfee-5f14-47ce-abed-cd226c110665"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ed4dfee-5f14-47ce-abed-cd226c110665?source=api-prod","cve":"CVE-2024-9528","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/5a85c367-99f5-4a46-94bc-ed6e6626514b/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.14 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"5a85c367-99f5-4a46-94bc-ed6e6626514b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5a85c367-99f5-4a46-94bc-ed6e6626514b?source=api-prod","cve":"CVE-2026-25313","affectedVersions":"<=6.1.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/5fe317a6-a391-441a-aac8-c8fa57e73169/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"5fe317a6-a391-441a-aac8-c8fa57e73169"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5fe317a6-a391-441a-aac8-c8fa57e73169?source=api-prod","cve":"CVE-2024-4709","affectedVersions":"<=5.1.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 23:26:31","sources":[{"name":"Wordfence","remoteId":"66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/66ca9c39-1ba0-4208-ae35-d2c3c9ea4eb9?source=api-prod","cve":"CVE-2024-6518","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/69dc9236-8079-434f-b2b5-060a0c5eba46/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"69dc9236-8079-434f-b2b5-060a0c5eba46"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/69dc9236-8079-434f-b2b5-060a0c5eba46?source=api-prod","cve":"CVE-2024-6703","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/8242e0f0-b9c5-46fe-b691-3275cd0f9a43/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-31 21:37:21","sources":[{"name":"Wordfence","remoteId":"8242e0f0-b9c5-46fe-b691-3275cd0f9a43"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8242e0f0-b9c5-46fe-b691-3275cd0f9a43?source=api-prod","cve":"CVE-2024-5053","affectedVersions":"<=5.1.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/8def156a-f2f2-4640-a1c9-c21c74e1f308/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValues\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"8def156a-f2f2-4640-a1c9-c21c74e1f308"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8def156a-f2f2-4640-a1c9-c21c74e1f308?source=api-prod","cve":"CVE-2024-4157","affectedVersions":"<=5.1.15","severity":"high"},{"advisoryId":"WPSECADV/WF/8e039295-2ccf-450c-8f2a-d113117b9dce/fluentform","title":"WP Fluent Forms < 3.6.67 - Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-06-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e039295-2ccf-450c-8f2a-d113117b9dce"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e039295-2ccf-450c-8f2a-d113117b9dce?source=api-prod","cve":"CVE-2021-34620","affectedVersions":"<3.6.67","severity":"high"},{"advisoryId":"WPSECADV/WF/938e5d6b-1ad6-4021-a148-1d1c9e8a0a83/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-02 10:27:32","sources":[{"name":"Wordfence","remoteId":"938e5d6b-1ad6-4021-a148-1d1c9e8a0a83"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/938e5d6b-1ad6-4021-a148-1d1c9e8a0a83?source=api-prod","cve":"CVE-2025-9260","affectedVersions":">=5.1.16,<=6.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/954e7509-3ebf-429a-8c65-9825ea190d53/fluentform","title":"FluentForm <= 4.3.25 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"954e7509-3ebf-429a-8c65-9825ea190d53"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/954e7509-3ebf-429a-8c65-9825ea190d53?source=api-prod","cve":"CVE-2023-24410","affectedVersions":"<=4.3.25","severity":"high"},{"advisoryId":"WPSECADV/WF/9e6a1af3-d53c-4e23-95d2-3b799bc10827/fluentform","title":"Contact Form Plugin by FluentForm <= 4.3.12 - CSV Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"9e6a1af3-d53c-4e23-95d2-3b799bc10827"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9e6a1af3-d53c-4e23-95d2-3b799bc10827?source=api-prod","cve":"CVE-2022-3463","affectedVersions":"<=4.3.12","severity":"high"},{"advisoryId":"WPSECADV/WF/be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7/fluentform","title":"Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-26 23:10:10","sources":[{"name":"Wordfence","remoteId":"be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be7c6cfa-6cac-46d2-8eb9-9fef8049f6e7?source=api-prod","cve":"CVE-2024-6521","affectedVersions":"<=5.1.19","severity":"medium"},{"advisoryId":"WPSECADV/WF/c2aee799-4e4c-4a41-8b76-e2ad576fe2e2/fluentform","title":"Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-05 18:10:08","sources":[{"name":"Wordfence","remoteId":"c2aee799-4e4c-4a41-8b76-e2ad576fe2e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c2aee799-4e4c-4a41-8b76-e2ad576fe2e2?source=api-prod","cve":"CVE-2025-13748","affectedVersions":"<=6.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca329b94-1d4c-439c-b45a-6b39ccf3d1eb/fluentform","title":"Fluent Forms <= 5.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca329b94-1d4c-439c-b45a-6b39ccf3d1eb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca329b94-1d4c-439c-b45a-6b39ccf3d1eb?source=api-prod","cve":"CVE-2024-9651","affectedVersions":"<=5.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e06fe8e4-e27a-4492-b175-3b0846e4cf10/fluentform","title":"Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-21 19:39:05","sources":[{"name":"Wordfence","remoteId":"e06fe8e4-e27a-4492-b175-3b0846e4cf10"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e06fe8e4-e27a-4492-b175-3b0846e4cf10?source=api-prod","cve":"CVE-2024-13666","affectedVersions":"<=5.2.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/f31bd18e-57d4-4c87-8a7c-a168e7e70061/fluentform","title":"Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-16 19:17:45","sources":[{"name":"Wordfence","remoteId":"f31bd18e-57d4-4c87-8a7c-a168e7e70061"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f31bd18e-57d4-4c87-8a7c-a168e7e70061?source=api-prod","cve":"CVE-2025-3615","affectedVersions":"<=6.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f4050403-6b8c-4023-b170-39f3cb68583e/fluentform","title":"Fluent Forms <= 5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"f4050403-6b8c-4023-b170-39f3cb68583e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f4050403-6b8c-4023-b170-39f3cb68583e?source=api-prod","cve":"CVE-2023-6957","affectedVersions":"<=5.1.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/f7dbf179-7099-4dfb-8dad-780f996a7005/fluentform","title":"Fluent Forms <= 6.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-06 20:40:48","sources":[{"name":"Wordfence","remoteId":"f7dbf179-7099-4dfb-8dad-780f996a7005"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f7dbf179-7099-4dfb-8dad-780f996a7005?source=api-prod","cve":"CVE-2025-13722","affectedVersions":"<=6.1.7","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_67657474792d696d61676573811c9dc5_gen.json b/internal/data/assets/plugin_67657474792d696d61676573811c9dc5_gen.json new file mode 100644 index 00000000..1bb6401e --- /dev/null +++ b/internal/data/assets/plugin_67657474792d696d61676573811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/f2c56e24-ebff-4b2d-b5ad-4f25ee20f91d/getty-images","title":"Getty Images <= 4.1.0 - Authenticated (Contributor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"f2c56e24-ebff-4b2d-b5ad-4f25ee20f91d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f2c56e24-ebff-4b2d-b5ad-4f25ee20f91d?source=api-prod","cve":"CVE-2026-39630","affectedVersions":"<=4.1.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_676966742d7570811c9dc5_gen.json b/internal/data/assets/plugin_676966742d7570811c9dc5_gen.json index 4c5c3a07..2a8e5c6a 100644 --- a/internal/data/assets/plugin_676966742d7570811c9dc5_gen.json +++ b/internal/data/assets/plugin_676966742d7570811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/3e8d9909-7b98-4d98-8293-0c30eebc6c7b/gift-up","title":"Gift Up 2.21.3 - Cross-Site Request Forgery via consume_post\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"3e8d9909-7b98-4d98-8293-0c30eebc6c7b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3e8d9909-7b98-4d98-8293-0c30eebc6c7b?source=api-prod","cve":"CVE-2023-49744","affectedVersions":"<=2.21.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/4e498706-3dbe-4c48-9c0d-0d90677aba0d/gift-up","title":"Gift Up Gift Cards for WordPress and WooCommerce <= 2.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"4e498706-3dbe-4c48-9c0d-0d90677aba0d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4e498706-3dbe-4c48-9c0d-0d90677aba0d?source=api-prod","cve":"CVE-2023-5703","affectedVersions":"<=2.20.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/95abec2d-a03a-4b07-8890-18568650c41f/gift-up","title":"Gift Up 2.21.3 - Cross-Site Request Forgery via consume_post\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"95abec2d-a03a-4b07-8890-18568650c41f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/95abec2d-a03a-4b07-8890-18568650c41f?source=api-prod","affectedVersions":"<=2.21.3","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/3e8d9909-7b98-4d98-8293-0c30eebc6c7b/gift-up","title":"Gift Up 2.21.3 - Cross-Site Request Forgery via consume_post\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"3e8d9909-7b98-4d98-8293-0c30eebc6c7b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3e8d9909-7b98-4d98-8293-0c30eebc6c7b?source=api-prod","cve":"CVE-2023-49744","affectedVersions":"<=2.21.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/4e498706-3dbe-4c48-9c0d-0d90677aba0d/gift-up","title":"Gift Up Gift Cards for WordPress and WooCommerce <= 2.20.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"4e498706-3dbe-4c48-9c0d-0d90677aba0d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4e498706-3dbe-4c48-9c0d-0d90677aba0d?source=api-prod","cve":"CVE-2023-5703","affectedVersions":"<=2.20.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/541fbcd6-353f-4ef7-88f1-fc81a6b73e04/gift-up","title":"Gift Up Gift Cards for WordPress and WooCommerce <= 3.1.7 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"541fbcd6-353f-4ef7-88f1-fc81a6b73e04"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/541fbcd6-353f-4ef7-88f1-fc81a6b73e04?source=api-prod","cve":"CVE-2026-32412","affectedVersions":"<=3.1.7","severity":"high"},{"advisoryId":"WPSECADV/WF/95abec2d-a03a-4b07-8890-18568650c41f/gift-up","title":"Gift Up 2.21.3 - Cross-Site Request Forgery via consume_post\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"95abec2d-a03a-4b07-8890-18568650c41f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/95abec2d-a03a-4b07-8890-18568650c41f?source=api-prod","affectedVersions":"<=2.21.3","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_676c6f62616c2d7061796d656e74732d776f6f636f6d6d65726365811c9dc5_gen.json b/internal/data/assets/plugin_676c6f62616c2d7061796d656e74732d776f6f636f6d6d65726365811c9dc5_gen.json index 4d5e254f..3c2c9816 100644 --- a/internal/data/assets/plugin_676c6f62616c2d7061796d656e74732d776f6f636f6d6d65726365811c9dc5_gen.json +++ b/internal/data/assets/plugin_676c6f62616c2d7061796d656e74732d776f6f636f6d6d65726365811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0e227024-af7e-44f8-bed9-70d361ab590f/global-payments-woocommerce","title":"GlobalPayments WooCommerce <= 1.13.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"0e227024-af7e-44f8-bed9-70d361ab590f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e227024-af7e-44f8-bed9-70d361ab590f?source=api-prod","cve":"CVE-2025-22767","affectedVersions":"<=1.13.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0e227024-af7e-44f8-bed9-70d361ab590f/global-payments-woocommerce","title":"GlobalPayments WooCommerce <= 1.13.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"0e227024-af7e-44f8-bed9-70d361ab590f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e227024-af7e-44f8-bed9-70d361ab590f?source=api-prod","cve":"CVE-2025-22767","affectedVersions":"<=1.13.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/87950d16-dba6-4759-b15f-57c495cdda67/global-payments-woocommerce","title":"GlobalPayments WooCommerce <= 1.18.0 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"87950d16-dba6-4759-b15f-57c495cdda67"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/87950d16-dba6-4759-b15f-57c495cdda67?source=api-prod","cve":"CVE-2026-39645","affectedVersions":"<=1.18.0","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_67726176697479736d7470811c9dc5_gen.json b/internal/data/assets/plugin_67726176697479736d7470811c9dc5_gen.json index 85547502..710351da 100644 --- a/internal/data/assets/plugin_67726176697479736d7470811c9dc5_gen.json +++ b/internal/data/assets/plugin_67726176697479736d7470811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0f9d18a4-262b-4011-91e9-b29a27a76470/gravitysmtp","title":"Gravity SMTP <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Plugin Uninstall\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-09 21:01:07","sources":[{"name":"Wordfence","remoteId":"0f9d18a4-262b-4011-91e9-b29a27a76470"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f9d18a4-262b-4011-91e9-b29a27a76470?source=api-prod","cve":"CVE-2026-4162","affectedVersions":"<=2.1.4","severity":"high"},{"advisoryId":"WPSECADV/WF/12a296db-ecc0-409b-8718-0c208504053a/gravitysmtp","title":"Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-30 12:09:08","sources":[{"name":"Wordfence","remoteId":"12a296db-ecc0-409b-8718-0c208504053a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/12a296db-ecc0-409b-8718-0c208504053a?source=api-prod","cve":"CVE-2026-4020","affectedVersions":"<=2.1.4","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0f9d18a4-262b-4011-91e9-b29a27a76470/gravitysmtp","title":"Gravity SMTP <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Plugin Uninstall\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-09 21:01:07","sources":[{"name":"Wordfence","remoteId":"0f9d18a4-262b-4011-91e9-b29a27a76470"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f9d18a4-262b-4011-91e9-b29a27a76470?source=api-prod","cve":"CVE-2026-4162","affectedVersions":"<=2.1.4","severity":"high"},{"advisoryId":"WPSECADV/WF/12a296db-ecc0-409b-8718-0c208504053a/gravitysmtp","title":"Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-30 12:09:08","sources":[{"name":"Wordfence","remoteId":"12a296db-ecc0-409b-8718-0c208504053a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/12a296db-ecc0-409b-8718-0c208504053a?source=api-prod","cve":"CVE-2026-4020","affectedVersions":"<=2.1.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_677265656e6c792d6164646f6e73811c9dc5_gen.json b/internal/data/assets/plugin_677265656e6c792d6164646f6e73811c9dc5_gen.json new file mode 100644 index 00000000..7f115a87 --- /dev/null +++ b/internal/data/assets/plugin_677265656e6c792d6164646f6e73811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/ef61aeba-2105-4da8-8e9c-480e6ed820b7/greenly-addons","title":"Greenly Theme Addons < 8.2 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"ef61aeba-2105-4da8-8e9c-480e6ed820b7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ef61aeba-2105-4da8-8e9c-480e6ed820b7?source=api-prod","cve":"CVE-2026-32393","affectedVersions":"<8.2","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_686964652d6d792d7770811c9dc5_gen.json b/internal/data/assets/plugin_686964652d6d792d7770811c9dc5_gen.json index fac61103..a415bd70 100644 --- a/internal/data/assets/plugin_686964652d6d792d7770811c9dc5_gen.json +++ b/internal/data/assets/plugin_686964652d6d792d7770811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/4cf89f94-587a-4fed-a6e4-3876b7dbc9ba/hide-my-wp","title":"Hide My WP Ghost – Security Plugin <= 5.0.18 - IP Address Spoofing to Protection Mechanism Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"4cf89f94-587a-4fed-a6e4-3876b7dbc9ba"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4cf89f94-587a-4fed-a6e4-3876b7dbc9ba?source=api-prod","cve":"CVE-2022-4537","affectedVersions":"<=5.0.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/5618db77-fe74-4982-92b3-cec554640bde/hide-my-wp","title":"Hide My WP Ghost <= 5.0.25 - CAPTCHA Bypass in brute_math_authenticate\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"5618db77-fe74-4982-92b3-cec554640bde"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5618db77-fe74-4982-92b3-cec554640bde?source=api-prod","cve":"CVE-2023-34001","affectedVersions":"<=5.0.25","severity":"medium"},{"advisoryId":"WPSECADV/WF/8445f318-ef4e-45c5-be9b-6080833c3bb6/hide-my-wp","title":"Hide My WP Ghost – Security & Firewall <= 5.2.01 - Login Page Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"8445f318-ef4e-45c5-be9b-6080833c3bb6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8445f318-ef4e-45c5-be9b-6080833c3bb6?source=api-prod","cve":"CVE-2024-6420","affectedVersions":"<=5.2.01","severity":"medium"},{"advisoryId":"WPSECADV/WF/9effa526-7454-4490-9bf4-0605254d6625/hide-my-wp","title":"Hide My WP Ghost – Security & Firewall <= 5.3.02 - Unauthenticated Login Page Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"9effa526-7454-4490-9bf4-0605254d6625"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9effa526-7454-4490-9bf4-0605254d6625?source=api-prod","cve":"CVE-2024-13794","affectedVersions":"<=5.3.02","severity":"medium"},{"advisoryId":"WPSECADV/WF/a003e922-d6c6-4f99-9b94-a3232d311677/hide-my-wp","title":"Hide My WP Ghost <= 5.4.01 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"a003e922-d6c6-4f99-9b94-a3232d311677"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a003e922-d6c6-4f99-9b94-a3232d311677?source=api-prod","cve":"CVE-2025-26909","affectedVersions":"<=5.4.01","severity":"critical"},{"advisoryId":"WPSECADV/WF/c467a634-d5cf-4e80-9a64-009cdad2a684/hide-my-wp","title":"Hide My WP Ghost – Security & Firewall <= 5.3.01 - Reflected Cross-Site Scripting via URL\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-14 18:16:20","sources":[{"name":"Wordfence","remoteId":"c467a634-d5cf-4e80-9a64-009cdad2a684"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c467a634-d5cf-4e80-9a64-009cdad2a684?source=api-prod","cve":"CVE-2024-10825","affectedVersions":"<=5.3.01","severity":"medium"},{"advisoryId":"WPSECADV/WF/f43db496-80ea-442c-9417-7aa03ec95f02/hide-my-wp","title":"WP Ghost <= 5.4.01 - Unauthenticated Limited File Read\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-13 16:21:37","sources":[{"name":"Wordfence","remoteId":"f43db496-80ea-442c-9417-7aa03ec95f02"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f43db496-80ea-442c-9417-7aa03ec95f02?source=api-prod","cve":"CVE-2025-2056","affectedVersions":"<=5.4.01","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/4cf89f94-587a-4fed-a6e4-3876b7dbc9ba/hide-my-wp","title":"Hide My WP Ghost – Security Plugin <= 5.0.18 - IP Address Spoofing to Protection Mechanism Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"4cf89f94-587a-4fed-a6e4-3876b7dbc9ba"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4cf89f94-587a-4fed-a6e4-3876b7dbc9ba?source=api-prod","cve":"CVE-2022-4537","affectedVersions":"<=5.0.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/5618db77-fe74-4982-92b3-cec554640bde/hide-my-wp","title":"Hide My WP Ghost <= 5.0.25 - CAPTCHA Bypass in brute_math_authenticate\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"5618db77-fe74-4982-92b3-cec554640bde"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5618db77-fe74-4982-92b3-cec554640bde?source=api-prod","cve":"CVE-2023-34001","affectedVersions":"<=5.0.25","severity":"medium"},{"advisoryId":"WPSECADV/WF/8445f318-ef4e-45c5-be9b-6080833c3bb6/hide-my-wp","title":"Hide My WP Ghost – Security & Firewall <= 5.2.01 - Login Page Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"8445f318-ef4e-45c5-be9b-6080833c3bb6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8445f318-ef4e-45c5-be9b-6080833c3bb6?source=api-prod","cve":"CVE-2024-6420","affectedVersions":"<=5.2.01","severity":"medium"},{"advisoryId":"WPSECADV/WF/9effa526-7454-4490-9bf4-0605254d6625/hide-my-wp","title":"Hide My WP Ghost – Security & Firewall <= 5.3.02 - Unauthenticated Login Page Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"9effa526-7454-4490-9bf4-0605254d6625"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9effa526-7454-4490-9bf4-0605254d6625?source=api-prod","cve":"CVE-2024-13794","affectedVersions":"<=5.3.02","severity":"medium"},{"advisoryId":"WPSECADV/WF/a003e922-d6c6-4f99-9b94-a3232d311677/hide-my-wp","title":"Hide My WP Ghost <= 5.4.01 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"a003e922-d6c6-4f99-9b94-a3232d311677"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a003e922-d6c6-4f99-9b94-a3232d311677?source=api-prod","cve":"CVE-2025-26909","affectedVersions":"<=5.4.01","severity":"critical"},{"advisoryId":"WPSECADV/WF/c467a634-d5cf-4e80-9a64-009cdad2a684/hide-my-wp","title":"Hide My WP Ghost – Security & Firewall <= 5.3.01 - Reflected Cross-Site Scripting via URL\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-14 18:16:20","sources":[{"name":"Wordfence","remoteId":"c467a634-d5cf-4e80-9a64-009cdad2a684"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c467a634-d5cf-4e80-9a64-009cdad2a684?source=api-prod","cve":"CVE-2024-10825","affectedVersions":"<=5.3.01","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca12d05f-23f4-44e4-b513-a0452a170130/hide-my-wp","title":"Hide My WP Ghost < 7.0.00 - Unauthenticated Open Redirect\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca12d05f-23f4-44e4-b513-a0452a170130"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca12d05f-23f4-44e4-b513-a0452a170130?source=api-prod","cve":"CVE-2026-39484","affectedVersions":"<7.0.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/f43db496-80ea-442c-9417-7aa03ec95f02/hide-my-wp","title":"WP Ghost <= 5.4.01 - Unauthenticated Limited File Read\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-13 16:21:37","sources":[{"name":"Wordfence","remoteId":"f43db496-80ea-442c-9417-7aa03ec95f02"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f43db496-80ea-442c-9417-7aa03ec95f02?source=api-prod","cve":"CVE-2025-2056","affectedVersions":"<=5.4.01","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_696e736572742d706870811c9dc5_gen.json b/internal/data/assets/plugin_696e736572742d706870811c9dc5_gen.json index 5eef8b9d..de70ff4d 100644 --- a/internal/data/assets/plugin_696e736572742d706870811c9dc5_gen.json +++ b/internal/data/assets/plugin_696e736572742d706870811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/069bd7ab-1b78-4465-8e13-5ef903f7e45f/insert-php","title":"Woody Ad Snippets <= 2.2.5 - Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-08-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"069bd7ab-1b78-4465-8e13-5ef903f7e45f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/069bd7ab-1b78-4465-8e13-5ef903f7e45f?source=api-prod","cve":"CVE-2019-14773","affectedVersions":"<=2.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/11681152-e4f0-4cea-8fc8-f297368e4b15/insert-php","title":"Woody Ad Snippets <= 2.2.8 - Authenticated Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-09-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"11681152-e4f0-4cea-8fc8-f297368e4b15"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/11681152-e4f0-4cea-8fc8-f297368e4b15?source=api-prod","cve":"CVE-2019-16289","affectedVersions":"<2.2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/134ad095-b0a0-4f0f-832d-3e558d4a250a/insert-php","title":"Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-14 20:26:37","sources":[{"name":"Wordfence","remoteId":"134ad095-b0a0-4f0f-832d-3e558d4a250a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/134ad095-b0a0-4f0f-832d-3e558d4a250a?source=api-prod","cve":"CVE-2024-3105","affectedVersions":"<=2.5.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/942ae035-91b3-4330-800c-2dbe94a4b4b5/insert-php","title":"Woody Ad Snippets <= 2.2.4 - Missing Authorization to Settings Import\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-08-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"942ae035-91b3-4330-800c-2dbe94a4b4b5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/942ae035-91b3-4330-800c-2dbe94a4b4b5?source=api-prod","cve":"CVE-2019-15858","affectedVersions":"<2.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/95bae3f2-313b-4b6c-a81c-8af6f169151b/insert-php","title":"Woody code snippets <= 2.4.5 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-06-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"95bae3f2-313b-4b6c-a81c-8af6f169151b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/95bae3f2-313b-4b6c-a81c-8af6f169151b?source=api-prod","affectedVersions":"<=2.4.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/e279f923-e30d-45b6-9734-2bd50731c33c/insert-php","title":"Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"e279f923-e30d-45b6-9734-2bd50731c33c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e279f923-e30d-45b6-9734-2bd50731c33c?source=api-prod","cve":"CVE-2024-35751","affectedVersions":"<=2.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e573c0a4-d053-400b-828c-0d0eca880776/insert-php","title":"Woody code snippets <= 2.3.9 - Cross-Site Request Forgery Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-09-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"e573c0a4-d053-400b-828c-0d0eca880776"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e573c0a4-d053-400b-828c-0d0eca880776?source=api-prod","cve":"CVE-2020-36759","affectedVersions":"<2.3.10","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/069bd7ab-1b78-4465-8e13-5ef903f7e45f/insert-php","title":"Woody Ad Snippets <= 2.2.5 - Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-08-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"069bd7ab-1b78-4465-8e13-5ef903f7e45f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/069bd7ab-1b78-4465-8e13-5ef903f7e45f?source=api-prod","cve":"CVE-2019-14773","affectedVersions":"<=2.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/11681152-e4f0-4cea-8fc8-f297368e4b15/insert-php","title":"Woody Ad Snippets <= 2.2.8 - Authenticated Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-09-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"11681152-e4f0-4cea-8fc8-f297368e4b15"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/11681152-e4f0-4cea-8fc8-f297368e4b15?source=api-prod","cve":"CVE-2019-16289","affectedVersions":"<2.2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/134ad095-b0a0-4f0f-832d-3e558d4a250a/insert-php","title":"Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-14 20:26:37","sources":[{"name":"Wordfence","remoteId":"134ad095-b0a0-4f0f-832d-3e558d4a250a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/134ad095-b0a0-4f0f-832d-3e558d4a250a?source=api-prod","cve":"CVE-2024-3105","affectedVersions":"<=2.5.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/942ae035-91b3-4330-800c-2dbe94a4b4b5/insert-php","title":"Woody Ad Snippets <= 2.2.4 - Missing Authorization to Settings Import\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-08-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"942ae035-91b3-4330-800c-2dbe94a4b4b5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/942ae035-91b3-4330-800c-2dbe94a4b4b5?source=api-prod","cve":"CVE-2019-15858","affectedVersions":"<2.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/95bae3f2-313b-4b6c-a81c-8af6f169151b/insert-php","title":"Woody code snippets <= 2.4.5 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-06-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"95bae3f2-313b-4b6c-a81c-8af6f169151b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/95bae3f2-313b-4b6c-a81c-8af6f169151b?source=api-prod","affectedVersions":"<=2.4.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/ada52ae9-7d14-405d-9efc-b993ea273a26/insert-php","title":"Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts <= 2.7.1 - Authenticated (Contributor+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"ada52ae9-7d14-405d-9efc-b993ea273a26"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ada52ae9-7d14-405d-9efc-b993ea273a26?source=api-prod","cve":"CVE-2026-25366","affectedVersions":"<=2.7.1","severity":"high"},{"advisoryId":"WPSECADV/WF/e279f923-e30d-45b6-9734-2bd50731c33c/insert-php","title":"Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"e279f923-e30d-45b6-9734-2bd50731c33c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e279f923-e30d-45b6-9734-2bd50731c33c?source=api-prod","cve":"CVE-2024-35751","affectedVersions":"<=2.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e573c0a4-d053-400b-828c-0d0eca880776/insert-php","title":"Woody code snippets <= 2.3.9 - Cross-Site Request Forgery Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-09-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"e573c0a4-d053-400b-828c-0d0eca880776"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e573c0a4-d053-400b-828c-0d0eca880776?source=api-prod","cve":"CVE-2020-36759","affectedVersions":"<2.3.10","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_696e7374616e74696f811c9dc5_gen.json b/internal/data/assets/plugin_696e7374616e74696f811c9dc5_gen.json index 81437f6f..d776872a 100644 --- a/internal/data/assets/plugin_696e7374616e74696f811c9dc5_gen.json +++ b/internal/data/assets/plugin_696e7374616e74696f811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/739abe9a-bcc2-4014-8441-38b326802a70/instantio","title":"Instantio <= 3.3.7 - Missing Authorization to Unauthenticated Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"739abe9a-bcc2-4014-8441-38b326802a70"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/739abe9a-bcc2-4014-8441-38b326802a70?source=api-prod","cve":"CVE-2025-24581","affectedVersions":"<=3.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/a7f82847-433d-49b1-815d-b0d9e70068c2/instantio","title":"Instantio – WooCommerce Quick Checkout | Instant Checkout, Side Cart & Popup Cart <= 1.2.5 - Cross Site Request Forgery\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-06-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"a7f82847-433d-49b1-815d-b0d9e70068c2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a7f82847-433d-49b1-815d-b0d9e70068c2?source=api-prod","affectedVersions":"<=1.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/e2521876-cd1c-4c4a-8486-b1c4da78ffdb/instantio","title":"Instantio <= 3.3.16 - Authenticated (Admin+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"e2521876-cd1c-4c4a-8486-b1c4da78ffdb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e2521876-cd1c-4c4a-8486-b1c4da78ffdb?source=api-prod","cve":"CVE-2025-47550","affectedVersions":"<=3.3.16","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/739abe9a-bcc2-4014-8441-38b326802a70/instantio","title":"Instantio <= 3.3.7 - Missing Authorization to Unauthenticated Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"739abe9a-bcc2-4014-8441-38b326802a70"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/739abe9a-bcc2-4014-8441-38b326802a70?source=api-prod","cve":"CVE-2025-24581","affectedVersions":"<=3.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/a7f82847-433d-49b1-815d-b0d9e70068c2/instantio","title":"Instantio – WooCommerce Quick Checkout | Instant Checkout, Side Cart & Popup Cart <= 1.2.5 - Cross Site Request Forgery\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-06-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"a7f82847-433d-49b1-815d-b0d9e70068c2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a7f82847-433d-49b1-815d-b0d9e70068c2?source=api-prod","affectedVersions":"<=1.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/d0a818b6-5e25-4c96-8757-b8593c713923/instantio","title":"Instantio <= 3.3.30 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d0a818b6-5e25-4c96-8757-b8593c713923"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d0a818b6-5e25-4c96-8757-b8593c713923?source=api-prod","cve":"CVE-2026-39571","affectedVersions":"<=3.3.30","severity":"medium"},{"advisoryId":"WPSECADV/WF/e2521876-cd1c-4c4a-8486-b1c4da78ffdb/instantio","title":"Instantio <= 3.3.16 - Authenticated (Admin+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"e2521876-cd1c-4c4a-8486-b1c4da78ffdb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e2521876-cd1c-4c4a-8486-b1c4da78ffdb?source=api-prod","cve":"CVE-2025-47550","affectedVersions":"<=3.3.16","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6a65742d656e67696e65811c9dc5_gen.json b/internal/data/assets/plugin_6a65742d656e67696e65811c9dc5_gen.json index 13d36581..0719607b 100644 --- a/internal/data/assets/plugin_6a65742d656e67696e65811c9dc5_gen.json +++ b/internal/data/assets/plugin_6a65742d656e67696e65811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/099e8784-48d2-4be7-9549-b9dbe57fe637/jet-engine","title":"JetEngine <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"099e8784-48d2-4be7-9549-b9dbe57fe637"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/099e8784-48d2-4be7-9549-b9dbe57fe637?source=api-prod","cve":"CVE-2025-49938","affectedVersions":"<=3.7.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/0ef8f81e-b241-43c3-9045-610cdbc08be1/jet-engine","title":"JetEngine <= 3.6.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"0ef8f81e-b241-43c3-9045-610cdbc08be1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0ef8f81e-b241-43c3-9045-610cdbc08be1?source=api-prod","cve":"CVE-2025-26870","affectedVersions":"<=3.6.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/1c1e1c18-fecd-45a9-a515-11073c9f1aec/jet-engine","title":"JetEngine <= 3.7.0 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c1e1c18-fecd-45a9-a515-11073c9f1aec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c1e1c18-fecd-45a9-a515-11073c9f1aec?source=api-prod","cve":"CVE-2025-53196","affectedVersions":"<=3.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/1c85e5e0-d8ee-46d3-99b1-df6c6744f020/jet-engine","title":"Multiple Plugins by Crocoblock <= (Various Versions) - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c85e5e0-d8ee-46d3-99b1-df6c6744f020"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c85e5e0-d8ee-46d3-99b1-df6c6744f020?source=api-prod","cve":"CVE-2023-48762","affectedVersions":"<=3.2.5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/29a5701f-92f7-4a02-a990-b189a381cff5/jet-engine","title":"JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via '_cct_search' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-13 12:57:24","sources":[{"name":"Wordfence","remoteId":"29a5701f-92f7-4a02-a990-b189a381cff5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/29a5701f-92f7-4a02-a990-b189a381cff5?source=api-prod","cve":"CVE-2026-4352","affectedVersions":"<=3.8.6.1","severity":"high"},{"advisoryId":"WPSECADV/WF/3f2c97f4-0a6e-4693-a6c8-bd81ca76988c/jet-engine","title":"JetEngine <= 3.2.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"3f2c97f4-0a6e-4693-a6c8-bd81ca76988c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3f2c97f4-0a6e-4693-a6c8-bd81ca76988c?source=api-prod","cve":"CVE-2023-48758","affectedVersions":"<=3.2.4","severity":"high"},{"advisoryId":"WPSECADV/WF/40abaa5e-7dd5-4a4e-877c-0a56386f5ffe/jet-engine","title":"JetEngine <= 3.7.7 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"40abaa5e-7dd5-4a4e-877c-0a56386f5ffe"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/40abaa5e-7dd5-4a4e-877c-0a56386f5ffe?source=api-prod","cve":"CVE-2025-67923","affectedVersions":"<=3.7.7","severity":"high"},{"advisoryId":"WPSECADV/WF/594431b7-9bc7-4e86-bc20-311fdab657b6/jet-engine","title":"JetEngine <= 3.8.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"594431b7-9bc7-4e86-bc20-311fdab657b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/594431b7-9bc7-4e86-bc20-311fdab657b6?source=api-prod","cve":"CVE-2025-68495","affectedVersions":"<=3.8.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/84875591-2754-4415-9a77-8824fdfa89dd/jet-engine","title":"JetEngine <= 3.8.1.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"84875591-2754-4415-9a77-8824fdfa89dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/84875591-2754-4415-9a77-8824fdfa89dd?source=api-prod","cve":"CVE-2025-69333","affectedVersions":"<=3.8.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/893500ba-cc16-4429-bbe1-725aa65589c9/jet-engine","title":"Multiple Plugins by Crocoblock <= (Various Versions) - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"893500ba-cc16-4429-bbe1-725aa65589c9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/893500ba-cc16-4429-bbe1-725aa65589c9?source=api-prod","cve":"CVE-2023-48761","affectedVersions":"<=3.2.5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8ad473d5-f54b-4801-9ba3-54e4dddf26f7/jet-engine","title":"JetEngine <= 3.7.1 - Authenticated (Contributor+) Server-Side Template Injection to Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ad473d5-f54b-4801-9ba3-54e4dddf26f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ad473d5-f54b-4801-9ba3-54e4dddf26f7?source=api-prod","cve":"CVE-2025-53194","affectedVersions":"<=3.7.1","severity":"high"},{"advisoryId":"WPSECADV/WF/9a4f28bb-7669-483a-b93a-276b7a10826a/jet-engine","title":"JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"9a4f28bb-7669-483a-b93a-276b7a10826a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9a4f28bb-7669-483a-b93a-276b7a10826a?source=api-prod","cve":"CVE-2026-28134","affectedVersions":"<=3.7.2","severity":"high"},{"advisoryId":"WPSECADV/WF/ad66015d-7831-4590-9583-3abf7ca43c3b/jet-engine","title":"JetEngine <= 3.2.4 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad66015d-7831-4590-9583-3abf7ca43c3b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad66015d-7831-4590-9583-3abf7ca43c3b?source=api-prod","cve":"CVE-2023-48757","affectedVersions":"<=3.2.4","severity":"high"},{"advisoryId":"WPSECADV/WF/d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e/jet-engine","title":"Crocoblock JetEngine <= 3.1.3 - Authenticated(Author+) Arbitrary File Upload to Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e?source=api-prod","cve":"CVE-2023-1406","affectedVersions":"<=3.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/d938b867-a29a-460b-bfc2-1ba4490ee105/jet-engine","title":"JetEngine <= 3.7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"d938b867-a29a-460b-bfc2-1ba4490ee105"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d938b867-a29a-460b-bfc2-1ba4490ee105?source=api-prod","cve":"CVE-2025-54688","affectedVersions":"<=3.7.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e37cabad-c41c-4fba-b01d-a5eb5c7d5254/jet-engine","title":"JetEngine <= 3.8.8.1 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"e37cabad-c41c-4fba-b01d-a5eb5c7d5254"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e37cabad-c41c-4fba-b01d-a5eb5c7d5254?source=api-prod","cve":"CVE-2026-42774","affectedVersions":"<=3.8.8.1","severity":"high"},{"advisoryId":"WPSECADV/WF/f10cf49b-1b78-43c1-b0d1-c1dbb74d5696/jet-engine","title":"JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 16:17:43","sources":[{"name":"Wordfence","remoteId":"f10cf49b-1b78-43c1-b0d1-c1dbb74d5696"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f10cf49b-1b78-43c1-b0d1-c1dbb74d5696?source=api-prod","cve":"CVE-2026-4662","affectedVersions":"<=3.8.6.1","severity":"high"},{"advisoryId":"WPSECADV/WF/f27979a8-0e68-4a45-9e3e-3667d88361d8/jet-engine","title":"Jet Engine <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-17 18:34:33","sources":[{"name":"Wordfence","remoteId":"f27979a8-0e68-4a45-9e3e-3667d88361d8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f27979a8-0e68-4a45-9e3e-3667d88361d8?source=api-prod","cve":"CVE-2025-0369","affectedVersions":"<=3.6.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f920d63e-2101-4192-8916-be2d42929a54/jet-engine","title":"JetEngine <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"f920d63e-2101-4192-8916-be2d42929a54"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f920d63e-2101-4192-8916-be2d42929a54?source=api-prod","cve":"CVE-2025-53195","affectedVersions":"<=3.7.0","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/099e8784-48d2-4be7-9549-b9dbe57fe637/jet-engine","title":"JetEngine <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"099e8784-48d2-4be7-9549-b9dbe57fe637"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/099e8784-48d2-4be7-9549-b9dbe57fe637?source=api-prod","cve":"CVE-2025-49938","affectedVersions":"<=3.7.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/0ef8f81e-b241-43c3-9045-610cdbc08be1/jet-engine","title":"JetEngine <= 3.6.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"0ef8f81e-b241-43c3-9045-610cdbc08be1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0ef8f81e-b241-43c3-9045-610cdbc08be1?source=api-prod","cve":"CVE-2025-26870","affectedVersions":"<=3.6.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/1c1e1c18-fecd-45a9-a515-11073c9f1aec/jet-engine","title":"JetEngine <= 3.7.0 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c1e1c18-fecd-45a9-a515-11073c9f1aec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c1e1c18-fecd-45a9-a515-11073c9f1aec?source=api-prod","cve":"CVE-2025-53196","affectedVersions":"<=3.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/1c85e5e0-d8ee-46d3-99b1-df6c6744f020/jet-engine","title":"Multiple Plugins by Crocoblock <= (Various Versions) - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c85e5e0-d8ee-46d3-99b1-df6c6744f020"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c85e5e0-d8ee-46d3-99b1-df6c6744f020?source=api-prod","cve":"CVE-2023-48762","affectedVersions":"<=3.2.5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/29a5701f-92f7-4a02-a990-b189a381cff5/jet-engine","title":"JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via '_cct_search' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-13 12:57:24","sources":[{"name":"Wordfence","remoteId":"29a5701f-92f7-4a02-a990-b189a381cff5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/29a5701f-92f7-4a02-a990-b189a381cff5?source=api-prod","cve":"CVE-2026-4352","affectedVersions":"<=3.8.6.1","severity":"high"},{"advisoryId":"WPSECADV/WF/3f2c97f4-0a6e-4693-a6c8-bd81ca76988c/jet-engine","title":"JetEngine <= 3.2.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"3f2c97f4-0a6e-4693-a6c8-bd81ca76988c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3f2c97f4-0a6e-4693-a6c8-bd81ca76988c?source=api-prod","cve":"CVE-2023-48758","affectedVersions":"<=3.2.4","severity":"high"},{"advisoryId":"WPSECADV/WF/40abaa5e-7dd5-4a4e-877c-0a56386f5ffe/jet-engine","title":"JetEngine <= 3.7.7 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"40abaa5e-7dd5-4a4e-877c-0a56386f5ffe"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/40abaa5e-7dd5-4a4e-877c-0a56386f5ffe?source=api-prod","cve":"CVE-2025-67923","affectedVersions":"<=3.7.7","severity":"high"},{"advisoryId":"WPSECADV/WF/594431b7-9bc7-4e86-bc20-311fdab657b6/jet-engine","title":"JetEngine <= 3.8.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"594431b7-9bc7-4e86-bc20-311fdab657b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/594431b7-9bc7-4e86-bc20-311fdab657b6?source=api-prod","cve":"CVE-2025-68495","affectedVersions":"<=3.8.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/84875591-2754-4415-9a77-8824fdfa89dd/jet-engine","title":"JetEngine <= 3.8.1.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"84875591-2754-4415-9a77-8824fdfa89dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/84875591-2754-4415-9a77-8824fdfa89dd?source=api-prod","cve":"CVE-2025-69333","affectedVersions":"<=3.8.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/893500ba-cc16-4429-bbe1-725aa65589c9/jet-engine","title":"Multiple Plugins by Crocoblock <= (Various Versions) - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"893500ba-cc16-4429-bbe1-725aa65589c9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/893500ba-cc16-4429-bbe1-725aa65589c9?source=api-prod","cve":"CVE-2023-48761","affectedVersions":"<=3.2.5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8ad473d5-f54b-4801-9ba3-54e4dddf26f7/jet-engine","title":"JetEngine <= 3.7.1 - Authenticated (Contributor+) Server-Side Template Injection to Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ad473d5-f54b-4801-9ba3-54e4dddf26f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ad473d5-f54b-4801-9ba3-54e4dddf26f7?source=api-prod","cve":"CVE-2025-53194","affectedVersions":"<=3.7.1","severity":"high"},{"advisoryId":"WPSECADV/WF/9a4f28bb-7669-483a-b93a-276b7a10826a/jet-engine","title":"JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"9a4f28bb-7669-483a-b93a-276b7a10826a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9a4f28bb-7669-483a-b93a-276b7a10826a?source=api-prod","cve":"CVE-2026-28134","affectedVersions":"<=3.7.2","severity":"high"},{"advisoryId":"WPSECADV/WF/ad66015d-7831-4590-9583-3abf7ca43c3b/jet-engine","title":"JetEngine <= 3.2.4 - Authenticated (Contributor+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad66015d-7831-4590-9583-3abf7ca43c3b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad66015d-7831-4590-9583-3abf7ca43c3b?source=api-prod","cve":"CVE-2023-48757","affectedVersions":"<=3.2.4","severity":"high"},{"advisoryId":"WPSECADV/WF/d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e/jet-engine","title":"Crocoblock JetEngine <= 3.1.3 - Authenticated(Author+) Arbitrary File Upload to Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d7e7247f-869a-4cf0-ae03-0b36ecbc1b7e?source=api-prod","cve":"CVE-2023-1406","affectedVersions":"<=3.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/d938b867-a29a-460b-bfc2-1ba4490ee105/jet-engine","title":"JetEngine <= 3.7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"d938b867-a29a-460b-bfc2-1ba4490ee105"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d938b867-a29a-460b-bfc2-1ba4490ee105?source=api-prod","cve":"CVE-2025-54688","affectedVersions":"<=3.7.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/e37cabad-c41c-4fba-b01d-a5eb5c7d5254/jet-engine","title":"JetEngine <= 3.8.8.1 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"e37cabad-c41c-4fba-b01d-a5eb5c7d5254"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e37cabad-c41c-4fba-b01d-a5eb5c7d5254?source=api-prod","cve":"CVE-2026-42774","affectedVersions":"<=3.8.8.1","severity":"high"},{"advisoryId":"WPSECADV/WF/f0e97124-641c-4d35-a274-6a127d2d7d18/jet-engine","title":"JetEngine < 3.8.4.1 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"f0e97124-641c-4d35-a274-6a127d2d7d18"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f0e97124-641c-4d35-a274-6a127d2d7d18?source=api-prod","cve":"CVE-2026-32355","affectedVersions":"<3.8.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/f10cf49b-1b78-43c1-b0d1-c1dbb74d5696/jet-engine","title":"JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via Listing Grid 'filtered_query' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 16:17:43","sources":[{"name":"Wordfence","remoteId":"f10cf49b-1b78-43c1-b0d1-c1dbb74d5696"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f10cf49b-1b78-43c1-b0d1-c1dbb74d5696?source=api-prod","cve":"CVE-2026-4662","affectedVersions":"<=3.8.6.1","severity":"high"},{"advisoryId":"WPSECADV/WF/f27979a8-0e68-4a45-9e3e-3667d88361d8/jet-engine","title":"Jet Engine <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-17 18:34:33","sources":[{"name":"Wordfence","remoteId":"f27979a8-0e68-4a45-9e3e-3667d88361d8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f27979a8-0e68-4a45-9e3e-3667d88361d8?source=api-prod","cve":"CVE-2025-0369","affectedVersions":"<=3.6.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f920d63e-2101-4192-8916-be2d42929a54/jet-engine","title":"JetEngine <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"f920d63e-2101-4192-8916-be2d42929a54"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f920d63e-2101-4192-8916-be2d42929a54?source=api-prod","cve":"CVE-2025-53195","affectedVersions":"<=3.7.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6a6574666f726d6275696c646572811c9dc5_gen.json b/internal/data/assets/plugin_6a6574666f726d6275696c646572811c9dc5_gen.json index 4b04dcf0..dc17f5df 100644 --- a/internal/data/assets/plugin_6a6574666f726d6275696c646572811c9dc5_gen.json +++ b/internal/data/assets/plugin_6a6574666f726d6275696c646572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0d8ea1c2-7c6e-43b3-97ca-a06438d51d11/jetformbuilder","title":"JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d8ea1c2-7c6e-43b3-97ca-a06438d51d11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d8ea1c2-7c6e-43b3-97ca-a06438d51d11?source=api-prod","cve":"CVE-2024-7291","affectedVersions":"<=3.3.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/1801fd3e-d56f-4540-9700-9e9de8b465e1/jetformbuilder","title":"JetFormBuilder <= 3.5.6.2 - Unauthenticated Arbitrary File Read via Media Field\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 18:28:08","sources":[{"name":"Wordfence","remoteId":"1801fd3e-d56f-4540-9700-9e9de8b465e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1801fd3e-d56f-4540-9700-9e9de8b465e1?source=api-prod","cve":"CVE-2026-4373","affectedVersions":"<=3.5.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/af387cb8-583f-4bc6-9de7-fc03fd12d01a/jetformbuilder","title":"JetFormBuilder <= 3.5.1.2 - Authenticated (Administrator+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"af387cb8-583f-4bc6-9de7-fc03fd12d01a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af387cb8-583f-4bc6-9de7-fc03fd12d01a?source=api-prod","cve":"CVE-2025-53990","affectedVersions":"<=3.5.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/c08444ef-77bc-4e9d-8d94-04b90cc99ded/jetformbuilder","title":"JetFormBuilder <= 3.5.3 - Missing Authorization to Unauthenticated Form Generation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 18:47:07","sources":[{"name":"Wordfence","remoteId":"c08444ef-77bc-4e9d-8d94-04b90cc99ded"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c08444ef-77bc-4e9d-8d94-04b90cc99ded?source=api-prod","cve":"CVE-2025-11991","affectedVersions":"<=3.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/e9d58191-769c-4632-a086-4dbce9bfb6ad/jetformbuilder","title":"JetFormBuilder <= 3.0.8 - Authenticated (Author+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"e9d58191-769c-4632-a086-4dbce9bfb6ad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e9d58191-769c-4632-a086-4dbce9bfb6ad?source=api-prod","cve":"CVE-2023-37866","affectedVersions":"<=3.0.8","severity":"high"},{"advisoryId":"WPSECADV/WF/f0343861-a376-43ea-826e-277c2a5ea635/jetformbuilder","title":"JetFormBuilder <= 3.1.4 - Unauthenticated Content Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"f0343861-a376-43ea-826e-277c2a5ea635"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f0343861-a376-43ea-826e-277c2a5ea635?source=api-prod","cve":"CVE-2023-48763","affectedVersions":"<=3.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/f37c4b2c-6f41-46b5-8427-b1883b39322e/jetformbuilder","title":"JetFormBuilder <= 3.0.6 - Cross-Site Request Fogery via 'do_admin_action'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"f37c4b2c-6f41-46b5-8427-b1883b39322e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f37c4b2c-6f41-46b5-8427-b1883b39322e?source=api-prod","cve":"CVE-2023-33212","affectedVersions":"<=3.0.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/f52f1866-cd9d-4443-85c8-e0e7e50f3fbc/jetformbuilder","title":"JetFormBuilder <= 3.5.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"f52f1866-cd9d-4443-85c8-e0e7e50f3fbc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f52f1866-cd9d-4443-85c8-e0e7e50f3fbc?source=api-prod","cve":"CVE-2025-64384","affectedVersions":"<=3.5.3","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/04af8675-1b1e-4f17-9eaf-87b49d8702e4/jetformbuilder","title":"JetFormBuilder — Dynamic Blocks Form Builder <= 3.5.6.1 - Authenticated (Contributor+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"04af8675-1b1e-4f17-9eaf-87b49d8702e4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/04af8675-1b1e-4f17-9eaf-87b49d8702e4?source=api-prod","cve":"CVE-2026-32525","affectedVersions":"<=3.5.6.1","severity":"high"},{"advisoryId":"WPSECADV/WF/0d8ea1c2-7c6e-43b3-97ca-a06438d51d11/jetformbuilder","title":"JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d8ea1c2-7c6e-43b3-97ca-a06438d51d11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d8ea1c2-7c6e-43b3-97ca-a06438d51d11?source=api-prod","cve":"CVE-2024-7291","affectedVersions":"<=3.3.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/1801fd3e-d56f-4540-9700-9e9de8b465e1/jetformbuilder","title":"JetFormBuilder <= 3.5.6.2 - Unauthenticated Arbitrary File Read via Media Field\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 18:28:08","sources":[{"name":"Wordfence","remoteId":"1801fd3e-d56f-4540-9700-9e9de8b465e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1801fd3e-d56f-4540-9700-9e9de8b465e1?source=api-prod","cve":"CVE-2026-4373","affectedVersions":"<=3.5.6.2","severity":"high"},{"advisoryId":"WPSECADV/WF/af387cb8-583f-4bc6-9de7-fc03fd12d01a/jetformbuilder","title":"JetFormBuilder <= 3.5.1.2 - Authenticated (Administrator+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"af387cb8-583f-4bc6-9de7-fc03fd12d01a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af387cb8-583f-4bc6-9de7-fc03fd12d01a?source=api-prod","cve":"CVE-2025-53990","affectedVersions":"<=3.5.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/c08444ef-77bc-4e9d-8d94-04b90cc99ded/jetformbuilder","title":"JetFormBuilder <= 3.5.3 - Missing Authorization to Unauthenticated Form Generation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 18:47:07","sources":[{"name":"Wordfence","remoteId":"c08444ef-77bc-4e9d-8d94-04b90cc99ded"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c08444ef-77bc-4e9d-8d94-04b90cc99ded?source=api-prod","cve":"CVE-2025-11991","affectedVersions":"<=3.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/e9d58191-769c-4632-a086-4dbce9bfb6ad/jetformbuilder","title":"JetFormBuilder <= 3.0.8 - Authenticated (Author+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"e9d58191-769c-4632-a086-4dbce9bfb6ad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e9d58191-769c-4632-a086-4dbce9bfb6ad?source=api-prod","cve":"CVE-2023-37866","affectedVersions":"<=3.0.8","severity":"high"},{"advisoryId":"WPSECADV/WF/f0343861-a376-43ea-826e-277c2a5ea635/jetformbuilder","title":"JetFormBuilder <= 3.1.4 - Unauthenticated Content Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"f0343861-a376-43ea-826e-277c2a5ea635"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f0343861-a376-43ea-826e-277c2a5ea635?source=api-prod","cve":"CVE-2023-48763","affectedVersions":"<=3.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/f37c4b2c-6f41-46b5-8427-b1883b39322e/jetformbuilder","title":"JetFormBuilder <= 3.0.6 - Cross-Site Request Fogery via 'do_admin_action'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"f37c4b2c-6f41-46b5-8427-b1883b39322e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f37c4b2c-6f41-46b5-8427-b1883b39322e?source=api-prod","cve":"CVE-2023-33212","affectedVersions":"<=3.0.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/f52f1866-cd9d-4443-85c8-e0e7e50f3fbc/jetformbuilder","title":"JetFormBuilder <= 3.5.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"f52f1866-cd9d-4443-85c8-e0e7e50f3fbc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f52f1866-cd9d-4443-85c8-e0e7e50f3fbc?source=api-prod","cve":"CVE-2025-64384","affectedVersions":"<=3.5.3","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6a6f626963612d636f7265811c9dc5_gen.json b/internal/data/assets/plugin_6a6f626963612d636f7265811c9dc5_gen.json index 53ab1b89..d0e1fe8b 100644 --- a/internal/data/assets/plugin_6a6f626963612d636f7265811c9dc5_gen.json +++ b/internal/data/assets/plugin_6a6f626963612d636f7265811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/66f6cae3-d38e-4ca3-82c5-606eb4a80c30/jobica-core","title":"Jobica Core <= 1.4.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"66f6cae3-d38e-4ca3-82c5-606eb4a80c30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/66f6cae3-d38e-4ca3-82c5-606eb4a80c30?source=api-prod","cve":"CVE-2026-27049","affectedVersions":"<=1.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/6fd646c7-f1b5-4ae7-adee-1e427fc4cf0a/jobica-core","title":"Jobica Core <= 1.4.1 - Authenticated (Subscriber+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"6fd646c7-f1b5-4ae7-adee-1e427fc4cf0a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6fd646c7-f1b5-4ae7-adee-1e427fc4cf0a?source=api-prod","cve":"CVE-2026-24978","affectedVersions":"<=1.4.1","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/3fa63ac2-b063-40a1-beaf-a27f56688347/jobica-core","title":"Jobica Core <= 1.4.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"3fa63ac2-b063-40a1-beaf-a27f56688347"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3fa63ac2-b063-40a1-beaf-a27f56688347?source=api-prod","cve":"CVE-2026-24979","affectedVersions":"<=1.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/66f6cae3-d38e-4ca3-82c5-606eb4a80c30/jobica-core","title":"Jobica Core <= 1.4.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"66f6cae3-d38e-4ca3-82c5-606eb4a80c30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/66f6cae3-d38e-4ca3-82c5-606eb4a80c30?source=api-prod","cve":"CVE-2026-27049","affectedVersions":"<=1.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/6fd646c7-f1b5-4ae7-adee-1e427fc4cf0a/jobica-core","title":"Jobica Core <= 1.4.1 - Authenticated (Subscriber+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"6fd646c7-f1b5-4ae7-adee-1e427fc4cf0a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6fd646c7-f1b5-4ae7-adee-1e427fc4cf0a?source=api-prod","cve":"CVE-2026-24978","affectedVersions":"<=1.4.1","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6c617465706f696e74811c9dc5_gen.json b/internal/data/assets/plugin_6c617465706f696e74811c9dc5_gen.json index d124695e..73942752 100644 --- a/internal/data/assets/plugin_6c617465706f696e74811c9dc5_gen.json +++ b/internal/data/assets/plugin_6c617465706f696e74811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/1d641e9e-e690-48ff-a28b-f4068d372aab/latepoint","title":"LatePoint <= 4.9.91 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"1d641e9e-e690-48ff-a28b-f4068d372aab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1d641e9e-e690-48ff-a28b-f4068d372aab?source=api-prod","cve":"CVE-2024-43992","affectedVersions":"<=4.9.91","severity":"medium"},{"advisoryId":"WPSECADV/WF/1f7aa23c-ffa7-481b-8481-a36c7ed599d8/latepoint","title":"LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-13 18:24:03","sources":[{"name":"Wordfence","remoteId":"1f7aa23c-ffa7-481b-8481-a36c7ed599d8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1f7aa23c-ffa7-481b-8481-a36c7ed599d8?source=api-prod","cve":"CVE-2025-14873","affectedVersions":"<=5.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/22bcfd36-ecf9-4d2c-ac94-94ffa0340c4c/latepoint","title":"LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-02 18:30:30","sources":[{"name":"Wordfence","remoteId":"22bcfd36-ecf9-4d2c-ac94-94ffa0340c4c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/22bcfd36-ecf9-4d2c-ac94-94ffa0340c4c?source=api-prod","cve":"CVE-2026-0617","affectedVersions":"<=5.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/28e9c77c-5c36-4449-ab90-86f2385ba1ae/latepoint","title":"LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-29 16:24:39","sources":[{"name":"Wordfence","remoteId":"28e9c77c-5c36-4449-ab90-86f2385ba1ae"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/28e9c77c-5c36-4449-ab90-86f2385ba1ae?source=api-prod","cve":"CVE-2025-6815","affectedVersions":"<=5.1.94","severity":"medium"},{"advisoryId":"WPSECADV/WF/55c5c094-69c0-4e2a-be0c-fab6f1039309/latepoint","title":"LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-07 15:17:40","sources":[{"name":"Wordfence","remoteId":"55c5c094-69c0-4e2a-be0c-fab6f1039309"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/55c5c094-69c0-4e2a-be0c-fab6f1039309?source=api-prod","cve":"CVE-2026-4785","affectedVersions":"<=5.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/5c9a23a3-5eb5-4f5b-bf32-c9d163426f29/latepoint","title":"LatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"5c9a23a3-5eb5-4f5b-bf32-c9d163426f29"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5c9a23a3-5eb5-4f5b-bf32-c9d163426f29?source=api-prod","cve":"CVE-2024-8911","affectedVersions":"<=5.0.11","severity":"critical"},{"advisoryId":"WPSECADV/WF/6215fa9f-06bc-4dc8-b1f5-a3bb75749f1d/latepoint","title":"LatePoint Plugin <= 4.9.9 - Missing Authorization and Sensitive Information Exposure via IDOR\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-13 21:00:45","sources":[{"name":"Wordfence","remoteId":"6215fa9f-06bc-4dc8-b1f5-a3bb75749f1d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6215fa9f-06bc-4dc8-b1f5-a3bb75749f1d?source=api-prod","cve":"CVE-2024-2472","affectedVersions":"<=4.9.9","severity":"critical"},{"advisoryId":"WPSECADV/WF/71e99412-031e-4f4a-9126-dd3a37975246/latepoint","title":"LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-27 07:23:53","sources":[{"name":"Wordfence","remoteId":"71e99412-031e-4f4a-9126-dd3a37975246"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/71e99412-031e-4f4a-9126-dd3a37975246?source=api-prod","cve":"CVE-2026-6741","affectedVersions":"<=5.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/7e9acd26-c341-4ece-bcf1-102f953a4b4f/latepoint","title":"Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"7e9acd26-c341-4ece-bcf1-102f953a4b4f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7e9acd26-c341-4ece-bcf1-102f953a4b4f?source=api-prod","cve":"CVE-2025-3769","affectedVersions":"<=5.1.92","severity":"medium"},{"advisoryId":"WPSECADV/WF/9547c6e9-3dfc-442c-900d-111b1528aa5b/latepoint","title":"LatePoint <= 5.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"9547c6e9-3dfc-442c-900d-111b1528aa5b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9547c6e9-3dfc-442c-900d-111b1528aa5b?source=api-prod","cve":"CVE-2025-30836","affectedVersions":"<=5.1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/a76a6800-61ae-47e8-9659-47c08535516d/latepoint","title":"LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Authenticated (Subscriber+) Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"a76a6800-61ae-47e8-9659-47c08535516d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a76a6800-61ae-47e8-9659-47c08535516d?source=api-prod","cve":"CVE-2026-32533","affectedVersions":"<=5.2.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/afec4c8c-a18d-4907-8879-2412f8a1abed/latepoint","title":"LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-16 15:19:09","sources":[{"name":"Wordfence","remoteId":"afec4c8c-a18d-4907-8879-2412f8a1abed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/afec4c8c-a18d-4907-8879-2412f8a1abed?source=api-prod","cve":"CVE-2026-5234","affectedVersions":"<=5.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/b3ae93da-57ee-4966-83af-b8c57f9ad7d9/latepoint","title":"LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 11:29:15","sources":[{"name":"Wordfence","remoteId":"b3ae93da-57ee-4966-83af-b8c57f9ad7d9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b3ae93da-57ee-4966-83af-b8c57f9ad7d9?source=api-prod","cve":"CVE-2026-2324","affectedVersions":"<=5.2.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/bac8c35b-2afa-4347-b86e-2f16db19a4d3/latepoint","title":"LatePoint <= 5.0.12 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"bac8c35b-2afa-4347-b86e-2f16db19a4d3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bac8c35b-2afa-4347-b86e-2f16db19a4d3?source=api-prod","cve":"CVE-2024-8943","affectedVersions":"<=5.0.12","severity":"critical"},{"advisoryId":"WPSECADV/WF/bd240932-ad50-40b3-94c7-6e885f96c5df/latepoint","title":"LatePoint <= 4.9.91 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"bd240932-ad50-40b3-94c7-6e885f96c5df"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bd240932-ad50-40b3-94c7-6e885f96c5df?source=api-prod","cve":"CVE-2024-43945","affectedVersions":"<=4.9.91","severity":"medium"},{"advisoryId":"WPSECADV/WF/c05575ef-3140-4340-9b4b-1803a8045ce0/latepoint","title":"LatePoint <= 5.1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-29 16:24:40","sources":[{"name":"Wordfence","remoteId":"c05575ef-3140-4340-9b4b-1803a8045ce0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c05575ef-3140-4340-9b4b-1803a8045ce0?source=api-prod","cve":"CVE-2025-6941","affectedVersions":"<=5.1.94","severity":"medium"},{"advisoryId":"WPSECADV/WF/c18ad885-52a8-467b-83f2-aeb0c8be8be0/latepoint","title":"LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-11 13:37:48","sources":[{"name":"Wordfence","remoteId":"c18ad885-52a8-467b-83f2-aeb0c8be8be0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c18ad885-52a8-467b-83f2-aeb0c8be8be0?source=api-prod","cve":"CVE-2026-1537","affectedVersions":"<=5.2.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/c958880e-6068-4e7d-a780-1251f3ab9bf7/latepoint","title":"LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 11:03:51","sources":[{"name":"Wordfence","remoteId":"c958880e-6068-4e7d-a780-1251f3ab9bf7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c958880e-6068-4e7d-a780-1251f3ab9bf7?source=api-prod","cve":"CVE-2026-1566","affectedVersions":"<=5.2.7","severity":"high"},{"advisoryId":"WPSECADV/WF/ca2b6f6e-4cc0-40ae-8969-c82c5a231f41/latepoint","title":"LatePoint <= 5.1.93 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca2b6f6e-4cc0-40ae-8969-c82c5a231f41"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca2b6f6e-4cc0-40ae-8969-c82c5a231f41?source=api-prod","cve":"CVE-2025-6715","affectedVersions":"<=5.1.93","severity":"critical"},{"advisoryId":"WPSECADV/WF/d7389e17-a357-481a-8716-3a93cb6afa7c/latepoint","title":"LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-29 16:24:40","sources":[{"name":"Wordfence","remoteId":"d7389e17-a357-481a-8716-3a93cb6afa7c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d7389e17-a357-481a-8716-3a93cb6afa7c?source=api-prod","cve":"CVE-2025-7038","affectedVersions":"<=5.1.94","severity":"high"},{"advisoryId":"WPSECADV/WF/df8a8ce0-7258-40ae-bf73-f8c6185fdd16/latepoint","title":"LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-29 16:24:40","sources":[{"name":"Wordfence","remoteId":"df8a8ce0-7258-40ae-bf73-f8c6185fdd16"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/df8a8ce0-7258-40ae-bf73-f8c6185fdd16?source=api-prod","cve":"CVE-2025-7052","affectedVersions":"<=5.1.94","severity":"high"},{"advisoryId":"WPSECADV/WF/e1bbd339-5eb7-4a62-9c68-bcd76507425c/latepoint","title":"LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON Import\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 11:25:27","sources":[{"name":"Wordfence","remoteId":"e1bbd339-5eb7-4a62-9c68-bcd76507425c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e1bbd339-5eb7-4a62-9c68-bcd76507425c?source=api-prod","cve":"CVE-2026-1487","affectedVersions":"<=5.2.7","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/1d641e9e-e690-48ff-a28b-f4068d372aab/latepoint","title":"LatePoint <= 4.9.91 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"1d641e9e-e690-48ff-a28b-f4068d372aab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1d641e9e-e690-48ff-a28b-f4068d372aab?source=api-prod","cve":"CVE-2024-43992","affectedVersions":"<=4.9.91","severity":"medium"},{"advisoryId":"WPSECADV/WF/1f7aa23c-ffa7-481b-8481-a36c7ed599d8/latepoint","title":"LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-13 18:24:03","sources":[{"name":"Wordfence","remoteId":"1f7aa23c-ffa7-481b-8481-a36c7ed599d8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1f7aa23c-ffa7-481b-8481-a36c7ed599d8?source=api-prod","cve":"CVE-2025-14873","affectedVersions":"<=5.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/22bcfd36-ecf9-4d2c-ac94-94ffa0340c4c/latepoint","title":"LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-02 18:30:30","sources":[{"name":"Wordfence","remoteId":"22bcfd36-ecf9-4d2c-ac94-94ffa0340c4c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/22bcfd36-ecf9-4d2c-ac94-94ffa0340c4c?source=api-prod","cve":"CVE-2026-0617","affectedVersions":"<=5.2.5","severity":"high"},{"advisoryId":"WPSECADV/WF/28e9c77c-5c36-4449-ab90-86f2385ba1ae/latepoint","title":"LatePoint <= 5.1.94 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-29 16:24:39","sources":[{"name":"Wordfence","remoteId":"28e9c77c-5c36-4449-ab90-86f2385ba1ae"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/28e9c77c-5c36-4449-ab90-86f2385ba1ae?source=api-prod","cve":"CVE-2025-6815","affectedVersions":"<=5.1.94","severity":"medium"},{"advisoryId":"WPSECADV/WF/55c5c094-69c0-4e2a-be0c-fab6f1039309/latepoint","title":"LatePoint <= 5.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-07 15:17:40","sources":[{"name":"Wordfence","remoteId":"55c5c094-69c0-4e2a-be0c-fab6f1039309"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/55c5c094-69c0-4e2a-be0c-fab6f1039309?source=api-prod","cve":"CVE-2026-4785","affectedVersions":"<=5.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/5c9a23a3-5eb5-4f5b-bf32-c9d163426f29/latepoint","title":"LatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"5c9a23a3-5eb5-4f5b-bf32-c9d163426f29"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5c9a23a3-5eb5-4f5b-bf32-c9d163426f29?source=api-prod","cve":"CVE-2024-8911","affectedVersions":"<=5.0.11","severity":"critical"},{"advisoryId":"WPSECADV/WF/6215fa9f-06bc-4dc8-b1f5-a3bb75749f1d/latepoint","title":"LatePoint Plugin <= 4.9.9 - Missing Authorization and Sensitive Information Exposure via IDOR\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-13 21:00:45","sources":[{"name":"Wordfence","remoteId":"6215fa9f-06bc-4dc8-b1f5-a3bb75749f1d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6215fa9f-06bc-4dc8-b1f5-a3bb75749f1d?source=api-prod","cve":"CVE-2024-2472","affectedVersions":"<=4.9.9","severity":"critical"},{"advisoryId":"WPSECADV/WF/628b3f53-decd-47ac-a2d1-339ade1e6944/latepoint","title":"LatePoint <= 5.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Customer Cabinet Profile Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-05 18:29:59","sources":[{"name":"Wordfence","remoteId":"628b3f53-decd-47ac-a2d1-339ade1e6944"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/628b3f53-decd-47ac-a2d1-339ade1e6944?source=api-prod","cve":"CVE-2026-7457","affectedVersions":"<=5.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/71e99412-031e-4f4a-9126-dd3a37975246/latepoint","title":"LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-27 07:23:53","sources":[{"name":"Wordfence","remoteId":"71e99412-031e-4f4a-9126-dd3a37975246"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/71e99412-031e-4f4a-9126-dd3a37975246?source=api-prod","cve":"CVE-2026-6741","affectedVersions":"<=5.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/7e9acd26-c341-4ece-bcf1-102f953a4b4f/latepoint","title":"Latepoint <= 5.1.92 - Unauthenticated Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"7e9acd26-c341-4ece-bcf1-102f953a4b4f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7e9acd26-c341-4ece-bcf1-102f953a4b4f?source=api-prod","cve":"CVE-2025-3769","affectedVersions":"<=5.1.92","severity":"medium"},{"advisoryId":"WPSECADV/WF/9547c6e9-3dfc-442c-900d-111b1528aa5b/latepoint","title":"LatePoint <= 5.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"9547c6e9-3dfc-442c-900d-111b1528aa5b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9547c6e9-3dfc-442c-900d-111b1528aa5b?source=api-prod","cve":"CVE-2025-30836","affectedVersions":"<=5.1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/a76a6800-61ae-47e8-9659-47c08535516d/latepoint","title":"LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Authenticated (Subscriber+) Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"a76a6800-61ae-47e8-9659-47c08535516d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a76a6800-61ae-47e8-9659-47c08535516d?source=api-prod","cve":"CVE-2026-32533","affectedVersions":"<=5.2.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/afec4c8c-a18d-4907-8879-2412f8a1abed/latepoint","title":"LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-16 15:19:09","sources":[{"name":"Wordfence","remoteId":"afec4c8c-a18d-4907-8879-2412f8a1abed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/afec4c8c-a18d-4907-8879-2412f8a1abed?source=api-prod","cve":"CVE-2026-5234","affectedVersions":"<=5.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/b3ae93da-57ee-4966-83af-b8c57f9ad7d9/latepoint","title":"LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 11:29:15","sources":[{"name":"Wordfence","remoteId":"b3ae93da-57ee-4966-83af-b8c57f9ad7d9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b3ae93da-57ee-4966-83af-b8c57f9ad7d9?source=api-prod","cve":"CVE-2026-2324","affectedVersions":"<=5.2.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/bac8c35b-2afa-4347-b86e-2f16db19a4d3/latepoint","title":"LatePoint <= 5.0.12 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"bac8c35b-2afa-4347-b86e-2f16db19a4d3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bac8c35b-2afa-4347-b86e-2f16db19a4d3?source=api-prod","cve":"CVE-2024-8943","affectedVersions":"<=5.0.12","severity":"critical"},{"advisoryId":"WPSECADV/WF/bd240932-ad50-40b3-94c7-6e885f96c5df/latepoint","title":"LatePoint <= 4.9.91 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"bd240932-ad50-40b3-94c7-6e885f96c5df"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bd240932-ad50-40b3-94c7-6e885f96c5df?source=api-prod","cve":"CVE-2024-43945","affectedVersions":"<=4.9.91","severity":"medium"},{"advisoryId":"WPSECADV/WF/c03ddcf0-6955-4645-b311-c3833ca61455/latepoint","title":"LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-05 18:41:45","sources":[{"name":"Wordfence","remoteId":"c03ddcf0-6955-4645-b311-c3833ca61455"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c03ddcf0-6955-4645-b311-c3833ca61455?source=api-prod","cve":"CVE-2026-7332","affectedVersions":"<=5.5.0","severity":"high"},{"advisoryId":"WPSECADV/WF/c05575ef-3140-4340-9b4b-1803a8045ce0/latepoint","title":"LatePoint <= 5.1.94 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-29 16:24:40","sources":[{"name":"Wordfence","remoteId":"c05575ef-3140-4340-9b4b-1803a8045ce0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c05575ef-3140-4340-9b4b-1803a8045ce0?source=api-prod","cve":"CVE-2025-6941","affectedVersions":"<=5.1.94","severity":"medium"},{"advisoryId":"WPSECADV/WF/c18ad885-52a8-467b-83f2-aeb0c8be8be0/latepoint","title":"LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to Booking Details Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-11 13:37:48","sources":[{"name":"Wordfence","remoteId":"c18ad885-52a8-467b-83f2-aeb0c8be8be0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c18ad885-52a8-467b-83f2-aeb0c8be8be0?source=api-prod","cve":"CVE-2026-1537","affectedVersions":"<=5.2.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8eedec9-d8d4-4052-baec-29f83ac306ac/latepoint","title":"LatePoint <= 5.5.0 - Unauthenticated Stored Cross-Site Scripting via 'first_name' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-05 18:19:16","sources":[{"name":"Wordfence","remoteId":"c8eedec9-d8d4-4052-baec-29f83ac306ac"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8eedec9-d8d4-4052-baec-29f83ac306ac?source=api-prod","cve":"CVE-2026-7448","affectedVersions":"<=5.5.0","severity":"high"},{"advisoryId":"WPSECADV/WF/c958880e-6068-4e7d-a780-1251f3ab9bf7/latepoint","title":"LatePoint <= 5.2.7 - Authenticated (Agent+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 11:03:51","sources":[{"name":"Wordfence","remoteId":"c958880e-6068-4e7d-a780-1251f3ab9bf7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c958880e-6068-4e7d-a780-1251f3ab9bf7?source=api-prod","cve":"CVE-2026-1566","affectedVersions":"<=5.2.7","severity":"high"},{"advisoryId":"WPSECADV/WF/ca2b6f6e-4cc0-40ae-8969-c82c5a231f41/latepoint","title":"LatePoint <= 5.1.93 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca2b6f6e-4cc0-40ae-8969-c82c5a231f41"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca2b6f6e-4cc0-40ae-8969-c82c5a231f41?source=api-prod","cve":"CVE-2025-6715","affectedVersions":"<=5.1.93","severity":"critical"},{"advisoryId":"WPSECADV/WF/d7389e17-a357-481a-8716-3a93cb6afa7c/latepoint","title":"LatePoint <= 5.1.94 - Unauthenticated Authentication Bypass via load_step Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-29 16:24:40","sources":[{"name":"Wordfence","remoteId":"d7389e17-a357-481a-8716-3a93cb6afa7c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d7389e17-a357-481a-8716-3a93cb6afa7c?source=api-prod","cve":"CVE-2025-7038","affectedVersions":"<=5.1.94","severity":"high"},{"advisoryId":"WPSECADV/WF/df8a8ce0-7258-40ae-bf73-f8c6185fdd16/latepoint","title":"LatePoint <= 5.1.94 - Cross-Site Request Forgery to Account Takeover via change_password() Function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-29 16:24:40","sources":[{"name":"Wordfence","remoteId":"df8a8ce0-7258-40ae-bf73-f8c6185fdd16"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/df8a8ce0-7258-40ae-bf73-f8c6185fdd16?source=api-prod","cve":"CVE-2025-7052","affectedVersions":"<=5.1.94","severity":"high"},{"advisoryId":"WPSECADV/WF/e1bbd339-5eb7-4a62-9c68-bcd76507425c/latepoint","title":"LatePoint <= 5.2.7 - Authenticated (Administrator+) SQL Injection via JSON Import\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 11:25:27","sources":[{"name":"Wordfence","remoteId":"e1bbd339-5eb7-4a62-9c68-bcd76507425c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e1bbd339-5eb7-4a62-9c68-bcd76507425c?source=api-prod","cve":"CVE-2026-1487","affectedVersions":"<=5.2.7","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6d6167652d6576656e747072657373811c9dc5_gen.json b/internal/data/assets/plugin_6d6167652d6576656e747072657373811c9dc5_gen.json index 815e8df5..3523c2dc 100644 --- a/internal/data/assets/plugin_6d6167652d6576656e747072657373811c9dc5_gen.json +++ b/internal/data/assets/plugin_6d6167652d6576656e747072657373811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/05fe7d6d-c206-4444-aab2-e4f64b143710/mage-eventpress","title":"WpEvently <= 5.0.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"05fe7d6d-c206-4444-aab2-e4f64b143710"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/05fe7d6d-c206-4444-aab2-e4f64b143710?source=api-prod","cve":"CVE-2025-66083","affectedVersions":"<=5.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/1471bd32-4b91-4351-957f-e0a497d471ec/mage-eventpress","title":"WpEvently <= 4.2.9 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"1471bd32-4b91-4351-957f-e0a497d471ec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1471bd32-4b91-4351-957f-e0a497d471ec?source=api-prod","cve":"CVE-2025-30895","affectedVersions":"<=4.2.9","severity":"high"},{"advisoryId":"WPSECADV/WF/2c66905d-6e53-4062-b63f-b9a249ebd3e1/mage-eventpress","title":"WpEvently <= 4.2.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"2c66905d-6e53-4062-b63f-b9a249ebd3e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2c66905d-6e53-4062-b63f-b9a249ebd3e1?source=api-prod","cve":"CVE-2025-30887","affectedVersions":"<=4.2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/2dbaf8a7-e3cc-42c1-9f8b-7eb14363cf8c/mage-eventpress","title":"WpEvently <= 5.1.1 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"2dbaf8a7-e3cc-42c1-9f8b-7eb14363cf8c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2dbaf8a7-e3cc-42c1-9f8b-7eb14363cf8c?source=api-prod","cve":"CVE-2026-23549","affectedVersions":"<=5.1.1","severity":"high"},{"advisoryId":"WPSECADV/WF/376c5091-7921-4470-acbf-44db53db38fc/mage-eventpress","title":"Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"376c5091-7921-4470-acbf-44db53db38fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/376c5091-7921-4470-acbf-44db53db38fc?source=api-prod","cve":"CVE-2024-32110","affectedVersions":"<=4.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/38db25f7-e2d4-460a-9305-cf952d4b4991/mage-eventpress","title":"Event Booking Manager for WooCommerce <= 5.1.4 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"38db25f7-e2d4-460a-9305-cf952d4b4991"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/38db25f7-e2d4-460a-9305-cf952d4b4991?source=api-prod","cve":"CVE-2026-25361","affectedVersions":"<=5.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/50812a8b-7d49-41fa-ba50-47d07a4b6caa/mage-eventpress","title":"Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently <= 4.1.1 - Authenticated (Contributor+) PHP Object Injection in mep_event_meta_save\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"50812a8b-7d49-41fa-ba50-47d07a4b6caa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/50812a8b-7d49-41fa-ba50-47d07a4b6caa?source=api-prod","cve":"CVE-2024-24796","affectedVersions":"<=4.1.1","severity":"high"},{"advisoryId":"WPSECADV/WF/6bd03b86-e9b7-44d5-9528-efd94f0f79f5/mage-eventpress","title":"Event Manager for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"6bd03b86-e9b7-44d5-9528-efd94f0f79f5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6bd03b86-e9b7-44d5-9528-efd94f0f79f5?source=api-prod","cve":"CVE-2024-43138","affectedVersions":"<=4.2.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/8f9cf8d3-ebc1-4d94-909e-938beb58601e/mage-eventpress","title":"WpEvently <= 4.4.8 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"8f9cf8d3-ebc1-4d94-909e-938beb58601e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8f9cf8d3-ebc1-4d94-909e-938beb58601e?source=api-prod","cve":"CVE-2025-54742","affectedVersions":"<=4.4.8","severity":"high"},{"advisoryId":"WPSECADV/WF/9379e1c9-fb83-43e4-af89-898dc0c2216c/mage-eventpress","title":"Event Manager and Tickets Selling Plugin for WooCommerce <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"9379e1c9-fb83-43e4-af89-898dc0c2216c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9379e1c9-fb83-43e4-af89-898dc0c2216c?source=api-prod","cve":"CVE-2023-0144","affectedVersions":"<=3.7.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/9601932a-0e0d-408f-91d0-47ff4e726b23/mage-eventpress","title":"WpEvently <= 4.4.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"9601932a-0e0d-408f-91d0-47ff4e726b23"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9601932a-0e0d-408f-91d0-47ff4e726b23?source=api-prod","cve":"CVE-2025-54705","affectedVersions":"<=4.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/a3659c4d-3a19-4f74-9f6d-26d7b24ebe56/mage-eventpress","title":"WpEvently <= 4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-06 21:50:06","sources":[{"name":"Wordfence","remoteId":"a3659c4d-3a19-4f74-9f6d-26d7b24ebe56"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a3659c4d-3a19-4f74-9f6d-26d7b24ebe56?source=api-prod","cve":"CVE-2025-5568","affectedVersions":"<=4.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/a7689a95-7f63-46e1-b5fd-4279be66e0f0/mage-eventpress","title":"WpEvently <= 5.0.8 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"a7689a95-7f63-46e1-b5fd-4279be66e0f0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a7689a95-7f63-46e1-b5fd-4279be66e0f0?source=api-prod","cve":"CVE-2026-24954","affectedVersions":"<=5.0.8","severity":"high"},{"advisoryId":"WPSECADV/WF/af59eb6d-1ffa-4593-9bfc-f910d907f6e0/mage-eventpress","title":"Event Manager for WooCommerce <= 3.7.7 - Cross-Site Request Forgery leading to Uninstall Form Submission\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"af59eb6d-1ffa-4593-9bfc-f910d907f6e0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af59eb6d-1ffa-4593-9bfc-f910d907f6e0?source=api-prod","cve":"CVE-2022-47164","affectedVersions":"<=3.7.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/bfc8c34c-3a1d-486e-96ca-ff50a1148813/mage-eventpress","title":"Event Manager for WooCommerce <= 4.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"bfc8c34c-3a1d-486e-96ca-ff50a1148813"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bfc8c34c-3a1d-486e-96ca-ff50a1148813?source=api-prod","cve":"CVE-2024-49703","affectedVersions":"<=4.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/c2f4c1de-7eeb-45c4-bbff-ec85f2cda5aa/mage-eventpress","title":"Event Manager for WooCommerce <= 3.8.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'mep_get_option' function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"c2f4c1de-7eeb-45c4-bbff-ec85f2cda5aa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c2f4c1de-7eeb-45c4-bbff-ec85f2cda5aa?source=api-prod","cve":"CVE-2023-28422","affectedVersions":"<=3.8.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/c4cd477c-29c5-4715-bffb-55754858f9fc/mage-eventpress","title":"WpEvently <= 4.3.6 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"c4cd477c-29c5-4715-bffb-55754858f9fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c4cd477c-29c5-4715-bffb-55754858f9fc?source=api-prod","cve":"CVE-2025-32145","affectedVersions":"<=4.3.6","severity":"high"},{"advisoryId":"WPSECADV/WF/c63079af-6a22-4692-ab81-96e166a00c38/mage-eventpress","title":"Event Manager and Tickets Selling Plugin for WooCommerce < 3.5.3 - Arbitrary Settings Change\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"c63079af-6a22-4692-ab81-96e166a00c38"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c63079af-6a22-4692-ab81-96e166a00c38?source=api-prod","affectedVersions":"<3.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/e7b719b9-7287-4d2a-b107-7c9bc18b9456/mage-eventpress","title":"WpEvently <= 5.0.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7b719b9-7287-4d2a-b107-7c9bc18b9456"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7b719b9-7287-4d2a-b107-7c9bc18b9456?source=api-prod","cve":"CVE-2025-66082","affectedVersions":"<=5.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/e93ccf9d-cd8b-4399-8d2d-c844a23d66c8/mage-eventpress","title":"Event Manager and Tickets Selling for WooCommerce < 3.5.8 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"e93ccf9d-cd8b-4399-8d2d-c844a23d66c8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e93ccf9d-cd8b-4399-8d2d-c844a23d66c8?source=api-prod","cve":"CVE-2022-0478","affectedVersions":"<3.5.8","severity":"high"},{"advisoryId":"WPSECADV/WF/ef7ef45a-612b-40ca-817d-05b3d29b2b05/mage-eventpress","title":"Event Manager and Tickets Selling Plugin for WooCommerce < 3.5.3 - Missing Authorization\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"ef7ef45a-612b-40ca-817d-05b3d29b2b05"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ef7ef45a-612b-40ca-817d-05b3d29b2b05?source=api-prod","affectedVersions":"<3.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/f20d9160-bddf-4fdb-a5a6-cc792bb1c1ee/mage-eventpress","title":"WpEvently <= 5.1.1 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"f20d9160-bddf-4fdb-a5a6-cc792bb1c1ee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f20d9160-bddf-4fdb-a5a6-cc792bb1c1ee?source=api-prod","cve":"CVE-2026-24942","affectedVersions":"<=5.1.1","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/05fe7d6d-c206-4444-aab2-e4f64b143710/mage-eventpress","title":"WpEvently <= 5.0.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"05fe7d6d-c206-4444-aab2-e4f64b143710"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/05fe7d6d-c206-4444-aab2-e4f64b143710?source=api-prod","cve":"CVE-2025-66083","affectedVersions":"<=5.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/1471bd32-4b91-4351-957f-e0a497d471ec/mage-eventpress","title":"WpEvently <= 4.2.9 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"1471bd32-4b91-4351-957f-e0a497d471ec"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1471bd32-4b91-4351-957f-e0a497d471ec?source=api-prod","cve":"CVE-2025-30895","affectedVersions":"<=4.2.9","severity":"high"},{"advisoryId":"WPSECADV/WF/2c66905d-6e53-4062-b63f-b9a249ebd3e1/mage-eventpress","title":"WpEvently <= 4.2.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"2c66905d-6e53-4062-b63f-b9a249ebd3e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2c66905d-6e53-4062-b63f-b9a249ebd3e1?source=api-prod","cve":"CVE-2025-30887","affectedVersions":"<=4.2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/2dbaf8a7-e3cc-42c1-9f8b-7eb14363cf8c/mage-eventpress","title":"WpEvently <= 5.1.1 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"2dbaf8a7-e3cc-42c1-9f8b-7eb14363cf8c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2dbaf8a7-e3cc-42c1-9f8b-7eb14363cf8c?source=api-prod","cve":"CVE-2026-23549","affectedVersions":"<=5.1.1","severity":"high"},{"advisoryId":"WPSECADV/WF/376c5091-7921-4470-acbf-44db53db38fc/mage-eventpress","title":"Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"376c5091-7921-4470-acbf-44db53db38fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/376c5091-7921-4470-acbf-44db53db38fc?source=api-prod","cve":"CVE-2024-32110","affectedVersions":"<=4.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/38db25f7-e2d4-460a-9305-cf952d4b4991/mage-eventpress","title":"Event Booking Manager for WooCommerce <= 5.1.4 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"38db25f7-e2d4-460a-9305-cf952d4b4991"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/38db25f7-e2d4-460a-9305-cf952d4b4991?source=api-prod","cve":"CVE-2026-25361","affectedVersions":"<=5.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/50812a8b-7d49-41fa-ba50-47d07a4b6caa/mage-eventpress","title":"Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently <= 4.1.1 - Authenticated (Contributor+) PHP Object Injection in mep_event_meta_save\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"50812a8b-7d49-41fa-ba50-47d07a4b6caa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/50812a8b-7d49-41fa-ba50-47d07a4b6caa?source=api-prod","cve":"CVE-2024-24796","affectedVersions":"<=4.1.1","severity":"high"},{"advisoryId":"WPSECADV/WF/6bd03b86-e9b7-44d5-9528-efd94f0f79f5/mage-eventpress","title":"Event Manager for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"6bd03b86-e9b7-44d5-9528-efd94f0f79f5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6bd03b86-e9b7-44d5-9528-efd94f0f79f5?source=api-prod","cve":"CVE-2024-43138","affectedVersions":"<=4.2.1","severity":"critical"},{"advisoryId":"WPSECADV/WF/738d266b-4bd4-4c0e-aac4-ef0ffeb33c45/mage-eventpress","title":"WpEvently < 5.1.9 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"738d266b-4bd4-4c0e-aac4-ef0ffeb33c45"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/738d266b-4bd4-4c0e-aac4-ef0ffeb33c45?source=api-prod","cve":"CVE-2026-32354","affectedVersions":"<5.1.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/8f9cf8d3-ebc1-4d94-909e-938beb58601e/mage-eventpress","title":"WpEvently <= 4.4.8 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"8f9cf8d3-ebc1-4d94-909e-938beb58601e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8f9cf8d3-ebc1-4d94-909e-938beb58601e?source=api-prod","cve":"CVE-2025-54742","affectedVersions":"<=4.4.8","severity":"high"},{"advisoryId":"WPSECADV/WF/9379e1c9-fb83-43e4-af89-898dc0c2216c/mage-eventpress","title":"Event Manager and Tickets Selling Plugin for WooCommerce <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"9379e1c9-fb83-43e4-af89-898dc0c2216c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9379e1c9-fb83-43e4-af89-898dc0c2216c?source=api-prod","cve":"CVE-2023-0144","affectedVersions":"<=3.7.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/9601932a-0e0d-408f-91d0-47ff4e726b23/mage-eventpress","title":"WpEvently <= 4.4.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"9601932a-0e0d-408f-91d0-47ff4e726b23"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9601932a-0e0d-408f-91d0-47ff4e726b23?source=api-prod","cve":"CVE-2025-54705","affectedVersions":"<=4.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/a3659c4d-3a19-4f74-9f6d-26d7b24ebe56/mage-eventpress","title":"WpEvently <= 4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-06 21:50:06","sources":[{"name":"Wordfence","remoteId":"a3659c4d-3a19-4f74-9f6d-26d7b24ebe56"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a3659c4d-3a19-4f74-9f6d-26d7b24ebe56?source=api-prod","cve":"CVE-2025-5568","affectedVersions":"<=4.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/a7689a95-7f63-46e1-b5fd-4279be66e0f0/mage-eventpress","title":"WpEvently <= 5.0.8 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"a7689a95-7f63-46e1-b5fd-4279be66e0f0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a7689a95-7f63-46e1-b5fd-4279be66e0f0?source=api-prod","cve":"CVE-2026-24954","affectedVersions":"<=5.0.8","severity":"high"},{"advisoryId":"WPSECADV/WF/af59eb6d-1ffa-4593-9bfc-f910d907f6e0/mage-eventpress","title":"Event Manager for WooCommerce <= 3.7.7 - Cross-Site Request Forgery leading to Uninstall Form Submission\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"af59eb6d-1ffa-4593-9bfc-f910d907f6e0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af59eb6d-1ffa-4593-9bfc-f910d907f6e0?source=api-prod","cve":"CVE-2022-47164","affectedVersions":"<=3.7.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/bfc8c34c-3a1d-486e-96ca-ff50a1148813/mage-eventpress","title":"Event Manager for WooCommerce <= 4.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"bfc8c34c-3a1d-486e-96ca-ff50a1148813"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bfc8c34c-3a1d-486e-96ca-ff50a1148813?source=api-prod","cve":"CVE-2024-49703","affectedVersions":"<=4.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/c2f4c1de-7eeb-45c4-bbff-ec85f2cda5aa/mage-eventpress","title":"Event Manager for WooCommerce <= 3.8.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'mep_get_option' function\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"c2f4c1de-7eeb-45c4-bbff-ec85f2cda5aa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c2f4c1de-7eeb-45c4-bbff-ec85f2cda5aa?source=api-prod","cve":"CVE-2023-28422","affectedVersions":"<=3.8.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/c4cd477c-29c5-4715-bffb-55754858f9fc/mage-eventpress","title":"WpEvently <= 4.3.6 - Authenticated (Contributor+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"c4cd477c-29c5-4715-bffb-55754858f9fc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c4cd477c-29c5-4715-bffb-55754858f9fc?source=api-prod","cve":"CVE-2025-32145","affectedVersions":"<=4.3.6","severity":"high"},{"advisoryId":"WPSECADV/WF/c63079af-6a22-4692-ab81-96e166a00c38/mage-eventpress","title":"Event Manager and Tickets Selling Plugin for WooCommerce < 3.5.3 - Arbitrary Settings Change\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"c63079af-6a22-4692-ab81-96e166a00c38"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c63079af-6a22-4692-ab81-96e166a00c38?source=api-prod","affectedVersions":"<3.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/e7b719b9-7287-4d2a-b107-7c9bc18b9456/mage-eventpress","title":"WpEvently <= 5.0.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7b719b9-7287-4d2a-b107-7c9bc18b9456"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7b719b9-7287-4d2a-b107-7c9bc18b9456?source=api-prod","cve":"CVE-2025-66082","affectedVersions":"<=5.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/e93ccf9d-cd8b-4399-8d2d-c844a23d66c8/mage-eventpress","title":"Event Manager and Tickets Selling for WooCommerce < 3.5.8 - SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"e93ccf9d-cd8b-4399-8d2d-c844a23d66c8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e93ccf9d-cd8b-4399-8d2d-c844a23d66c8?source=api-prod","cve":"CVE-2022-0478","affectedVersions":"<3.5.8","severity":"high"},{"advisoryId":"WPSECADV/WF/ef7ef45a-612b-40ca-817d-05b3d29b2b05/mage-eventpress","title":"Event Manager and Tickets Selling Plugin for WooCommerce < 3.5.3 - Missing Authorization\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-11-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"ef7ef45a-612b-40ca-817d-05b3d29b2b05"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ef7ef45a-612b-40ca-817d-05b3d29b2b05?source=api-prod","affectedVersions":"<3.5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/f20d9160-bddf-4fdb-a5a6-cc792bb1c1ee/mage-eventpress","title":"WpEvently <= 5.1.1 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"f20d9160-bddf-4fdb-a5a6-cc792bb1c1ee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f20d9160-bddf-4fdb-a5a6-cc792bb1c1ee?source=api-prod","cve":"CVE-2026-24942","affectedVersions":"<=5.1.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6d61696c65727072657373811c9dc5_gen.json b/internal/data/assets/plugin_6d61696c65727072657373811c9dc5_gen.json new file mode 100644 index 00000000..4d60ea30 --- /dev/null +++ b/internal/data/assets/plugin_6d61696c65727072657373811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/c6f8f178-47a4-4bca-b8a2-e8f148c24e1b/mailerpress","title":"MailerPress <= 1.4.2 - Authenticated (Contributor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"c6f8f178-47a4-4bca-b8a2-e8f148c24e1b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c6f8f178-47a4-4bca-b8a2-e8f148c24e1b?source=api-prod","cve":"CVE-2026-32353","affectedVersions":"<=1.4.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6d6564696c617a61722d636f7265811c9dc5_gen.json b/internal/data/assets/plugin_6d6564696c617a61722d636f7265811c9dc5_gen.json new file mode 100644 index 00000000..03fe06e1 --- /dev/null +++ b/internal/data/assets/plugin_6d6564696c617a61722d636f7265811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/2affce7c-6c59-4a50-ab26-5da2e18120d7/medilazar-core","title":"Medilazar Core < 1.4.7 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"2affce7c-6c59-4a50-ab26-5da2e18120d7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2affce7c-6c59-4a50-ab26-5da2e18120d7?source=api-prod","cve":"CVE-2026-32426","affectedVersions":"<1.4.7","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6d6564696c696e6b2d636f7265811c9dc5_gen.json b/internal/data/assets/plugin_6d6564696c696e6b2d636f7265811c9dc5_gen.json new file mode 100644 index 00000000..56f71014 --- /dev/null +++ b/internal/data/assets/plugin_6d6564696c696e6b2d636f7265811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/c7fdd481-57f0-4fa8-8434-868ef6341fd2/medilink-core","title":"Medilink-Core < 2.0.7 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"c7fdd481-57f0-4fa8-8434-868ef6341fd2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c7fdd481-57f0-4fa8-8434-868ef6341fd2?source=api-prod","cve":"CVE-2026-32369","affectedVersions":"<2.0.7","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6d6f64616c2d6469616c6f67811c9dc5_gen.json b/internal/data/assets/plugin_6d6f64616c2d6469616c6f67811c9dc5_gen.json index aac663d2..d0aa3a60 100644 --- a/internal/data/assets/plugin_6d6f64616c2d6469616c6f67811c9dc5_gen.json +++ b/internal/data/assets/plugin_6d6f64616c2d6469616c6f67811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/99140d47-88bb-48a1-863a-93a558541800/modal-dialog","title":"Modal Dialog <= 3.5.14 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"99140d47-88bb-48a1-863a-93a558541800"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/99140d47-88bb-48a1-863a-93a558541800?source=api-prod","cve":"CVE-2023-31071","affectedVersions":"<3.5.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/d5f82abe-64bb-4539-8fe7-261fad60cfa9/modal-dialog","title":"Modal Dialog <= 3.5.9 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"d5f82abe-64bb-4539-8fe7-261fad60cfa9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d5f82abe-64bb-4539-8fe7-261fad60cfa9?source=api-prod","cve":"CVE-2023-24001","affectedVersions":"<=3.5.9","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/99140d47-88bb-48a1-863a-93a558541800/modal-dialog","title":"Modal Dialog <= 3.5.14 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"99140d47-88bb-48a1-863a-93a558541800"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/99140d47-88bb-48a1-863a-93a558541800?source=api-prod","cve":"CVE-2023-31071","affectedVersions":"<3.5.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/aa8daa65-dc64-4cbf-9b49-2db08b64b02e/modal-dialog","title":"Modal Dialog <= 3.5.16 - Authenticated (Admin+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"aa8daa65-dc64-4cbf-9b49-2db08b64b02e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa8daa65-dc64-4cbf-9b49-2db08b64b02e?source=api-prod","cve":"CVE-2026-32367","affectedVersions":"<=3.5.16","severity":"high"},{"advisoryId":"WPSECADV/WF/d5f82abe-64bb-4539-8fe7-261fad60cfa9/modal-dialog","title":"Modal Dialog <= 3.5.9 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"d5f82abe-64bb-4539-8fe7-261fad60cfa9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d5f82abe-64bb-4539-8fe7-261fad60cfa9?source=api-prod","cve":"CVE-2023-24001","affectedVersions":"<=3.5.9","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6d70332d6d757369632d706c617965722d62792d736f6e616172811c9dc5_gen.json b/internal/data/assets/plugin_6d70332d6d757369632d706c617965722d62792d736f6e616172811c9dc5_gen.json index 0aa9964c..ada13412 100644 --- a/internal/data/assets/plugin_6d70332d6d757369632d706c617965722d62792d736f6e616172811c9dc5_gen.json +++ b/internal/data/assets/plugin_6d70332d6d757369632d706c617965722d62792d736f6e616172811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/261aad1e-43fc-4927-a97d-85a001863023/mp3-music-player-by-sonaar","title":"MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 5.3 - 5.10 - Authenticated (Author+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-13 20:09:32","sources":[{"name":"Wordfence","remoteId":"261aad1e-43fc-4927-a97d-85a001863023"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/261aad1e-43fc-4927-a97d-85a001863023?source=api-prod","cve":"CVE-2026-1249","affectedVersions":">=5.3,<=5.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/43adc9dd-1780-440f-90c2-ff05a22eb084/mp3-music-player-by-sonaar","title":"MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.7.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"43adc9dd-1780-440f-90c2-ff05a22eb084"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/43adc9dd-1780-440f-90c2-ff05a22eb084?source=api-prod","cve":"CVE-2024-7856","affectedVersions":"<=5.7.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/547325ad-0b01-42d5-b47c-362044587395/mp3-music-player-by-sonaar","title":"MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Podcast RSS Feed\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-30 19:24:55","sources":[{"name":"Wordfence","remoteId":"547325ad-0b01-42d5-b47c-362044587395"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/547325ad-0b01-42d5-b47c-362044587395?source=api-prod","cve":"CVE-2024-13157","affectedVersions":"<=5.9.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/5e722b30-f136-4f57-a248-cf9cdd499552/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"5e722b30-f136-4f57-a248-cf9cdd499552"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5e722b30-f136-4f57-a248-cf9cdd499552?source=api-prod","cve":"CVE-2024-30487","affectedVersions":"<=5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/6bcb9d95-acb4-4405-b785-1e5eace10dc9/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10 - Missing Authorization to Template Import\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"6bcb9d95-acb4-4405-b785-1e5eace10dc9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6bcb9d95-acb4-4405-b785-1e5eace10dc9?source=api-prod","cve":"CVE-2023-47822","affectedVersions":"<=4.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/7ec14923-0f68-45e8-8d99-9921c5928ac4/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.9.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"7ec14923-0f68-45e8-8d99-9921c5928ac4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7ec14923-0f68-45e8-8d99-9921c5928ac4?source=api-prod","cve":"CVE-2025-32235","affectedVersions":"<=5.9.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/861d0218-0f0f-4299-a0ff-854832348457/mp3-music-player-by-sonaar","title":"MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-18 18:57:36","sources":[{"name":"Wordfence","remoteId":"861d0218-0f0f-4299-a0ff-854832348457"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/861d0218-0f0f-4299-a0ff-854832348457?source=api-prod","cve":"CVE-2024-10268","affectedVersions":"<=5.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/9576408b-d048-4e36-bc1a-c01c9f586365/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10.1 - Unauthenticated Arbitrary File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"9576408b-d048-4e36-bc1a-c01c9f586365"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9576408b-d048-4e36-bc1a-c01c9f586365?source=api-prod","cve":"CVE-2024-31343","affectedVersions":"<=4.10.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/a54e9aa6-943d-4f76-81af-3424a23f9313/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"a54e9aa6-943d-4f76-81af-3424a23f9313"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a54e9aa6-943d-4f76-81af-3424a23f9313?source=api-prod","cve":"CVE-2024-56266","affectedVersions":"<=5.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/bcdbd108-5e17-4e67-a2a2-0f1464c1ba6c/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"bcdbd108-5e17-4e67-a2a2-0f1464c1ba6c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bcdbd108-5e17-4e67-a2a2-0f1464c1ba6c?source=api-prod","cve":"CVE-2024-30530","affectedVersions":"<=5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/c14783d3-68de-49c6-9c54-eb7fc4a7bf94/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-09 19:09:44","sources":[{"name":"Wordfence","remoteId":"c14783d3-68de-49c6-9c54-eb7fc4a7bf94"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c14783d3-68de-49c6-9c54-eb7fc4a7bf94?source=api-prod","cve":"CVE-2024-5664","affectedVersions":"<=5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/ce8fa964-d543-4d46-a534-e403dff4f425/mp3-music-player-by-sonaar","title":"MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 4.0 - 5.10 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"ce8fa964-d543-4d46-a534-e403dff4f425"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ce8fa964-d543-4d46-a534-e403dff4f425?source=api-prod","cve":"CVE-2026-1219","affectedVersions":">=4.0,<=5.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/e42841dc-157f-45eb-8959-249326d50650/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 2.4.1 - Multiple Admin+ Cross Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"e42841dc-157f-45eb-8959-249326d50650"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e42841dc-157f-45eb-8959-249326d50650?source=api-prod","cve":"CVE-2021-24624","affectedVersions":"<=2.4.1","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/261aad1e-43fc-4927-a97d-85a001863023/mp3-music-player-by-sonaar","title":"MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 5.3 - 5.10 - Authenticated (Author+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-13 20:09:32","sources":[{"name":"Wordfence","remoteId":"261aad1e-43fc-4927-a97d-85a001863023"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/261aad1e-43fc-4927-a97d-85a001863023?source=api-prod","cve":"CVE-2026-1249","affectedVersions":">=5.3,<=5.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/43adc9dd-1780-440f-90c2-ff05a22eb084/mp3-music-player-by-sonaar","title":"MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.7.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"43adc9dd-1780-440f-90c2-ff05a22eb084"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/43adc9dd-1780-440f-90c2-ff05a22eb084?source=api-prod","cve":"CVE-2024-7856","affectedVersions":"<=5.7.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/547325ad-0b01-42d5-b47c-362044587395/mp3-music-player-by-sonaar","title":"MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Podcast RSS Feed\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-30 19:24:55","sources":[{"name":"Wordfence","remoteId":"547325ad-0b01-42d5-b47c-362044587395"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/547325ad-0b01-42d5-b47c-362044587395?source=api-prod","cve":"CVE-2024-13157","affectedVersions":"<=5.9.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/5e722b30-f136-4f57-a248-cf9cdd499552/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"5e722b30-f136-4f57-a248-cf9cdd499552"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5e722b30-f136-4f57-a248-cf9cdd499552?source=api-prod","cve":"CVE-2024-30487","affectedVersions":"<=5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/6bcb9d95-acb4-4405-b785-1e5eace10dc9/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10 - Missing Authorization to Template Import\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"6bcb9d95-acb4-4405-b785-1e5eace10dc9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6bcb9d95-acb4-4405-b785-1e5eace10dc9?source=api-prod","cve":"CVE-2023-47822","affectedVersions":"<=4.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/7ec14923-0f68-45e8-8d99-9921c5928ac4/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.9.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"7ec14923-0f68-45e8-8d99-9921c5928ac4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7ec14923-0f68-45e8-8d99-9921c5928ac4?source=api-prod","cve":"CVE-2025-32235","affectedVersions":"<=5.9.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/861d0218-0f0f-4299-a0ff-854832348457/mp3-music-player-by-sonaar","title":"MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-18 18:57:36","sources":[{"name":"Wordfence","remoteId":"861d0218-0f0f-4299-a0ff-854832348457"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/861d0218-0f0f-4299-a0ff-854832348457?source=api-prod","cve":"CVE-2024-10268","affectedVersions":"<=5.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/9576408b-d048-4e36-bc1a-c01c9f586365/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 4.10.1 - Unauthenticated Arbitrary File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"9576408b-d048-4e36-bc1a-c01c9f586365"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9576408b-d048-4e36-bc1a-c01c9f586365?source=api-prod","cve":"CVE-2024-31343","affectedVersions":"<=4.10.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/a54e9aa6-943d-4f76-81af-3424a23f9313/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"a54e9aa6-943d-4f76-81af-3424a23f9313"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a54e9aa6-943d-4f76-81af-3424a23f9313?source=api-prod","cve":"CVE-2024-56266","affectedVersions":"<=5.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/bcdbd108-5e17-4e67-a2a2-0f1464c1ba6c/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"bcdbd108-5e17-4e67-a2a2-0f1464c1ba6c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bcdbd108-5e17-4e67-a2a2-0f1464c1ba6c?source=api-prod","cve":"CVE-2024-30530","affectedVersions":"<=5.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/c14783d3-68de-49c6-9c54-eb7fc4a7bf94/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-09 19:09:44","sources":[{"name":"Wordfence","remoteId":"c14783d3-68de-49c6-9c54-eb7fc4a7bf94"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c14783d3-68de-49c6-9c54-eb7fc4a7bf94?source=api-prod","cve":"CVE-2024-5664","affectedVersions":"<=5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/cb713c9c-adb4-410c-a92f-d4d5b002d626/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.11 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"cb713c9c-adb4-410c-a92f-d4d5b002d626"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cb713c9c-adb4-410c-a92f-d4d5b002d626?source=api-prod","cve":"CVE-2026-39647","affectedVersions":"<=5.11","severity":"high"},{"advisoryId":"WPSECADV/WF/ce8fa964-d543-4d46-a534-e403dff4f425/mp3-music-player-by-sonaar","title":"MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 4.0 - 5.10 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"ce8fa964-d543-4d46-a534-e403dff4f425"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ce8fa964-d543-4d46-a534-e403dff4f425?source=api-prod","cve":"CVE-2026-1219","affectedVersions":">=4.0,<=5.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/e42841dc-157f-45eb-8959-249326d50650/mp3-music-player-by-sonaar","title":"MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 2.4.1 - Multiple Admin+ Cross Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"e42841dc-157f-45eb-8959-249326d50650"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e42841dc-157f-45eb-8959-249326d50650?source=api-prod","cve":"CVE-2021-24624","affectedVersions":"<=2.4.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6e656c696f2d636f6e74656e74811c9dc5_gen.json b/internal/data/assets/plugin_6e656c696f2d636f6e74656e74811c9dc5_gen.json index 82920a4e..db9671b4 100644 --- a/internal/data/assets/plugin_6e656c696f2d636f6e74656e74811c9dc5_gen.json +++ b/internal/data/assets/plugin_6e656c696f2d636f6e74656e74811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/150d9d64-6f7f-4646-b03f-dbc63fd0e791/nelio-content","title":"Nelio Content <= 3.2.0 - Authenticated (Contributor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"150d9d64-6f7f-4646-b03f-dbc63fd0e791"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/150d9d64-6f7f-4646-b03f-dbc63fd0e791?source=api-prod","cve":"CVE-2024-30531","affectedVersions":"<=3.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/42cd1d08-4d5a-466b-930c-f4e28ae4d52c/nelio-content","title":"Nelio Content <= 4.2.0 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"42cd1d08-4d5a-466b-930c-f4e28ae4d52c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/42cd1d08-4d5a-466b-930c-f4e28ae4d52c?source=api-prod","cve":"CVE-2026-24572","affectedVersions":"<=4.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/cc6b521b-32a4-40a2-bb4e-c0c7642693c9/nelio-content","title":"Nelio Content <= 4.0.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"cc6b521b-32a4-40a2-bb4e-c0c7642693c9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc6b521b-32a4-40a2-bb4e-c0c7642693c9?source=api-prod","cve":"CVE-2025-62927","affectedVersions":"<=4.0.5","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/150d9d64-6f7f-4646-b03f-dbc63fd0e791/nelio-content","title":"Nelio Content <= 3.2.0 - Authenticated (Contributor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"150d9d64-6f7f-4646-b03f-dbc63fd0e791"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/150d9d64-6f7f-4646-b03f-dbc63fd0e791?source=api-prod","cve":"CVE-2024-30531","affectedVersions":"<=3.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/42cd1d08-4d5a-466b-930c-f4e28ae4d52c/nelio-content","title":"Nelio Content <= 4.2.0 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"42cd1d08-4d5a-466b-930c-f4e28ae4d52c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/42cd1d08-4d5a-466b-930c-f4e28ae4d52c?source=api-prod","cve":"CVE-2026-24572","affectedVersions":"<=4.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/67bacd52-9d23-4222-a8a7-ae98f66c752a/nelio-content","title":"Nelio Content <= 4.3.1 - Authenticated (Contributor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"67bacd52-9d23-4222-a8a7-ae98f66c752a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/67bacd52-9d23-4222-a8a7-ae98f66c752a?source=api-prod","cve":"CVE-2026-39521","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/cc6b521b-32a4-40a2-bb4e-c0c7642693c9/nelio-content","title":"Nelio Content <= 4.0.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"cc6b521b-32a4-40a2-bb4e-c0c7642693c9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cc6b521b-32a4-40a2-bb4e-c0c7642693c9?source=api-prod","cve":"CVE-2025-62927","affectedVersions":"<=4.0.5","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6e696e6a612d7461626c6573811c9dc5_gen.json b/internal/data/assets/plugin_6e696e6a612d7461626c6573811c9dc5_gen.json index 2e174761..e8666a63 100644 --- a/internal/data/assets/plugin_6e696e6a612d7461626c6573811c9dc5_gen.json +++ b/internal/data/assets/plugin_6e696e6a612d7461626c6573811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/02480559-be5c-4d23-9e62-bb76fafb4f42/ninja-tables","title":"Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"02480559-be5c-4d23-9e62-bb76fafb4f42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/02480559-be5c-4d23-9e62-bb76fafb4f42?source=api-prod","cve":"CVE-2025-2940","affectedVersions":"<=5.0.18","severity":"high"},{"advisoryId":"WPSECADV/WF/338158b5-bbda-4cd8-b4ea-97a3926a0989/ninja-tables","title":"Ninja Tables <= 4.3.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"338158b5-bbda-4cd8-b4ea-97a3926a0989"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/338158b5-bbda-4cd8-b4ea-97a3926a0989?source=api-prod","cve":"CVE-2022-47136","affectedVersions":"<=4.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/35219b1e-f716-4be8-926c-62a7c462d2eb/ninja-tables","title":"Ninja Tables <= 5.2.3 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"35219b1e-f716-4be8-926c-62a7c462d2eb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/35219b1e-f716-4be8-926c-62a7c462d2eb?source=api-prod","cve":"CVE-2025-67519","affectedVersions":"<=5.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/404fab1b-45e9-470a-a0ae-73c01386d95e/ninja-tables","title":"Ninja Tables – Easiest Data Table Builder <= 5.0.9 - Authenticated (Admin+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"404fab1b-45e9-470a-a0ae-73c01386d95e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/404fab1b-45e9-470a-a0ae-73c01386d95e?source=api-prod","cve":"CVE-2024-35635","affectedVersions":"<=5.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/49bd0848-afc0-4aa2-86a4-1b697206b925/ninja-tables","title":"Ninja Tables – Easy Data Table <= 5.0.16 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"49bd0848-afc0-4aa2-86a4-1b697206b925"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/49bd0848-afc0-4aa2-86a4-1b697206b925?source=api-prod","cve":"CVE-2024-12772","affectedVersions":"<=5.0.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/64338fc4-e8c9-4fa5-bb77-861fb5142286/ninja-tables","title":"Ninja Tables <= 4.1.7 - Admin+ Stored Cross-Site Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"64338fc4-e8c9-4fa5-bb77-861fb5142286"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/64338fc4-e8c9-4fa5-bb77-861fb5142286?source=api-prod","cve":"CVE-2021-24900","affectedVersions":"<=4.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/8b9e69f0-7b21-4cc5-924c-1556764cbb0d/ninja-tables","title":"Ninja Tables <= 5.2.4 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"8b9e69f0-7b21-4cc5-924c-1556764cbb0d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8b9e69f0-7b21-4cc5-924c-1556764cbb0d?source=api-prod","cve":"CVE-2025-69351","affectedVersions":"<=5.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/8e38553d-5dba-4c84-95f7-43420245c770/ninja-tables","title":"Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated PHP Object Injection to Limited Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e38553d-5dba-4c84-95f7-43420245c770"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e38553d-5dba-4c84-95f7-43420245c770?source=api-prod","cve":"CVE-2025-2939","affectedVersions":"<=5.0.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/b1eb6896-2de3-4d4d-9b5f-253aaffd193b/ninja-tables","title":"Ninja Tables – Easiest Data Table Builder <= 5.0.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-26 18:30:02","sources":[{"name":"Wordfence","remoteId":"b1eb6896-2de3-4d4d-9b5f-253aaffd193b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b1eb6896-2de3-4d4d-9b5f-253aaffd193b?source=api-prod","cve":"CVE-2024-7304","affectedVersions":"<=5.0.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/baee1bba-c531-4a6a-8e4d-5c44e3d7e84f/ninja-tables","title":"Ninja Tables – Easy Data Table Builder <= 5.2.5 - Authenticated (Contributor+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"baee1bba-c531-4a6a-8e4d-5c44e3d7e84f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/baee1bba-c531-4a6a-8e4d-5c44e3d7e84f?source=api-prod","cve":"CVE-2026-25008","affectedVersions":"<=5.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/c86e5cfd-f450-48d6-819e-5345fc0fdfc8/ninja-tables","title":"Ninja Tables <= 5.0.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"c86e5cfd-f450-48d6-819e-5345fc0fdfc8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c86e5cfd-f450-48d6-819e-5345fc0fdfc8?source=api-prod","cve":"CVE-2024-23504","affectedVersions":"<=5.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/fc296c70-358e-4908-be49-5ffae83aca9b/ninja-tables","title":"Ninja Tables <= 4.3.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"fc296c70-358e-4908-be49-5ffae83aca9b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fc296c70-358e-4908-be49-5ffae83aca9b?source=api-prod","cve":"CVE-2022-47137","affectedVersions":"<=4.3.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/02480559-be5c-4d23-9e62-bb76fafb4f42/ninja-tables","title":"Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"02480559-be5c-4d23-9e62-bb76fafb4f42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/02480559-be5c-4d23-9e62-bb76fafb4f42?source=api-prod","cve":"CVE-2025-2940","affectedVersions":"<=5.0.18","severity":"high"},{"advisoryId":"WPSECADV/WF/338158b5-bbda-4cd8-b4ea-97a3926a0989/ninja-tables","title":"Ninja Tables <= 4.3.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"338158b5-bbda-4cd8-b4ea-97a3926a0989"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/338158b5-bbda-4cd8-b4ea-97a3926a0989?source=api-prod","cve":"CVE-2022-47136","affectedVersions":"<=4.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/35219b1e-f716-4be8-926c-62a7c462d2eb/ninja-tables","title":"Ninja Tables <= 5.2.3 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"35219b1e-f716-4be8-926c-62a7c462d2eb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/35219b1e-f716-4be8-926c-62a7c462d2eb?source=api-prod","cve":"CVE-2025-67519","affectedVersions":"<=5.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/404fab1b-45e9-470a-a0ae-73c01386d95e/ninja-tables","title":"Ninja Tables – Easiest Data Table Builder <= 5.0.9 - Authenticated (Admin+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"404fab1b-45e9-470a-a0ae-73c01386d95e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/404fab1b-45e9-470a-a0ae-73c01386d95e?source=api-prod","cve":"CVE-2024-35635","affectedVersions":"<=5.0.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/49bd0848-afc0-4aa2-86a4-1b697206b925/ninja-tables","title":"Ninja Tables – Easy Data Table <= 5.0.16 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"49bd0848-afc0-4aa2-86a4-1b697206b925"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/49bd0848-afc0-4aa2-86a4-1b697206b925?source=api-prod","cve":"CVE-2024-12772","affectedVersions":"<=5.0.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/592d42eb-4025-44af-a519-672656ad8b0e/ninja-tables","title":"Ninja Tables <= 5.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Table Creation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-05 15:30:47","sources":[{"name":"Wordfence","remoteId":"592d42eb-4025-44af-a519-672656ad8b0e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/592d42eb-4025-44af-a519-672656ad8b0e?source=api-prod","cve":"CVE-2026-2306","affectedVersions":"<=5.2.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/64338fc4-e8c9-4fa5-bb77-861fb5142286/ninja-tables","title":"Ninja Tables <= 4.1.7 - Admin+ Stored Cross-Site Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"64338fc4-e8c9-4fa5-bb77-861fb5142286"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/64338fc4-e8c9-4fa5-bb77-861fb5142286?source=api-prod","cve":"CVE-2021-24900","affectedVersions":"<=4.1.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/8b9e69f0-7b21-4cc5-924c-1556764cbb0d/ninja-tables","title":"Ninja Tables <= 5.2.4 - Authenticated (Contributor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"8b9e69f0-7b21-4cc5-924c-1556764cbb0d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8b9e69f0-7b21-4cc5-924c-1556764cbb0d?source=api-prod","cve":"CVE-2025-69351","affectedVersions":"<=5.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/8e38553d-5dba-4c84-95f7-43420245c770/ninja-tables","title":"Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated PHP Object Injection to Limited Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"8e38553d-5dba-4c84-95f7-43420245c770"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8e38553d-5dba-4c84-95f7-43420245c770?source=api-prod","cve":"CVE-2025-2939","affectedVersions":"<=5.0.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/b1eb6896-2de3-4d4d-9b5f-253aaffd193b/ninja-tables","title":"Ninja Tables – Easiest Data Table Builder <= 5.0.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-26 18:30:02","sources":[{"name":"Wordfence","remoteId":"b1eb6896-2de3-4d4d-9b5f-253aaffd193b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b1eb6896-2de3-4d4d-9b5f-253aaffd193b?source=api-prod","cve":"CVE-2024-7304","affectedVersions":"<=5.0.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/baee1bba-c531-4a6a-8e4d-5c44e3d7e84f/ninja-tables","title":"Ninja Tables – Easy Data Table Builder <= 5.2.5 - Authenticated (Contributor+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"baee1bba-c531-4a6a-8e4d-5c44e3d7e84f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/baee1bba-c531-4a6a-8e4d-5c44e3d7e84f?source=api-prod","cve":"CVE-2026-25008","affectedVersions":"<=5.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/c86e5cfd-f450-48d6-819e-5345fc0fdfc8/ninja-tables","title":"Ninja Tables <= 5.0.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"c86e5cfd-f450-48d6-819e-5345fc0fdfc8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c86e5cfd-f450-48d6-819e-5345fc0fdfc8?source=api-prod","cve":"CVE-2024-23504","affectedVersions":"<=5.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/fc296c70-358e-4908-be49-5ffae83aca9b/ninja-tables","title":"Ninja Tables <= 4.3.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"fc296c70-358e-4908-be49-5ffae83aca9b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fc296c70-358e-4908-be49-5ffae83aca9b?source=api-prod","cve":"CVE-2022-47137","affectedVersions":"<=4.3.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_6e6f6f2d766973696f6e6172792d636f7265811c9dc5_gen.json b/internal/data/assets/plugin_6e6f6f2d766973696f6e6172792d636f7265811c9dc5_gen.json index b4562a5c..e0a18af7 100644 --- a/internal/data/assets/plugin_6e6f6f2d766973696f6e6172792d636f7265811c9dc5_gen.json +++ b/internal/data/assets/plugin_6e6f6f2d766973696f6e6172792d636f7265811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/cb981b48-a31a-4ebb-96c9-c6d31e2dfe02/noo-visionary-core","title":"Visionary Core <= 1.4.9 - Authenticated (Subscriber+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"cb981b48-a31a-4ebb-96c9-c6d31e2dfe02"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cb981b48-a31a-4ebb-96c9-c6d31e2dfe02?source=api-prod","cve":"CVE-2026-24981","affectedVersions":"<=1.4.9","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/279f2c7f-385d-4ff4-bc10-ce8be7e217f9/noo-visionary-core","title":"Visionary Core <= 1.4.9 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"279f2c7f-385d-4ff4-bc10-ce8be7e217f9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/279f2c7f-385d-4ff4-bc10-ce8be7e217f9?source=api-prod","cve":"CVE-2026-24980","affectedVersions":"<=1.4.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/cb981b48-a31a-4ebb-96c9-c6d31e2dfe02/noo-visionary-core","title":"Visionary Core <= 1.4.9 - Authenticated (Subscriber+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"cb981b48-a31a-4ebb-96c9-c6d31e2dfe02"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cb981b48-a31a-4ebb-96c9-c6d31e2dfe02?source=api-prod","cve":"CVE-2026-24981","affectedVersions":"<=1.4.9","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_706167656c61796572811c9dc5_gen.json b/internal/data/assets/plugin_706167656c61796572811c9dc5_gen.json index 38aab19c..9f34a6de 100644 --- a/internal/data/assets/plugin_706167656c61796572811c9dc5_gen.json +++ b/internal/data/assets/plugin_706167656c61796572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/09ac7546-0572-4446-99f7-fe84f76fac9b/pagelayer","title":"PageLayer <= 1.8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"09ac7546-0572-4446-99f7-fe84f76fac9b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/09ac7546-0572-4446-99f7-fe84f76fac9b?source=api-prod","cve":"CVE-2024-43972","affectedVersions":"<=1.8.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/1de8da4c-dee7-4d59-a475-a969008aa0d4/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"1de8da4c-dee7-4d59-a475-a969008aa0d4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1de8da4c-dee7-4d59-a475-a969008aa0d4?source=api-prod","cve":"CVE-2024-13430","affectedVersions":"<=1.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/2216d82c-29ae-4355-8118-6ebc49726c12/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-12 15:20:40","sources":[{"name":"Wordfence","remoteId":"2216d82c-29ae-4355-8118-6ebc49726c12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2216d82c-29ae-4355-8118-6ebc49726c12?source=api-prod","cve":"CVE-2025-12366","affectedVersions":"<=2.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/2e3897fb-0f40-4111-8a7d-60415e1f9f96/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"2e3897fb-0f40-4111-8a7d-60415e1f9f96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2e3897fb-0f40-4111-8a7d-60415e1f9f96?source=api-prod","cve":"CVE-2025-2104","affectedVersions":"<=1.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/3a0c8ecc-f0a1-41fa-a5f7-2d65d610efc0/pagelayer","title":"PageLayer <= 1.7.7 - Cross-Site Request Forgery via pagelayer_load_plugin\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"3a0c8ecc-f0a1-41fa-a5f7-2d65d610efc0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3a0c8ecc-f0a1-41fa-a5f7-2d65d610efc0?source=api-prod","cve":"CVE-2023-49196","affectedVersions":"<=1.7.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/467e0946-cfbb-4ea3-b2d9-db21d0f182cd/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 - Reflected Cross-Site Scripting via font-size\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-12-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"467e0946-cfbb-4ea3-b2d9-db21d0f182cd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/467e0946-cfbb-4ea3-b2d9-db21d0f182cd?source=api-prod","cve":"CVE-2020-36383","affectedVersions":"<1.3.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/4d8d581c-8198-4431-a534-aac8f05750cb/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.7.6 - Missing Authorization to Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d8d581c-8198-4431-a534-aac8f05750cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d8d581c-8198-4431-a534-aac8f05750cb?source=api-prod","cve":"CVE-2023-4687","affectedVersions":"<=1.7.6","severity":"high"},{"advisoryId":"WPSECADV/WF/4d9f7832-3dff-4cb8-a6be-a16449164363/pagelayer","title":"PageLayer <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d9f7832-3dff-4cb8-a6be-a16449164363"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d9f7832-3dff-4cb8-a6be-a16449164363?source=api-prod","cve":"CVE-2025-24573","affectedVersions":"<=1.9.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/542b6312-b264-49d5-882a-454427c60c8a/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-09 16:20:57","sources":[{"name":"Wordfence","remoteId":"542b6312-b264-49d5-882a-454427c60c8a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/542b6312-b264-49d5-882a-454427c60c8a?source=api-prod","cve":"CVE-2025-1926","affectedVersions":"<=1.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/5df2f3cc-affc-4549-b59e-d145cce10c79/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5df2f3cc-affc-4549-b59e-d145cce10c79"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5df2f3cc-affc-4549-b59e-d145cce10c79?source=api-prod","cve":"CVE-2024-13427","affectedVersions":"<=2.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/636731ab-31e6-4750-b691-4850b29022dc/pagelayer","title":"Page Builder: Pagelayer <= 1.8.7 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"636731ab-31e6-4750-b691-4850b29022dc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/636731ab-31e6-4750-b691-4850b29022dc?source=api-prod","cve":"CVE-2024-8426","affectedVersions":"<=1.8.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/666c02bd-d3e2-4e40-b189-b73e1136610b/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Cross-Site Request Forgery to Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-05-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"666c02bd-d3e2-4e40-b189-b73e1136610b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/666c02bd-d3e2-4e40-b189-b73e1136610b?source=api-prod","cve":"CVE-2020-35944","affectedVersions":"<1.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/8ade80e4-a05a-4418-9c01-67c0366213b6/pagelayer","title":"PageLayer <= 1.8.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ade80e4-a05a-4418-9c01-67c0366213b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ade80e4-a05a-4418-9c01-67c0366213b6?source=api-prod","cve":"CVE-2024-30465","affectedVersions":"<=1.8.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/915c119d-2bae-4ea6-babb-7e8e99054cd0/pagelayer","title":"Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"915c119d-2bae-4ea6-babb-7e8e99054cd0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/915c119d-2bae-4ea6-babb-7e8e99054cd0?source=api-prod","cve":"CVE-2026-2509","affectedVersions":"<=2.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/98bff131-dee2-4549-9167-69dc3f8d6b9d/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"98bff131-dee2-4549-9167-69dc3f8d6b9d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/98bff131-dee2-4549-9167-69dc3f8d6b9d?source=api-prod","cve":"CVE-2024-2127","affectedVersions":"<=1.8.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/99c13de3-e040-4c11-b9c0-bd6a337c4769/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 - Reflected Cross-Site Scripting via Color Settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-12-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"99c13de3-e040-4c11-b9c0-bd6a337c4769"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/99c13de3-e040-4c11-b9c0-bd6a337c4769?source=api-prod","cve":"CVE-2020-36384","affectedVersions":"<1.3.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6db6736-4629-47b7-976a-f81335430119/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-23 15:53:03","sources":[{"name":"Wordfence","remoteId":"b6db6736-4629-47b7-976a-f81335430119"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6db6736-4629-47b7-976a-f81335430119?source=api-prod","cve":"CVE-2025-4223","affectedVersions":"<=2.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/b8bd08d0-5c78-40a8-abc1-de387908df9d/pagelayer","title":"Pagelayer <= 1.7.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via Header/Footer code\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"b8bd08d0-5c78-40a8-abc1-de387908df9d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b8bd08d0-5c78-40a8-abc1-de387908df9d?source=api-prod","cve":"CVE-2023-5124","affectedVersions":"<1.8.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c4884ba9-4448-43b0-93d3-110b719845ea/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"c4884ba9-4448-43b0-93d3-110b719845ea"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c4884ba9-4448-43b0-93d3-110b719845ea?source=api-prod","cve":"CVE-2024-2504","affectedVersions":"<=1.8.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8032213-52e7-4222-a9a5-13fa64d66213/pagelayer","title":"Page Builder: Pagelayer <= 1.8.9 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"c8032213-52e7-4222-a9a5-13fa64d66213"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8032213-52e7-4222-a9a5-13fa64d66213?source=api-prod","cve":"CVE-2024-8618","affectedVersions":"<=1.8.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/c9bd3620-60a2-4741-b623-5147b6997575/pagelayer","title":"Page Builder: Pagelayer <= 1.7.7 - Authenticated (Author+) Stored Cross-Site Scripting via Header/Footer\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"c9bd3620-60a2-4741-b623-5147b6997575"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c9bd3620-60a2-4741-b623-5147b6997575?source=api-prod","cve":"CVE-2023-5087","affectedVersions":"<=1.7.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca7f1b56-a732-40c1-a05e-4ab3e6b05037/pagelayer","title":"Page Builder: Pagelayer <= 1.7.9 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca7f1b56-a732-40c1-a05e-4ab3e6b05037"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca7f1b56-a732-40c1-a05e-4ab3e6b05037?source=api-prod","cve":"CVE-2023-7115","affectedVersions":"<=1.7.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/ce101aad-10a3-4a8c-9f4a-0e38e35b4dab/pagelayer","title":"Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-27 20:45:22","sources":[{"name":"Wordfence","remoteId":"ce101aad-10a3-4a8c-9f4a-0e38e35b4dab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ce101aad-10a3-4a8c-9f4a-0e38e35b4dab?source=api-prod","cve":"CVE-2026-2442","affectedVersions":"<=2.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/d14c8890-482c-4d43-a68f-0d04c4feca8f/pagelayer","title":"PageLayer <= 1.7.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via meta fields\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"d14c8890-482c-4d43-a68f-0d04c4feca8f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d14c8890-482c-4d43-a68f-0d04c4feca8f?source=api-prod","cve":"CVE-2023-6738","affectedVersions":"<=1.7.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/d33a77c6-9977-4d92-92c4-4273ee73452e/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Missing Authorization to Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-05-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"d33a77c6-9977-4d92-92c4-4273ee73452e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d33a77c6-9977-4d92-92c4-4273ee73452e?source=api-prod","cve":"CVE-2020-35947","affectedVersions":"<1.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/e34b6ae5-1370-4058-95dd-5686978ca45b/pagelayer","title":"PageLayer <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"e34b6ae5-1370-4058-95dd-5686978ca45b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e34b6ae5-1370-4058-95dd-5686978ca45b?source=api-prod","affectedVersions":"<1.7.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/e635dfb3-002d-4197-b14a-0136a1990a75/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"e635dfb3-002d-4197-b14a-0136a1990a75"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e635dfb3-002d-4197-b14a-0136a1990a75?source=api-prod","cve":"CVE-2024-1590","affectedVersions":"<=1.8.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/09ac7546-0572-4446-99f7-fe84f76fac9b/pagelayer","title":"PageLayer <= 1.8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"09ac7546-0572-4446-99f7-fe84f76fac9b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/09ac7546-0572-4446-99f7-fe84f76fac9b?source=api-prod","cve":"CVE-2024-43972","affectedVersions":"<=1.8.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/1de8da4c-dee7-4d59-a475-a969008aa0d4/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"1de8da4c-dee7-4d59-a475-a969008aa0d4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1de8da4c-dee7-4d59-a475-a969008aa0d4?source=api-prod","cve":"CVE-2024-13430","affectedVersions":"<=1.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/2216d82c-29ae-4355-8118-6ebc49726c12/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-12 15:20:40","sources":[{"name":"Wordfence","remoteId":"2216d82c-29ae-4355-8118-6ebc49726c12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2216d82c-29ae-4355-8118-6ebc49726c12?source=api-prod","cve":"CVE-2025-12366","affectedVersions":"<=2.0.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/2e3897fb-0f40-4111-8a7d-60415e1f9f96/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"2e3897fb-0f40-4111-8a7d-60415e1f9f96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2e3897fb-0f40-4111-8a7d-60415e1f9f96?source=api-prod","cve":"CVE-2025-2104","affectedVersions":"<=1.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/3a0c8ecc-f0a1-41fa-a5f7-2d65d610efc0/pagelayer","title":"PageLayer <= 1.7.7 - Cross-Site Request Forgery via pagelayer_load_plugin\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"3a0c8ecc-f0a1-41fa-a5f7-2d65d610efc0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3a0c8ecc-f0a1-41fa-a5f7-2d65d610efc0?source=api-prod","cve":"CVE-2023-49196","affectedVersions":"<=1.7.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/467e0946-cfbb-4ea3-b2d9-db21d0f182cd/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 - Reflected Cross-Site Scripting via font-size\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-12-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"467e0946-cfbb-4ea3-b2d9-db21d0f182cd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/467e0946-cfbb-4ea3-b2d9-db21d0f182cd?source=api-prod","cve":"CVE-2020-36383","affectedVersions":"<1.3.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/4d8d581c-8198-4431-a534-aac8f05750cb/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.7.6 - Missing Authorization to Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d8d581c-8198-4431-a534-aac8f05750cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d8d581c-8198-4431-a534-aac8f05750cb?source=api-prod","cve":"CVE-2023-4687","affectedVersions":"<=1.7.6","severity":"high"},{"advisoryId":"WPSECADV/WF/4d9f7832-3dff-4cb8-a6be-a16449164363/pagelayer","title":"PageLayer <= 1.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"4d9f7832-3dff-4cb8-a6be-a16449164363"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d9f7832-3dff-4cb8-a6be-a16449164363?source=api-prod","cve":"CVE-2025-24573","affectedVersions":"<=1.9.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/542b6312-b264-49d5-882a-454427c60c8a/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-09 16:20:57","sources":[{"name":"Wordfence","remoteId":"542b6312-b264-49d5-882a-454427c60c8a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/542b6312-b264-49d5-882a-454427c60c8a?source=api-prod","cve":"CVE-2025-1926","affectedVersions":"<=1.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/5df2f3cc-affc-4549-b59e-d145cce10c79/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5df2f3cc-affc-4549-b59e-d145cce10c79"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5df2f3cc-affc-4549-b59e-d145cce10c79?source=api-prod","cve":"CVE-2024-13427","affectedVersions":"<=2.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/636731ab-31e6-4750-b691-4850b29022dc/pagelayer","title":"Page Builder: Pagelayer <= 1.8.7 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"636731ab-31e6-4750-b691-4850b29022dc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/636731ab-31e6-4750-b691-4850b29022dc?source=api-prod","cve":"CVE-2024-8426","affectedVersions":"<=1.8.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/666c02bd-d3e2-4e40-b189-b73e1136610b/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Cross-Site Request Forgery to Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-05-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"666c02bd-d3e2-4e40-b189-b73e1136610b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/666c02bd-d3e2-4e40-b189-b73e1136610b?source=api-prod","cve":"CVE-2020-35944","affectedVersions":"<1.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/8ade80e4-a05a-4418-9c01-67c0366213b6/pagelayer","title":"PageLayer <= 1.8.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"8ade80e4-a05a-4418-9c01-67c0366213b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ade80e4-a05a-4418-9c01-67c0366213b6?source=api-prod","cve":"CVE-2024-30465","affectedVersions":"<=1.8.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/915c119d-2bae-4ea6-babb-7e8e99054cd0/pagelayer","title":"Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"915c119d-2bae-4ea6-babb-7e8e99054cd0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/915c119d-2bae-4ea6-babb-7e8e99054cd0?source=api-prod","cve":"CVE-2026-2509","affectedVersions":"<=2.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/98bff131-dee2-4549-9167-69dc3f8d6b9d/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"98bff131-dee2-4549-9167-69dc3f8d6b9d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/98bff131-dee2-4549-9167-69dc3f8d6b9d?source=api-prod","cve":"CVE-2024-2127","affectedVersions":"<=1.8.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/99c13de3-e040-4c11-b9c0-bd6a337c4769/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder < 1.3.5 - Reflected Cross-Site Scripting via Color Settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-12-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"99c13de3-e040-4c11-b9c0-bd6a337c4769"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/99c13de3-e040-4c11-b9c0-bd6a337c4769?source=api-prod","cve":"CVE-2020-36384","affectedVersions":"<1.3.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6db6736-4629-47b7-976a-f81335430119/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-23 15:53:03","sources":[{"name":"Wordfence","remoteId":"b6db6736-4629-47b7-976a-f81335430119"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6db6736-4629-47b7-976a-f81335430119?source=api-prod","cve":"CVE-2025-4223","affectedVersions":"<=2.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/b8bd08d0-5c78-40a8-abc1-de387908df9d/pagelayer","title":"Pagelayer <= 1.7.9 - Authenticated(Administrator+) Stored Cross-Site Scripting via Header/Footer code\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"b8bd08d0-5c78-40a8-abc1-de387908df9d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b8bd08d0-5c78-40a8-abc1-de387908df9d?source=api-prod","cve":"CVE-2023-5124","affectedVersions":"<1.8.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c4884ba9-4448-43b0-93d3-110b719845ea/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"c4884ba9-4448-43b0-93d3-110b719845ea"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c4884ba9-4448-43b0-93d3-110b719845ea?source=api-prod","cve":"CVE-2024-2504","affectedVersions":"<=1.8.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/c6c5bea1-c34d-428d-a77e-16cdd45fbc40/pagelayer","title":"PageLayer <= 2.0.8 - Authenticated (Contributor+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"c6c5bea1-c34d-428d-a77e-16cdd45fbc40"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c6c5bea1-c34d-428d-a77e-16cdd45fbc40?source=api-prod","cve":"CVE-2026-39469","affectedVersions":"<=2.0.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8032213-52e7-4222-a9a5-13fa64d66213/pagelayer","title":"Page Builder: Pagelayer <= 1.8.9 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"c8032213-52e7-4222-a9a5-13fa64d66213"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8032213-52e7-4222-a9a5-13fa64d66213?source=api-prod","cve":"CVE-2024-8618","affectedVersions":"<=1.8.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/c9bd3620-60a2-4741-b623-5147b6997575/pagelayer","title":"Page Builder: Pagelayer <= 1.7.7 - Authenticated (Author+) Stored Cross-Site Scripting via Header/Footer\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"c9bd3620-60a2-4741-b623-5147b6997575"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c9bd3620-60a2-4741-b623-5147b6997575?source=api-prod","cve":"CVE-2023-5087","affectedVersions":"<=1.7.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca7f1b56-a732-40c1-a05e-4ab3e6b05037/pagelayer","title":"Page Builder: Pagelayer <= 1.7.9 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca7f1b56-a732-40c1-a05e-4ab3e6b05037"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca7f1b56-a732-40c1-a05e-4ab3e6b05037?source=api-prod","cve":"CVE-2023-7115","affectedVersions":"<=1.7.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/ce101aad-10a3-4a8c-9f4a-0e38e35b4dab/pagelayer","title":"Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-27 20:45:22","sources":[{"name":"Wordfence","remoteId":"ce101aad-10a3-4a8c-9f4a-0e38e35b4dab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ce101aad-10a3-4a8c-9f4a-0e38e35b4dab?source=api-prod","cve":"CVE-2026-2442","affectedVersions":"<=2.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/d14c8890-482c-4d43-a68f-0d04c4feca8f/pagelayer","title":"PageLayer <= 1.7.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via meta fields\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-01-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"d14c8890-482c-4d43-a68f-0d04c4feca8f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d14c8890-482c-4d43-a68f-0d04c4feca8f?source=api-prod","cve":"CVE-2023-6738","affectedVersions":"<=1.7.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/d33a77c6-9977-4d92-92c4-4273ee73452e/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.1.1 - Missing Authorization to Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-05-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"d33a77c6-9977-4d92-92c4-4273ee73452e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d33a77c6-9977-4d92-92c4-4273ee73452e?source=api-prod","cve":"CVE-2020-35947","affectedVersions":"<1.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/e34b6ae5-1370-4058-95dd-5686978ca45b/pagelayer","title":"PageLayer <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"e34b6ae5-1370-4058-95dd-5686978ca45b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e34b6ae5-1370-4058-95dd-5686978ca45b?source=api-prod","affectedVersions":"<1.7.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/e635dfb3-002d-4197-b14a-0136a1990a75/pagelayer","title":"Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"e635dfb3-002d-4197-b14a-0136a1990a75"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e635dfb3-002d-4197-b14a-0136a1990a75?source=api-prod","cve":"CVE-2024-1590","affectedVersions":"<=1.8.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_706f6469676565811c9dc5_gen.json b/internal/data/assets/plugin_706f6469676565811c9dc5_gen.json new file mode 100644 index 00000000..d34546a9 --- /dev/null +++ b/internal/data/assets/plugin_706f6469676565811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/5b97cb49-abcd-4e54-b78c-0009212ffe38/podigee","title":"Podigee <= 1.4.0 - Unauthenticated Sever-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"5b97cb49-abcd-4e54-b78c-0009212ffe38"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5b97cb49-abcd-4e54-b78c-0009212ffe38?source=api-prod","cve":"CVE-2026-39695","affectedVersions":"<=1.4.0","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_72737670811c9dc5_gen.json b/internal/data/assets/plugin_72737670811c9dc5_gen.json index c3e252b8..a97fd3c6 100644 --- a/internal/data/assets/plugin_72737670811c9dc5_gen.json +++ b/internal/data/assets/plugin_72737670811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/120f15aa-ccef-49be-8743-e77d699601e2/rsvp","title":"RSVP and Event Management Plugin <= 2.7.14 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"120f15aa-ccef-49be-8743-e77d699601e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/120f15aa-ccef-49be-8743-e77d699601e2?source=api-prod","cve":"CVE-2025-24683","affectedVersions":"<=2.7.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/4ac44e4f-7052-465c-82ab-c3f23a62c898/rsvp","title":"RSVP and Event Management <= 2.7.7 - Unauthenticated Sensitive Information Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"4ac44e4f-7052-465c-82ab-c3f23a62c898"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ac44e4f-7052-465c-82ab-c3f23a62c898?source=api-prod","cve":"CVE-2022-1054","affectedVersions":"<=2.7.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/6f73b12b-813d-49fa-84a0-3345023a16c6/rsvp","title":"RSVP and Event Management <= 2.7.4 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f73b12b-813d-49fa-84a0-3345023a16c6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f73b12b-813d-49fa-84a0-3345023a16c6?source=api-prod","affectedVersions":"<2.7.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/792d6c70-4c17-493a-bb4a-08a55e8240d3/rsvp","title":"RSVP and Event Management Plugin <= 2.3.7 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-06-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"792d6c70-4c17-493a-bb4a-08a55e8240d3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/792d6c70-4c17-493a-bb4a-08a55e8240d3?source=api-prod","cve":"CVE-2017-18563","affectedVersions":"<2.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/d234212a-2019-477d-81d1-b2acc2321055/rsvp","title":"RSVP and Event Management <= 2.7.13 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"d234212a-2019-477d-81d1-b2acc2321055"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d234212a-2019-477d-81d1-b2acc2321055?source=api-prod","cve":"CVE-2024-12711","affectedVersions":"<=2.7.13","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/120f15aa-ccef-49be-8743-e77d699601e2/rsvp","title":"RSVP and Event Management Plugin <= 2.7.14 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"120f15aa-ccef-49be-8743-e77d699601e2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/120f15aa-ccef-49be-8743-e77d699601e2?source=api-prod","cve":"CVE-2025-24683","affectedVersions":"<=2.7.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/4ac44e4f-7052-465c-82ab-c3f23a62c898/rsvp","title":"RSVP and Event Management <= 2.7.7 - Unauthenticated Sensitive Information Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"4ac44e4f-7052-465c-82ab-c3f23a62c898"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ac44e4f-7052-465c-82ab-c3f23a62c898?source=api-prod","cve":"CVE-2022-1054","affectedVersions":"<=2.7.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/6f73b12b-813d-49fa-84a0-3345023a16c6/rsvp","title":"RSVP and Event Management <= 2.7.4 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-01-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"6f73b12b-813d-49fa-84a0-3345023a16c6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6f73b12b-813d-49fa-84a0-3345023a16c6?source=api-prod","affectedVersions":"<2.7.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/792d6c70-4c17-493a-bb4a-08a55e8240d3/rsvp","title":"RSVP and Event Management Plugin <= 2.3.7 - Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2017-06-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"792d6c70-4c17-493a-bb4a-08a55e8240d3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/792d6c70-4c17-493a-bb4a-08a55e8240d3?source=api-prod","cve":"CVE-2017-18563","affectedVersions":"<2.3.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/9b4a1529-ddc5-42f2-9e50-7f45851fca4b/rsvp","title":"RSVP and Event Management <= 2.7.16 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"9b4a1529-ddc5-42f2-9e50-7f45851fca4b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9b4a1529-ddc5-42f2-9e50-7f45851fca4b?source=api-prod","cve":"CVE-2026-39536","affectedVersions":"<=2.7.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/d234212a-2019-477d-81d1-b2acc2321055/rsvp","title":"RSVP and Event Management <= 2.7.13 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"d234212a-2019-477d-81d1-b2acc2321055"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d234212a-2019-477d-81d1-b2acc2321055?source=api-prod","cve":"CVE-2024-12711","affectedVersions":"<=2.7.13","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_727431382d657874656e73696f6e73811c9dc5_gen.json b/internal/data/assets/plugin_727431382d657874656e73696f6e73811c9dc5_gen.json index 4551c264..7d1d980b 100644 --- a/internal/data/assets/plugin_727431382d657874656e73696f6e73811c9dc5_gen.json +++ b/internal/data/assets/plugin_727431382d657874656e73696f6e73811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/810e0fad-38d5-42de-bc46-8176b7756ffd/rt18-extensions","title":"RT-Theme 18 | Extensions <= 2.5 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"810e0fad-38d5-42de-bc46-8176b7756ffd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/810e0fad-38d5-42de-bc46-8176b7756ffd?source=api-prod","cve":"CVE-2026-39710","affectedVersions":"<=2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/f804f31b-4778-4d2d-bcaa-a9f79f6753ee/rt18-extensions","title":"RT-Theme 18 | Extensions <= 2.4 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"f804f31b-4778-4d2d-bcaa-a9f79f6753ee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f804f31b-4778-4d2d-bcaa-a9f79f6753ee?source=api-prod","cve":"CVE-2025-32288","affectedVersions":"<=2.4","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/389364b7-4ab9-41b2-86f0-d30393e08146/rt18-extensions","title":"RT-Theme 18 | Extensions <= 2.5 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"389364b7-4ab9-41b2-86f0-d30393e08146"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/389364b7-4ab9-41b2-86f0-d30393e08146?source=api-prod","cve":"CVE-2026-39711","affectedVersions":"<=2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/810e0fad-38d5-42de-bc46-8176b7756ffd/rt18-extensions","title":"RT-Theme 18 | Extensions <= 2.5 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"810e0fad-38d5-42de-bc46-8176b7756ffd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/810e0fad-38d5-42de-bc46-8176b7756ffd?source=api-prod","cve":"CVE-2026-39710","affectedVersions":"<=2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/f804f31b-4778-4d2d-bcaa-a9f79f6753ee/rt18-extensions","title":"RT-Theme 18 | Extensions <= 2.4 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"f804f31b-4778-4d2d-bcaa-a9f79f6753ee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f804f31b-4778-4d2d-bcaa-a9f79f6753ee?source=api-prod","cve":"CVE-2025-32288","affectedVersions":"<=2.4","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_73656f2d62792d72616e6b2d6d6174682d70726f811c9dc5_gen.json b/internal/data/assets/plugin_73656f2d62792d72616e6b2d6d6174682d70726f811c9dc5_gen.json index b670d1de..e9cb0e82 100644 --- a/internal/data/assets/plugin_73656f2d62792d72616e6b2d6d6174682d70726f811c9dc5_gen.json +++ b/internal/data/assets/plugin_73656f2d62792d72616e6b2d6d6174682d70726f811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/b4ec9001-c4aa-4db3-b7d7-29afa243f78a/seo-by-rank-math-pro","title":"Rank Math SEO PRO <= 3.0.35 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"b4ec9001-c4aa-4db3-b7d7-29afa243f78a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b4ec9001-c4aa-4db3-b7d7-29afa243f78a?source=api-prod","cve":"CVE-2023-32800","affectedVersions":"<=3.0.35","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/3391d3dd-572e-4238-bfa6-f54db0b1fec4/seo-by-rank-math-pro","title":"Rank Math SEO PRO <= 3.0.96 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"3391d3dd-572e-4238-bfa6-f54db0b1fec4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3391d3dd-572e-4238-bfa6-f54db0b1fec4?source=api-prod","cve":"CVE-2026-28080","affectedVersions":"<=3.0.96","severity":"medium"},{"advisoryId":"WPSECADV/WF/b4ec9001-c4aa-4db3-b7d7-29afa243f78a/seo-by-rank-math-pro","title":"Rank Math SEO PRO <= 3.0.35 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"b4ec9001-c4aa-4db3-b7d7-29afa243f78a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b4ec9001-c4aa-4db3-b7d7-29afa243f78a?source=api-prod","cve":"CVE-2023-32800","affectedVersions":"<=3.0.35","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_73686f706275696c646572811c9dc5_gen.json b/internal/data/assets/plugin_73686f706275696c646572811c9dc5_gen.json index ac9ef99b..afad59cb 100644 --- a/internal/data/assets/plugin_73686f706275696c646572811c9dc5_gen.json +++ b/internal/data/assets/plugin_73686f706275696c646572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/213a40fe-a143-46c9-b383-83c3fc31675d/shopbuilder","title":"Shopbuilder <= 3.2.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"213a40fe-a143-46c9-b383-83c3fc31675d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/213a40fe-a143-46c9-b383-83c3fc31675d?source=api-prod","cve":"CVE-2025-13456","affectedVersions":"<=3.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/23b6e418-5560-4543-9042-5f338df315e5/shopbuilder","title":"ShopBuilder – Elementor WooCommerce Builder Addons <= 2.1.12 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"23b6e418-5560-4543-9042-5f338df315e5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/23b6e418-5560-4543-9042-5f338df315e5?source=api-prod","cve":"CVE-2024-37520","affectedVersions":"<=2.1.12","severity":"high"},{"advisoryId":"WPSECADV/WF/d0f216fc-7073-42da-a3cc-7452fa9775bd/shopbuilder","title":"ShopBuilder – Elementor WooCommerce Builder Addons <= 2.1.8 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"d0f216fc-7073-42da-a3cc-7452fa9775bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d0f216fc-7073-42da-a3cc-7452fa9775bd?source=api-prod","cve":"CVE-2024-34812","affectedVersions":"<=2.1.8","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0e363267-0b15-46e8-a112-d24dd6b8a22e/shopbuilder","title":"ShopBuilder – Elementor WooCommerce Builder Addons <= 3.2.4 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"0e363267-0b15-46e8-a112-d24dd6b8a22e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e363267-0b15-46e8-a112-d24dd6b8a22e?source=api-prod","cve":"CVE-2026-32372","affectedVersions":"<=3.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/213a40fe-a143-46c9-b383-83c3fc31675d/shopbuilder","title":"Shopbuilder <= 3.2.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"213a40fe-a143-46c9-b383-83c3fc31675d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/213a40fe-a143-46c9-b383-83c3fc31675d?source=api-prod","cve":"CVE-2025-13456","affectedVersions":"<=3.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/23b6e418-5560-4543-9042-5f338df315e5/shopbuilder","title":"ShopBuilder – Elementor WooCommerce Builder Addons <= 2.1.12 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"23b6e418-5560-4543-9042-5f338df315e5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/23b6e418-5560-4543-9042-5f338df315e5?source=api-prod","cve":"CVE-2024-37520","affectedVersions":"<=2.1.12","severity":"high"},{"advisoryId":"WPSECADV/WF/d0f216fc-7073-42da-a3cc-7452fa9775bd/shopbuilder","title":"ShopBuilder – Elementor WooCommerce Builder Addons <= 2.1.8 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"d0f216fc-7073-42da-a3cc-7452fa9775bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d0f216fc-7073-42da-a3cc-7452fa9775bd?source=api-prod","cve":"CVE-2024-34812","affectedVersions":"<=2.1.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_73696d706c652d626c6f672d63617264811c9dc5_gen.json b/internal/data/assets/plugin_73696d706c652d626c6f672d63617264811c9dc5_gen.json index ae413918..6d01711f 100644 --- a/internal/data/assets/plugin_73696d706c652d626c6f672d63617264811c9dc5_gen.json +++ b/internal/data/assets/plugin_73696d706c652d626c6f672d63617264811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/36cec19a-4631-4ada-b37a-f4b2dc264096/simple-blog-card","title":"Simple Blog Card <= 1.31 - Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"36cec19a-4631-4ada-b37a-f4b2dc264096"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/36cec19a-4631-4ada-b37a-f4b2dc264096?source=api-prod","cve":"CVE-2023-4036","affectedVersions":"<1.32","severity":"medium"},{"advisoryId":"WPSECADV/WF/78f6d878-6ba8-4d80-9c9b-1a363d6aaed5/simple-blog-card","title":"Simple Blog Card <= 1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"78f6d878-6ba8-4d80-9c9b-1a363d6aaed5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/78f6d878-6ba8-4d80-9c9b-1a363d6aaed5?source=api-prod","cve":"CVE-2023-4035","affectedVersions":"<=1.30","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/36cec19a-4631-4ada-b37a-f4b2dc264096/simple-blog-card","title":"Simple Blog Card <= 1.31 - Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"36cec19a-4631-4ada-b37a-f4b2dc264096"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/36cec19a-4631-4ada-b37a-f4b2dc264096?source=api-prod","cve":"CVE-2023-4036","affectedVersions":"<1.32","severity":"medium"},{"advisoryId":"WPSECADV/WF/78f6d878-6ba8-4d80-9c9b-1a363d6aaed5/simple-blog-card","title":"Simple Blog Card <= 1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"78f6d878-6ba8-4d80-9c9b-1a363d6aaed5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/78f6d878-6ba8-4d80-9c9b-1a363d6aaed5?source=api-prod","cve":"CVE-2023-4035","affectedVersions":"<=1.30","severity":"medium"},{"advisoryId":"WPSECADV/WF/b4aa1dce-de3d-4049-a24d-cadb59912ad1/simple-blog-card","title":"Simple Blog Card <= 2.37 - Authenticated (Contributor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"b4aa1dce-de3d-4049-a24d-cadb59912ad1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b4aa1dce-de3d-4049-a24d-cadb59912ad1?source=api-prod","cve":"CVE-2026-32357","affectedVersions":"<=2.37","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_73696d706c652d686973746f7279811c9dc5_gen.json b/internal/data/assets/plugin_73696d706c652d686973746f7279811c9dc5_gen.json index 9b45cd51..f15cd16a 100644 --- a/internal/data/assets/plugin_73696d706c652d686973746f7279811c9dc5_gen.json +++ b/internal/data/assets/plugin_73696d706c652d686973746f7279811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/62e01d59-e649-4b84-993b-9faf28a24274/simple-history","title":"Simple History Plugin < 2.7.5 - Sensitive Information Disclosure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-07-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"62e01d59-e649-4b84-993b-9faf28a24274"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62e01d59-e649-4b84-993b-9faf28a24274?source=api-prod","affectedVersions":"<=2.7.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/8f1e6f04-04d4-4484-86bd-28df6388a953/simple-history","title":"Simple History <= 3.3.1 - Authenticated (Subscriber+) CSV Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"8f1e6f04-04d4-4484-86bd-28df6388a953"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8f1e6f04-04d4-4484-86bd-28df6388a953?source=api-prod","cve":"CVE-2022-45350","affectedVersions":"<=3.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6364415-da02-4236-b635-d8fbd27faa33/simple-history","title":"Simple History <= 5.8.1 - Authenticated (Administrator+) Sensitive Information Exposure via Detective Mode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-05 21:58:10","sources":[{"name":"Wordfence","remoteId":"b6364415-da02-4236-b635-d8fbd27faa33"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6364415-da02-4236-b635-d8fbd27faa33?source=api-prod","cve":"CVE-2025-5760","affectedVersions":"<=5.8.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f30af3c4-82be-40d5-be9f-82631b8f3ee2/simple-history","title":"Simple History <= 1.0.7 - Sensitive Information Disclosure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"f30af3c4-82be-40d5-be9f-82631b8f3ee2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f30af3c4-82be-40d5-be9f-82631b8f3ee2?source=api-prod","affectedVersions":"<=1.0.7","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/62e01d59-e649-4b84-993b-9faf28a24274/simple-history","title":"Simple History Plugin < 2.7.5 - Sensitive Information Disclosure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-07-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"62e01d59-e649-4b84-993b-9faf28a24274"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62e01d59-e649-4b84-993b-9faf28a24274?source=api-prod","affectedVersions":"<=2.7.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/8f1e6f04-04d4-4484-86bd-28df6388a953/simple-history","title":"Simple History <= 3.3.1 - Authenticated (Subscriber+) CSV Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"8f1e6f04-04d4-4484-86bd-28df6388a953"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8f1e6f04-04d4-4484-86bd-28df6388a953?source=api-prod","cve":"CVE-2022-45350","affectedVersions":"<=3.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/b6364415-da02-4236-b635-d8fbd27faa33/simple-history","title":"Simple History <= 5.8.1 - Authenticated (Administrator+) Sensitive Information Exposure via Detective Mode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-05 21:58:10","sources":[{"name":"Wordfence","remoteId":"b6364415-da02-4236-b635-d8fbd27faa33"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6364415-da02-4236-b635-d8fbd27faa33?source=api-prod","cve":"CVE-2025-5760","affectedVersions":"<=5.8.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/f30af3c4-82be-40d5-be9f-82631b8f3ee2/simple-history","title":"Simple History <= 1.0.7 - Sensitive Information Disclosure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2014-08-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"f30af3c4-82be-40d5-be9f-82631b8f3ee2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f30af3c4-82be-40d5-be9f-82631b8f3ee2?source=api-prod","affectedVersions":"<=1.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/fbb7624c-848f-485b-b4df-866ebf45d3a0/simple-history","title":"Simple History <= 5.24.0 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"fbb7624c-848f-485b-b4df-866ebf45d3a0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fbb7624c-848f-485b-b4df-866ebf45d3a0?source=api-prod","cve":"CVE-2026-39473","affectedVersions":"<=5.24.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_73696d706c792d67616c6c6572792d626c6f636b811c9dc5_gen.json b/internal/data/assets/plugin_73696d706c792d67616c6c6572792d626c6f636b811c9dc5_gen.json index 856660c7..e2604347 100644 --- a/internal/data/assets/plugin_73696d706c792d67616c6c6572792d626c6f636b811c9dc5_gen.json +++ b/internal/data/assets/plugin_73696d706c792d67616c6c6572792d626c6f636b811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/38af4b11-c36a-441e-b49c-c3ad9ddfd210/simply-gallery-block","title":"Gallery Blocks with Lightbox <= 3.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"38af4b11-c36a-441e-b49c-c3ad9ddfd210"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/38af4b11-c36a-441e-b49c-c3ad9ddfd210?source=api-prod","cve":"CVE-2025-32176","affectedVersions":"<=3.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42/simply-gallery-block","title":"Freemius SDK <= 2.4.2 - Missing Authorization Checks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"39fb0499-9ab4-4a2f-b0db-ece86bcf4d42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=api-prod","cve":"CVE-2022-4974","affectedVersions":"<2.3.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/3e7bd708-2e82-4fef-85f2-bf4f56f66bc4/simply-gallery-block","title":"Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via galleryID and className Parameters\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-27 20:19:59","sources":[{"name":"Wordfence","remoteId":"3e7bd708-2e82-4fef-85f2-bf4f56f66bc4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3e7bd708-2e82-4fef-85f2-bf4f56f66bc4?source=api-prod","cve":"CVE-2024-5424","affectedVersions":"<=3.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/5253fe2b-040b-417c-b257-0cb59ee5aa6e/simply-gallery-block","title":"Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"5253fe2b-040b-417c-b257-0cb59ee5aa6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5253fe2b-040b-417c-b257-0cb59ee5aa6e?source=api-prod","cve":"CVE-2023-33999","affectedVersions":">=1.8.4,<=3.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/5de488a2-72d6-4eeb-9b92-7f5bea1ee4ff/simply-gallery-block","title":"Gallery Blocks with Lightbox <= 2.2.0 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-08-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5de488a2-72d6-4eeb-9b92-7f5bea1ee4ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5de488a2-72d6-4eeb-9b92-7f5bea1ee4ff?source=api-prod","cve":"CVE-2021-24667","affectedVersions":"<2.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/60ab0311-888c-46ae-98fe-9e7d4dfe13bf/simply-gallery-block","title":"Gallery Blocks with Lightbox <= 3.3.0 - Missing Authorization to Authenticated (Contributor+) Plugin Settings Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-12 15:46:53","sources":[{"name":"Wordfence","remoteId":"60ab0311-888c-46ae-98fe-9e7d4dfe13bf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/60ab0311-888c-46ae-98fe-9e7d4dfe13bf?source=api-prod","cve":"CVE-2025-14288","affectedVersions":"<=3.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/7561bce2-bd70-4da3-bbf0-318e59cd1852/simply-gallery-block","title":"Gallery Blocks with Lightbox <= 3.0.7 - Missing Authorization in pgc_sgb_action_wizard\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"7561bce2-bd70-4da3-bbf0-318e59cd1852"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7561bce2-bd70-4da3-bbf0-318e59cd1852?source=api-prod","cve":"CVE-2023-0441","affectedVersions":"<=3.0.7","severity":"high"},{"advisoryId":"WPSECADV/WF/89bd70b2-0b5f-4edb-890b-d291bdb8a851/simply-gallery-block","title":"Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery <= 3.2.4.2 - Authenticated (Editor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-21 17:21:58","sources":[{"name":"Wordfence","remoteId":"89bd70b2-0b5f-4edb-890b-d291bdb8a851"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/89bd70b2-0b5f-4edb-890b-d291bdb8a851?source=api-prod","cve":"CVE-2024-10034","affectedVersions":"<=3.2.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9ebd4586-bddc-4669-957b-2bab7a35adee/simply-gallery-block","title":"SimpLy Gallery <= 3.3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"9ebd4586-bddc-4669-957b-2bab7a35adee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9ebd4586-bddc-4669-957b-2bab7a35adee?source=api-prod","cve":"CVE-2025-63052","affectedVersions":"<=3.3.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/d694491c-c0f5-4418-805a-db792ea4f712/simply-gallery-block","title":"Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-30 17:17:30","sources":[{"name":"Wordfence","remoteId":"d694491c-c0f5-4418-805a-db792ea4f712"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d694491c-c0f5-4418-805a-db792ea4f712?source=api-prod","cve":"CVE-2024-13362","affectedVersions":"<=3.2.4.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/244f087a-ddc6-4f48-812d-3fed9e1536a0/simply-gallery-block","title":"Mixed Media Gallery Blocks <= 3.3.2 - Authenticated (Contributor+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"244f087a-ddc6-4f48-812d-3fed9e1536a0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/244f087a-ddc6-4f48-812d-3fed9e1536a0?source=api-prod","cve":"CVE-2026-25345","affectedVersions":"<=3.3.2","severity":"high"},{"advisoryId":"WPSECADV/WF/38af4b11-c36a-441e-b49c-c3ad9ddfd210/simply-gallery-block","title":"Gallery Blocks with Lightbox <= 3.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"38af4b11-c36a-441e-b49c-c3ad9ddfd210"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/38af4b11-c36a-441e-b49c-c3ad9ddfd210?source=api-prod","cve":"CVE-2025-32176","affectedVersions":"<=3.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42/simply-gallery-block","title":"Freemius SDK <= 2.4.2 - Missing Authorization Checks\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-03-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"39fb0499-9ab4-4a2f-b0db-ece86bcf4d42"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=api-prod","cve":"CVE-2022-4974","affectedVersions":"<2.3.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/3e7bd708-2e82-4fef-85f2-bf4f56f66bc4/simply-gallery-block","title":"Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via galleryID and className Parameters\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-27 20:19:59","sources":[{"name":"Wordfence","remoteId":"3e7bd708-2e82-4fef-85f2-bf4f56f66bc4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3e7bd708-2e82-4fef-85f2-bf4f56f66bc4?source=api-prod","cve":"CVE-2024-5424","affectedVersions":"<=3.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/5253fe2b-040b-417c-b257-0cb59ee5aa6e/simply-gallery-block","title":"Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"5253fe2b-040b-417c-b257-0cb59ee5aa6e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5253fe2b-040b-417c-b257-0cb59ee5aa6e?source=api-prod","cve":"CVE-2023-33999","affectedVersions":">=1.8.4,<=3.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/5de488a2-72d6-4eeb-9b92-7f5bea1ee4ff/simply-gallery-block","title":"Gallery Blocks with Lightbox <= 2.2.0 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-08-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5de488a2-72d6-4eeb-9b92-7f5bea1ee4ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5de488a2-72d6-4eeb-9b92-7f5bea1ee4ff?source=api-prod","cve":"CVE-2021-24667","affectedVersions":"<2.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/60ab0311-888c-46ae-98fe-9e7d4dfe13bf/simply-gallery-block","title":"Gallery Blocks with Lightbox <= 3.3.0 - Missing Authorization to Authenticated (Contributor+) Plugin Settings Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-12 15:46:53","sources":[{"name":"Wordfence","remoteId":"60ab0311-888c-46ae-98fe-9e7d4dfe13bf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/60ab0311-888c-46ae-98fe-9e7d4dfe13bf?source=api-prod","cve":"CVE-2025-14288","affectedVersions":"<=3.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/7561bce2-bd70-4da3-bbf0-318e59cd1852/simply-gallery-block","title":"Gallery Blocks with Lightbox <= 3.0.7 - Missing Authorization in pgc_sgb_action_wizard\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"7561bce2-bd70-4da3-bbf0-318e59cd1852"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7561bce2-bd70-4da3-bbf0-318e59cd1852?source=api-prod","cve":"CVE-2023-0441","affectedVersions":"<=3.0.7","severity":"high"},{"advisoryId":"WPSECADV/WF/89bd70b2-0b5f-4edb-890b-d291bdb8a851/simply-gallery-block","title":"Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery <= 3.2.4.2 - Authenticated (Editor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-21 17:21:58","sources":[{"name":"Wordfence","remoteId":"89bd70b2-0b5f-4edb-890b-d291bdb8a851"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/89bd70b2-0b5f-4edb-890b-d291bdb8a851?source=api-prod","cve":"CVE-2024-10034","affectedVersions":"<=3.2.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9ebd4586-bddc-4669-957b-2bab7a35adee/simply-gallery-block","title":"SimpLy Gallery <= 3.3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"9ebd4586-bddc-4669-957b-2bab7a35adee"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9ebd4586-bddc-4669-957b-2bab7a35adee?source=api-prod","cve":"CVE-2025-63052","affectedVersions":"<=3.3.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/d694491c-c0f5-4418-805a-db792ea4f712/simply-gallery-block","title":"Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-30 17:17:30","sources":[{"name":"Wordfence","remoteId":"d694491c-c0f5-4418-805a-db792ea4f712"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d694491c-c0f5-4418-805a-db792ea4f712?source=api-prod","cve":"CVE-2024-13362","affectedVersions":"<=3.2.4.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_736c6963657770811c9dc5_gen.json b/internal/data/assets/plugin_736c6963657770811c9dc5_gen.json index 33737946..7ffe89e3 100644 --- a/internal/data/assets/plugin_736c6963657770811c9dc5_gen.json +++ b/internal/data/assets/plugin_736c6963657770811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/45dd22d4-9a51-4569-a756-1f1a5f8626c1/slicewp","title":"WordPress Affiliates Plugin — SliceWP Affiliates <= 1.1.20 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"45dd22d4-9a51-4569-a756-1f1a5f8626c1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/45dd22d4-9a51-4569-a756-1f1a5f8626c1?source=api-prod","cve":"CVE-2024-8714","affectedVersions":"<=1.1.20","severity":"medium"},{"advisoryId":"WPSECADV/WF/73aad911-531b-4118-9d39-27cbae75db01/slicewp","title":"Affiliate Program Suite — SliceWP Affiliates <= 1.1.23 - Cross-Site Request Forgery to Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-17 21:10:02","sources":[{"name":"Wordfence","remoteId":"73aad911-531b-4118-9d39-27cbae75db01"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/73aad911-531b-4118-9d39-27cbae75db01?source=api-prod","cve":"CVE-2024-12454","affectedVersions":"<=1.1.23","severity":"medium"},{"advisoryId":"WPSECADV/WF/9f79fe15-65a1-44ab-a43e-1410ce1f1d77/slicewp","title":"WordPress Affiliates Plugin — SliceWP Affiliates <= 1.1.10 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"9f79fe15-65a1-44ab-a43e-1410ce1f1d77"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9f79fe15-65a1-44ab-a43e-1410ce1f1d77?source=api-prod","cve":"CVE-2024-34413","affectedVersions":"<=1.1.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/b33fd509-1cc3-48de-bd4a-7c9749da1cf8/slicewp","title":"SliceWP <= 1.1.18 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"b33fd509-1cc3-48de-bd4a-7c9749da1cf8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b33fd509-1cc3-48de-bd4a-7c9749da1cf8?source=api-prod","cve":"CVE-2024-47388","affectedVersions":"<=1.1.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/d8461a10-44e1-437a-ad6c-7107aeb66124/slicewp","title":"WordPress Affiliates Plugin — SliceWP Affiliates <= 1.0.45 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-08-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"d8461a10-44e1-437a-ad6c-7107aeb66124"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d8461a10-44e1-437a-ad6c-7107aeb66124?source=api-prod","affectedVersions":"<=1.0.45","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/45dd22d4-9a51-4569-a756-1f1a5f8626c1/slicewp","title":"WordPress Affiliates Plugin — SliceWP Affiliates <= 1.1.20 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"45dd22d4-9a51-4569-a756-1f1a5f8626c1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/45dd22d4-9a51-4569-a756-1f1a5f8626c1?source=api-prod","cve":"CVE-2024-8714","affectedVersions":"<=1.1.20","severity":"medium"},{"advisoryId":"WPSECADV/WF/5b9e92ea-49fc-420d-9d0e-29bcf78843bd/slicewp","title":"Affiliate Program Suite <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via slicewp_affiliate_url Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-05 17:50:49","sources":[{"name":"Wordfence","remoteId":"5b9e92ea-49fc-420d-9d0e-29bcf78843bd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5b9e92ea-49fc-420d-9d0e-29bcf78843bd?source=api-prod","cve":"CVE-2026-6672","affectedVersions":"<=1.2.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/73aad911-531b-4118-9d39-27cbae75db01/slicewp","title":"Affiliate Program Suite — SliceWP Affiliates <= 1.1.23 - Cross-Site Request Forgery to Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-17 21:10:02","sources":[{"name":"Wordfence","remoteId":"73aad911-531b-4118-9d39-27cbae75db01"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/73aad911-531b-4118-9d39-27cbae75db01?source=api-prod","cve":"CVE-2024-12454","affectedVersions":"<=1.1.23","severity":"medium"},{"advisoryId":"WPSECADV/WF/9f79fe15-65a1-44ab-a43e-1410ce1f1d77/slicewp","title":"WordPress Affiliates Plugin — SliceWP Affiliates <= 1.1.10 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"9f79fe15-65a1-44ab-a43e-1410ce1f1d77"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9f79fe15-65a1-44ab-a43e-1410ce1f1d77?source=api-prod","cve":"CVE-2024-34413","affectedVersions":"<=1.1.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/b33fd509-1cc3-48de-bd4a-7c9749da1cf8/slicewp","title":"SliceWP <= 1.1.18 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"b33fd509-1cc3-48de-bd4a-7c9749da1cf8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b33fd509-1cc3-48de-bd4a-7c9749da1cf8?source=api-prod","cve":"CVE-2024-47388","affectedVersions":"<=1.1.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/d8461a10-44e1-437a-ad6c-7107aeb66124/slicewp","title":"WordPress Affiliates Plugin — SliceWP Affiliates <= 1.0.45 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-08-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"d8461a10-44e1-437a-ad6c-7107aeb66124"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d8461a10-44e1-437a-ad6c-7107aeb66124?source=api-prod","affectedVersions":"<=1.0.45","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_73717565657a65811c9dc5_gen.json b/internal/data/assets/plugin_73717565657a65811c9dc5_gen.json index 324c9aa0..9f04143d 100644 --- a/internal/data/assets/plugin_73717565657a65811c9dc5_gen.json +++ b/internal/data/assets/plugin_73717565657a65811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/30beb916-764e-48fd-bcd4-f772b9d92133/squeeze","title":"Squeeze <= 1.6 - Authenticated (Admin+) Full Path Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"30beb916-764e-48fd-bcd4-f772b9d92133"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/30beb916-764e-48fd-bcd4-f772b9d92133?source=api-prod","cve":"CVE-2025-31003","affectedVersions":"<=1.6","severity":"low"},{"advisoryId":"WPSECADV/WF/70a14d11-6525-465c-8fc6-0920af748027/squeeze","title":"Squeeze <= 1.4 - Authenticated (Admin+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"70a14d11-6525-465c-8fc6-0920af748027"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/70a14d11-6525-465c-8fc6-0920af748027?source=api-prod","cve":"CVE-2024-35767","affectedVersions":"<=1.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/a815496c-cd68-4ab4-a3bd-5fdcf59d02a6/squeeze","title":"Squeeze <= 1.6 - Authenticated (Admin+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"a815496c-cd68-4ab4-a3bd-5fdcf59d02a6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a815496c-cd68-4ab4-a3bd-5fdcf59d02a6?source=api-prod","cve":"CVE-2025-31002","affectedVersions":"<=1.6","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/30beb916-764e-48fd-bcd4-f772b9d92133/squeeze","title":"Squeeze <= 1.6 - Authenticated (Admin+) Full Path Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"30beb916-764e-48fd-bcd4-f772b9d92133"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/30beb916-764e-48fd-bcd4-f772b9d92133?source=api-prod","cve":"CVE-2025-31003","affectedVersions":"<=1.6","severity":"low"},{"advisoryId":"WPSECADV/WF/694b05bf-7779-4365-811e-029408922ec9/squeeze","title":"Squeeze <= 1.7.7 - Authenticated (Subscriber+) Directory Traversal\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"694b05bf-7779-4365-811e-029408922ec9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/694b05bf-7779-4365-811e-029408922ec9?source=api-prod","cve":"CVE-2026-32415","affectedVersions":"<=1.7.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/70a14d11-6525-465c-8fc6-0920af748027/squeeze","title":"Squeeze <= 1.4 - Authenticated (Admin+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"70a14d11-6525-465c-8fc6-0920af748027"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/70a14d11-6525-465c-8fc6-0920af748027?source=api-prod","cve":"CVE-2024-35767","affectedVersions":"<=1.4","severity":"critical"},{"advisoryId":"WPSECADV/WF/a815496c-cd68-4ab4-a3bd-5fdcf59d02a6/squeeze","title":"Squeeze <= 1.6 - Authenticated (Admin+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"a815496c-cd68-4ab4-a3bd-5fdcf59d02a6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a815496c-cd68-4ab4-a3bd-5fdcf59d02a6?source=api-prod","cve":"CVE-2025-31002","affectedVersions":"<=1.6","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_74642d636f6d706f736572811c9dc5_gen.json b/internal/data/assets/plugin_74642d636f6d706f736572811c9dc5_gen.json index 75733cea..3630c730 100644 --- a/internal/data/assets/plugin_74642d636f6d706f736572811c9dc5_gen.json +++ b/internal/data/assets/plugin_74642d636f6d706f736572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/199d3a1f-bfde-4081-bb68-ebb6f9d360b2/td-composer","title":"tagDiv Composer < 4.4 - Cross-Site Request Forgery to Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"199d3a1f-bfde-4081-bb68-ebb6f9d360b2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/199d3a1f-bfde-4081-bb68-ebb6f9d360b2?source=api-prod","cve":"CVE-2023-39166","affectedVersions":"<4.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/2aaa8c34-cf7b-4630-adc8-cbb534deff89/td-composer","title":"tagDiv Composer <= 5.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 19:53:56","sources":[{"name":"Wordfence","remoteId":"2aaa8c34-cf7b-4630-adc8-cbb534deff89"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2aaa8c34-cf7b-4630-adc8-cbb534deff89?source=api-prod","cve":"CVE-2025-1705","affectedVersions":"<=5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ab4ac58-ea16-4b3b-8646-afe10f331f0c/td-composer","title":"tagDiv Composer <= 5.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"2ab4ac58-ea16-4b3b-8646-afe10f331f0c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ab4ac58-ea16-4b3b-8646-afe10f331f0c?source=api-prod","cve":"CVE-2025-62030","affectedVersions":"<=5.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/2bd6b66d-f33e-4287-850b-a199de72f6ad/td-composer","title":"tagDiv Composer <= 5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-01 14:50:00","sources":[{"name":"Wordfence","remoteId":"2bd6b66d-f33e-4287-850b-a199de72f6ad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2bd6b66d-f33e-4287-850b-a199de72f6ad?source=api-prod","cve":"CVE-2025-3510","affectedVersions":"<=5.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/372f4908-8796-4a52-8346-bd0eb1e41adc/td-composer","title":"tagDiv Composer < 4.0 - Reflected Cross-Site Scripting via ‘td_video_url’\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"372f4908-8796-4a52-8346-bd0eb1e41adc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/372f4908-8796-4a52-8346-bd0eb1e41adc?source=api-prod","cve":"CVE-2023-1596","affectedVersions":"<4.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/3861f675-1a26-4947-91ef-8ab04646704f/td-composer","title":"tagDiv Composer <= 4.1 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"3861f675-1a26-4947-91ef-8ab04646704f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3861f675-1a26-4947-91ef-8ab04646704f?source=api-prod","cve":"CVE-2023-3170","affectedVersions":"<=4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/4124003c-4864-48f1-acba-9a613d9c99ae/td-composer","title":"TagDiv Composer <= 5.3 - Unauthenticated Arbitrary PHP Object Instantiation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-03 16:22:47","sources":[{"name":"Wordfence","remoteId":"4124003c-4864-48f1-acba-9a613d9c99ae"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4124003c-4864-48f1-acba-9a613d9c99ae?source=api-prod","cve":"CVE-2024-13645","affectedVersions":"<=5.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/41ef545a-7de1-406c-8686-57216e697a1b/td-composer","title":"tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'account_id' and 'account_username'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 16:33:57","sources":[{"name":"Wordfence","remoteId":"41ef545a-7de1-406c-8686-57216e697a1b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/41ef545a-7de1-406c-8686-57216e697a1b?source=api-prod","cve":"CVE-2025-2804","affectedVersions":"<=5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/466fc6f3-7b2d-4975-a838-16e27bc9f9b5/td-composer","title":"tagDiv Composer <= 4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via button Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"466fc6f3-7b2d-4975-a838-16e27bc9f9b5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/466fc6f3-7b2d-4975-a838-16e27bc9f9b5?source=api-prod","cve":"CVE-2024-3888","affectedVersions":"<=4.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/4c2a88c3-5c11-4b42-b8f8-aafecf6c4c74/td-composer","title":"tagDiv Composer <= 4.8 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"4c2a88c3-5c11-4b42-b8f8-aafecf6c4c74"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4c2a88c3-5c11-4b42-b8f8-aafecf6c4c74?source=api-prod","cve":"CVE-2024-3814","affectedVersions":"<=4.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/52bd9946-dccc-427a-9abd-0b7153e7484f/td-composer","title":"tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'data'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"52bd9946-dccc-427a-9abd-0b7153e7484f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/52bd9946-dccc-427a-9abd-0b7153e7484f?source=api-prod","cve":"CVE-2025-2806","affectedVersions":"<=5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/5fb3a347-e124-484b-9eff-281a10c25a5c/td-composer","title":"tagDiv Composer <= 5.4.1 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"5fb3a347-e124-484b-9eff-281a10c25a5c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5fb3a347-e124-484b-9eff-281a10c25a5c?source=api-prod","cve":"CVE-2025-62031","affectedVersions":"<=5.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/6998cf4c-6086-402b-a95f-ee6a4980dffb/td-composer","title":"tagDiv Composer <= 4.1 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"6998cf4c-6086-402b-a95f-ee6a4980dffb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6998cf4c-6086-402b-a95f-ee6a4980dffb?source=api-prod","cve":"CVE-2023-3169","affectedVersions":"<=4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/87b7bc4a-4d2f-4bcb-a9d5-72e31c95c09e/td-composer","title":"tagDiv Composer <= 4.8 - Authenticated (Contributor+) Local File Inclusion via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"87b7bc4a-4d2f-4bcb-a9d5-72e31c95c09e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/87b7bc4a-4d2f-4bcb-a9d5-72e31c95c09e?source=api-prod","cve":"CVE-2024-3813","affectedVersions":"<=4.8","severity":"high"},{"advisoryId":"WPSECADV/WF/9cc1627c-2eb7-4817-a7ce-eaa9097fd5f8/td-composer","title":"tagDiv Composer <= 5.4.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"9cc1627c-2eb7-4817-a7ce-eaa9097fd5f8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9cc1627c-2eb7-4817-a7ce-eaa9097fd5f8?source=api-prod","cve":"CVE-2025-50001","affectedVersions":"<=5.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/b8347b4e-a5ba-49c5-9ae6-690a1a5c9aac/td-composer","title":"tagDiv Composer < 3.5 - Unauthorized Account Access and Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"b8347b4e-a5ba-49c5-9ae6-690a1a5c9aac"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b8347b4e-a5ba-49c5-9ae6-690a1a5c9aac?source=api-prod","cve":"CVE-2022-3477","affectedVersions":"<3.5","severity":"critical"},{"advisoryId":"WPSECADV/WF/db95415a-5354-498b-8368-58c47d9948de/td-composer","title":"tagDiv Composer <= 5.0 - Reflected Cross-Site Scripting via envato_code[]\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"db95415a-5354-498b-8368-58c47d9948de"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/db95415a-5354-498b-8368-58c47d9948de?source=api-prod","cve":"CVE-2024-5212","affectedVersions":"<=5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e1012821-dae9-4fed-9f18-90eef50114ac/td-composer","title":"tagDiv Composer <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"e1012821-dae9-4fed-9f18-90eef50114ac"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e1012821-dae9-4fed-9f18-90eef50114ac?source=api-prod","cve":"CVE-2025-50005","affectedVersions":"<=5.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/ed9db9c1-c6b5-459e-9820-ec4ee47b244e/td-composer","title":"tagDiv Composer <= 5.0 - Reflected Cross-Site Scripting via envato_code[]\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"ed9db9c1-c6b5-459e-9820-ec4ee47b244e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ed9db9c1-c6b5-459e-9820-ec4ee47b244e?source=api-prod","cve":"CVE-2024-3886","affectedVersions":"<=5.0","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/1196b20e-5fa4-44bf-8cdc-35e1c0db0c74/td-composer","title":"tagDiv Composer <= 5.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1196b20e-5fa4-44bf-8cdc-35e1c0db0c74"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1196b20e-5fa4-44bf-8cdc-35e1c0db0c74?source=api-prod","cve":"CVE-2026-39692","affectedVersions":"<=5.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/199d3a1f-bfde-4081-bb68-ebb6f9d360b2/td-composer","title":"tagDiv Composer < 4.4 - Cross-Site Request Forgery to Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"199d3a1f-bfde-4081-bb68-ebb6f9d360b2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/199d3a1f-bfde-4081-bb68-ebb6f9d360b2?source=api-prod","cve":"CVE-2023-39166","affectedVersions":"<4.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/2aaa8c34-cf7b-4630-adc8-cbb534deff89/td-composer","title":"tagDiv Composer <= 5.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 19:53:56","sources":[{"name":"Wordfence","remoteId":"2aaa8c34-cf7b-4630-adc8-cbb534deff89"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2aaa8c34-cf7b-4630-adc8-cbb534deff89?source=api-prod","cve":"CVE-2025-1705","affectedVersions":"<=5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ab4ac58-ea16-4b3b-8646-afe10f331f0c/td-composer","title":"tagDiv Composer <= 5.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"2ab4ac58-ea16-4b3b-8646-afe10f331f0c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ab4ac58-ea16-4b3b-8646-afe10f331f0c?source=api-prod","cve":"CVE-2025-62030","affectedVersions":"<=5.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/2bd6b66d-f33e-4287-850b-a199de72f6ad/td-composer","title":"tagDiv Composer <= 5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-01 14:50:00","sources":[{"name":"Wordfence","remoteId":"2bd6b66d-f33e-4287-850b-a199de72f6ad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2bd6b66d-f33e-4287-850b-a199de72f6ad?source=api-prod","cve":"CVE-2025-3510","affectedVersions":"<=5.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/372f4908-8796-4a52-8346-bd0eb1e41adc/td-composer","title":"tagDiv Composer < 4.0 - Reflected Cross-Site Scripting via ‘td_video_url’\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"372f4908-8796-4a52-8346-bd0eb1e41adc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/372f4908-8796-4a52-8346-bd0eb1e41adc?source=api-prod","cve":"CVE-2023-1596","affectedVersions":"<4.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/3861f675-1a26-4947-91ef-8ab04646704f/td-composer","title":"tagDiv Composer <= 4.1 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"3861f675-1a26-4947-91ef-8ab04646704f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3861f675-1a26-4947-91ef-8ab04646704f?source=api-prod","cve":"CVE-2023-3170","affectedVersions":"<=4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/4124003c-4864-48f1-acba-9a613d9c99ae/td-composer","title":"TagDiv Composer <= 5.3 - Unauthenticated Arbitrary PHP Object Instantiation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-03 16:22:47","sources":[{"name":"Wordfence","remoteId":"4124003c-4864-48f1-acba-9a613d9c99ae"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4124003c-4864-48f1-acba-9a613d9c99ae?source=api-prod","cve":"CVE-2024-13645","affectedVersions":"<=5.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/41ef545a-7de1-406c-8686-57216e697a1b/td-composer","title":"tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'account_id' and 'account_username'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 16:33:57","sources":[{"name":"Wordfence","remoteId":"41ef545a-7de1-406c-8686-57216e697a1b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/41ef545a-7de1-406c-8686-57216e697a1b?source=api-prod","cve":"CVE-2025-2804","affectedVersions":"<=5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/466fc6f3-7b2d-4975-a838-16e27bc9f9b5/td-composer","title":"tagDiv Composer <= 4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via button Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-06-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"466fc6f3-7b2d-4975-a838-16e27bc9f9b5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/466fc6f3-7b2d-4975-a838-16e27bc9f9b5?source=api-prod","cve":"CVE-2024-3888","affectedVersions":"<=4.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/4c2a88c3-5c11-4b42-b8f8-aafecf6c4c74/td-composer","title":"tagDiv Composer <= 4.8 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"4c2a88c3-5c11-4b42-b8f8-aafecf6c4c74"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4c2a88c3-5c11-4b42-b8f8-aafecf6c4c74?source=api-prod","cve":"CVE-2024-3814","affectedVersions":"<=4.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/52bd9946-dccc-427a-9abd-0b7153e7484f/td-composer","title":"tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'data'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"52bd9946-dccc-427a-9abd-0b7153e7484f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/52bd9946-dccc-427a-9abd-0b7153e7484f?source=api-prod","cve":"CVE-2025-2806","affectedVersions":"<=5.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/5af46aef-9c1d-46f2-987d-62c2d668bdad/td-composer","title":"tagDiv Composer <= 5.4.3 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"5af46aef-9c1d-46f2-987d-62c2d668bdad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5af46aef-9c1d-46f2-987d-62c2d668bdad?source=api-prod","cve":"CVE-2026-39712","affectedVersions":"<=5.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/5fb3a347-e124-484b-9eff-281a10c25a5c/td-composer","title":"tagDiv Composer <= 5.4.1 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"5fb3a347-e124-484b-9eff-281a10c25a5c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5fb3a347-e124-484b-9eff-281a10c25a5c?source=api-prod","cve":"CVE-2025-62031","affectedVersions":"<=5.4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/6998cf4c-6086-402b-a95f-ee6a4980dffb/td-composer","title":"tagDiv Composer <= 4.1 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"6998cf4c-6086-402b-a95f-ee6a4980dffb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6998cf4c-6086-402b-a95f-ee6a4980dffb?source=api-prod","cve":"CVE-2023-3169","affectedVersions":"<=4.1","severity":"high"},{"advisoryId":"WPSECADV/WF/87b7bc4a-4d2f-4bcb-a9d5-72e31c95c09e/td-composer","title":"tagDiv Composer <= 4.8 - Authenticated (Contributor+) Local File Inclusion via Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"87b7bc4a-4d2f-4bcb-a9d5-72e31c95c09e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/87b7bc4a-4d2f-4bcb-a9d5-72e31c95c09e?source=api-prod","cve":"CVE-2024-3813","affectedVersions":"<=4.8","severity":"high"},{"advisoryId":"WPSECADV/WF/9cc1627c-2eb7-4817-a7ce-eaa9097fd5f8/td-composer","title":"tagDiv Composer <= 5.4.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"9cc1627c-2eb7-4817-a7ce-eaa9097fd5f8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9cc1627c-2eb7-4817-a7ce-eaa9097fd5f8?source=api-prod","cve":"CVE-2025-50001","affectedVersions":"<=5.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/b8347b4e-a5ba-49c5-9ae6-690a1a5c9aac/td-composer","title":"tagDiv Composer < 3.5 - Unauthorized Account Access and Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"b8347b4e-a5ba-49c5-9ae6-690a1a5c9aac"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b8347b4e-a5ba-49c5-9ae6-690a1a5c9aac?source=api-prod","cve":"CVE-2022-3477","affectedVersions":"<3.5","severity":"critical"},{"advisoryId":"WPSECADV/WF/db95415a-5354-498b-8368-58c47d9948de/td-composer","title":"tagDiv Composer <= 5.0 - Reflected Cross-Site Scripting via envato_code[]\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"db95415a-5354-498b-8368-58c47d9948de"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/db95415a-5354-498b-8368-58c47d9948de?source=api-prod","cve":"CVE-2024-5212","affectedVersions":"<=5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/e1012821-dae9-4fed-9f18-90eef50114ac/td-composer","title":"tagDiv Composer <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"e1012821-dae9-4fed-9f18-90eef50114ac"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e1012821-dae9-4fed-9f18-90eef50114ac?source=api-prod","cve":"CVE-2025-50005","affectedVersions":"<=5.4.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/ed9db9c1-c6b5-459e-9820-ec4ee47b244e/td-composer","title":"tagDiv Composer <= 5.0 - Reflected Cross-Site Scripting via envato_code[]\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"ed9db9c1-c6b5-459e-9820-ec4ee47b244e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ed9db9c1-c6b5-459e-9820-ec4ee47b244e?source=api-prod","cve":"CVE-2024-3886","affectedVersions":"<=5.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7468652d706c75732d6164646f6e732d666f722d626c6f636b2d656469746f72811c9dc5_gen.json b/internal/data/assets/plugin_7468652d706c75732d6164646f6e732d666f722d626c6f636b2d656469746f72811c9dc5_gen.json index 6eef3a64..834ca32a 100644 --- a/internal/data/assets/plugin_7468652d706c75732d6164646f6e732d666f722d626c6f636b2d656469746f72811c9dc5_gen.json +++ b/internal/data/assets/plugin_7468652d706c75732d6164646f6e732d666f722d626c6f636b2d656469746f72811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/5e31eda3-06f8-44c5-8b05-74283d4d20bb/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 4.6.3 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"5e31eda3-06f8-44c5-8b05-74283d4d20bb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5e31eda3-06f8-44c5-8b05-74283d4d20bb?source=api-prod","cve":"CVE-2026-24377","affectedVersions":"<=4.6.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/79337804-beff-4316-98b3-aacb8416eb52/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"79337804-beff-4316-98b3-aacb8416eb52"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/79337804-beff-4316-98b3-aacb8416eb52?source=api-prod","cve":"CVE-2024-50452","affectedVersions":"<=3.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/7d6c19e2-b280-4937-8f66-eac1da3cd365/the-plus-addons-for-block-editor","title":"The Plus Blocks for Block Editor | Gutenberg <= 3.2.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7d6c19e2-b280-4937-8f66-eac1da3cd365"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7d6c19e2-b280-4937-8f66-eac1da3cd365?source=api-prod","cve":"CVE-2024-33572","affectedVersions":"<=3.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/819580a0-75ea-475d-b6b8-47d57e5c3d05/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 4.0.7 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"819580a0-75ea-475d-b6b8-47d57e5c3d05"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/819580a0-75ea-475d-b6b8-47d57e5c3d05?source=api-prod","cve":"CVE-2024-56294","affectedVersions":"<=4.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/8c3f1202-886a-471c-9b93-0efbf4282618/the-plus-addons-for-block-editor","title":"The Plus Blocks for Block Editor | Gutenberg <= 3.2.5 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"8c3f1202-886a-471c-9b93-0efbf4282618"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c3f1202-886a-471c-9b93-0efbf4282618?source=api-prod","cve":"CVE-2024-30435","affectedVersions":"<=3.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/adf10688-834c-4922-89a3-0048dde5f210/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"adf10688-834c-4922-89a3-0048dde5f210"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/adf10688-834c-4922-89a3-0048dde5f210?source=api-prod","cve":"CVE-2024-56246","affectedVersions":"<=4.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca9ad8ca-aad1-4950-b540-64ffc4a07c12/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-18 19:56:11","sources":[{"name":"Wordfence","remoteId":"ca9ad8ca-aad1-4950-b540-64ffc4a07c12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca9ad8ca-aad1-4950-b540-64ffc4a07c12?source=api-prod","cve":"CVE-2025-8567","affectedVersions":"<=4.5.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/d99d4b9a-aa09-434d-91a8-7afaa0e8b5db/the-plus-addons-for-block-editor","title":"Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"d99d4b9a-aa09-434d-91a8-7afaa0e8b5db"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d99d4b9a-aa09-434d-91a8-7afaa0e8b5db?source=api-prod","cve":"CVE-2024-5020","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/e04171d6-b905-4633-80ca-427b35d5ead6/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 4.5.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"e04171d6-b905-4633-80ca-427b35d5ead6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e04171d6-b905-4633-80ca-427b35d5ead6?source=api-prod","cve":"CVE-2025-54739","affectedVersions":"<=4.5.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/02220c1d-a7f2-41eb-ac5f-f89d63c54a59/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 4.7.0 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"02220c1d-a7f2-41eb-ac5f-f89d63c54a59"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/02220c1d-a7f2-41eb-ac5f-f89d63c54a59?source=api-prod","cve":"CVE-2026-39516","affectedVersions":"<=4.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/5e31eda3-06f8-44c5-8b05-74283d4d20bb/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 4.6.3 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"5e31eda3-06f8-44c5-8b05-74283d4d20bb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5e31eda3-06f8-44c5-8b05-74283d4d20bb?source=api-prod","cve":"CVE-2026-24377","affectedVersions":"<=4.6.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/79337804-beff-4316-98b3-aacb8416eb52/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"79337804-beff-4316-98b3-aacb8416eb52"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/79337804-beff-4316-98b3-aacb8416eb52?source=api-prod","cve":"CVE-2024-50452","affectedVersions":"<=3.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/7d6c19e2-b280-4937-8f66-eac1da3cd365/the-plus-addons-for-block-editor","title":"The Plus Blocks for Block Editor | Gutenberg <= 3.2.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7d6c19e2-b280-4937-8f66-eac1da3cd365"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7d6c19e2-b280-4937-8f66-eac1da3cd365?source=api-prod","cve":"CVE-2024-33572","affectedVersions":"<=3.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/819580a0-75ea-475d-b6b8-47d57e5c3d05/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 4.0.7 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"819580a0-75ea-475d-b6b8-47d57e5c3d05"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/819580a0-75ea-475d-b6b8-47d57e5c3d05?source=api-prod","cve":"CVE-2024-56294","affectedVersions":"<=4.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/8c3f1202-886a-471c-9b93-0efbf4282618/the-plus-addons-for-block-editor","title":"The Plus Blocks for Block Editor | Gutenberg <= 3.2.5 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"8c3f1202-886a-471c-9b93-0efbf4282618"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c3f1202-886a-471c-9b93-0efbf4282618?source=api-prod","cve":"CVE-2024-30435","affectedVersions":"<=3.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/adf10688-834c-4922-89a3-0048dde5f210/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"adf10688-834c-4922-89a3-0048dde5f210"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/adf10688-834c-4922-89a3-0048dde5f210?source=api-prod","cve":"CVE-2024-56246","affectedVersions":"<=4.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca9ad8ca-aad1-4950-b540-64ffc4a07c12/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-18 19:56:11","sources":[{"name":"Wordfence","remoteId":"ca9ad8ca-aad1-4950-b540-64ffc4a07c12"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca9ad8ca-aad1-4950-b540-64ffc4a07c12?source=api-prod","cve":"CVE-2025-8567","affectedVersions":"<=4.5.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/d99d4b9a-aa09-434d-91a8-7afaa0e8b5db/the-plus-addons-for-block-editor","title":"Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"d99d4b9a-aa09-434d-91a8-7afaa0e8b5db"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d99d4b9a-aa09-434d-91a8-7afaa0e8b5db?source=api-prod","cve":"CVE-2024-5020","affectedVersions":"<=4.3.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/e04171d6-b905-4633-80ca-427b35d5ead6/the-plus-addons-for-block-editor","title":"Nexter Blocks <= 4.5.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"e04171d6-b905-4633-80ca-427b35d5ead6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e04171d6-b905-4633-80ca-427b35d5ead6?source=api-prod","cve":"CVE-2025-54739","affectedVersions":"<=4.5.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7468652d746563682d7472696265811c9dc5_gen.json b/internal/data/assets/plugin_7468652d746563682d7472696265811c9dc5_gen.json index 4765db87..aff1a742 100644 --- a/internal/data/assets/plugin_7468652d746563682d7472696265811c9dc5_gen.json +++ b/internal/data/assets/plugin_7468652d746563682d7472696265811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/470d64e6-9dd5-4069-8b16-ea26a3b9f0e1/the-tech-tribe","title":"The Tribal <= 1.3.3 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"470d64e6-9dd5-4069-8b16-ea26a3b9f0e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/470d64e6-9dd5-4069-8b16-ea26a3b9f0e1?source=api-prod","cve":"CVE-2025-60140","affectedVersions":"<=1.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/67c495dd-ccff-49ff-91cd-40dd66696401/the-tech-tribe","title":"The Tribal <= 1.3.3 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"67c495dd-ccff-49ff-91cd-40dd66696401"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/67c495dd-ccff-49ff-91cd-40dd66696401?source=api-prod","cve":"CVE-2025-60141","affectedVersions":"<=1.3.3","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/293260d1-84a3-4af7-a293-8466624c86cc/the-tech-tribe","title":"The Tribal <= 1.3.4 - Unauthenticated Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"293260d1-84a3-4af7-a293-8466624c86cc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/293260d1-84a3-4af7-a293-8466624c86cc?source=api-prod","cve":"CVE-2026-39709","affectedVersions":"<=1.3.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/470d64e6-9dd5-4069-8b16-ea26a3b9f0e1/the-tech-tribe","title":"The Tribal <= 1.3.3 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"470d64e6-9dd5-4069-8b16-ea26a3b9f0e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/470d64e6-9dd5-4069-8b16-ea26a3b9f0e1?source=api-prod","cve":"CVE-2025-60140","affectedVersions":"<=1.3.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/67c495dd-ccff-49ff-91cd-40dd66696401/the-tech-tribe","title":"The Tribal <= 1.3.3 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"67c495dd-ccff-49ff-91cd-40dd66696401"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/67c495dd-ccff-49ff-91cd-40dd66696401?source=api-prod","cve":"CVE-2025-60141","affectedVersions":"<=1.3.3","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_747572626f2d6d616e61676572811c9dc5_gen.json b/internal/data/assets/plugin_747572626f2d6d616e61676572811c9dc5_gen.json new file mode 100644 index 00000000..5edb0502 --- /dev/null +++ b/internal/data/assets/plugin_747572626f2d6d616e61676572811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/fb5c7875-e531-4ee8-bd19-360cbcfef8ed/turbo-manager","title":"Turbo Manager < 4.0.8 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"fb5c7875-e531-4ee8-bd19-360cbcfef8ed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fb5c7875-e531-4ee8-bd19-360cbcfef8ed?source=api-prod","cve":"CVE-2026-32364","affectedVersions":"<4.0.8","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7475746f722d70726f811c9dc5_gen.json b/internal/data/assets/plugin_7475746f722d70726f811c9dc5_gen.json index cb4ed40c..2ef3c680 100644 --- a/internal/data/assets/plugin_7475746f722d70726f811c9dc5_gen.json +++ b/internal/data/assets/plugin_7475746f722d70726f811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/4b41d134-be9e-469f-b26b-ac30d95db0a3/tutor-pro","title":"Tutor LMS Pro – eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-12 18:27:44","sources":[{"name":"Wordfence","remoteId":"4b41d134-be9e-469f-b26b-ac30d95db0a3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4b41d134-be9e-469f-b26b-ac30d95db0a3?source=api-prod","cve":"CVE-2025-6184","affectedVersions":"<=3.7.0","severity":"high"},{"advisoryId":"WPSECADV/WF/59859583-49e5-4a80-8659-b9ca7ddc089d/tutor-pro","title":"Tutor LMS Pro <= 2.7.0 - Missing Authorization to Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"59859583-49e5-4a80-8659-b9ca7ddc089d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/59859583-49e5-4a80-8659-b9ca7ddc089d?source=api-prod","cve":"CVE-2024-4351","affectedVersions":"<=2.7.0","severity":"high"},{"advisoryId":"WPSECADV/WF/8dc16ba4-3c2e-43e2-82a0-b742276b9640/tutor-pro","title":"Tutor LMS Pro – eLearning and online course solution <= 3.8.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to View/Edit Other Assignments\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-24 17:30:42","sources":[{"name":"Wordfence","remoteId":"8dc16ba4-3c2e-43e2-82a0-b742276b9640"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8dc16ba4-3c2e-43e2-82a0-b742276b9640?source=api-prod","cve":"CVE-2025-6639","affectedVersions":"<=3.8.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/92a120ac-66ae-4678-a87a-e62da885d50b/tutor-pro","title":"Tutor LMS Pro <= 3.9.5 - Authentication Bypass via Social Login\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-09 16:33:12","sources":[{"name":"Wordfence","remoteId":"92a120ac-66ae-4678-a87a-e62da885d50b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/92a120ac-66ae-4678-a87a-e62da885d50b?source=api-prod","cve":"CVE-2026-0953","affectedVersions":"<=3.9.5","severity":"critical"},{"advisoryId":"WPSECADV/WF/942fffb6-2719-4b70-9759-21b2d50002c5/tutor-pro","title":"Tutor LMS Pro <= 2.7.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"942fffb6-2719-4b70-9759-21b2d50002c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/942fffb6-2719-4b70-9759-21b2d50002c5?source=api-prod","cve":"CVE-2024-4222","affectedVersions":"<=2.7.0","severity":"high"},{"advisoryId":"WPSECADV/WF/97fdd2f9-02ad-492c-88d1-1e7bd9c404a5/tutor-pro","title":"Tutor LMS Pro <= 3.9.6 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"97fdd2f9-02ad-492c-88d1-1e7bd9c404a5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/97fdd2f9-02ad-492c-88d1-1e7bd9c404a5?source=api-prod","cve":"CVE-2026-22332","affectedVersions":"<=3.9.6","severity":"high"},{"advisoryId":"WPSECADV/WF/aa5c23ed-7239-40e1-a795-1ae8d4c2d6c8/tutor-pro","title":"Tutor LMS Pro <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"aa5c23ed-7239-40e1-a795-1ae8d4c2d6c8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa5c23ed-7239-40e1-a795-1ae8d4c2d6c8?source=api-prod","cve":"CVE-2024-5784","affectedVersions":"<=2.7.2","severity":"high"},{"advisoryId":"WPSECADV/WF/ad4e5243-e41a-4624-b9cd-47ab79637560/tutor-pro","title":"Tutor LMS Pro <= 3.9.4 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad4e5243-e41a-4624-b9cd-47ab79637560"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad4e5243-e41a-4624-b9cd-47ab79637560?source=api-prod","cve":"CVE-2026-25406","affectedVersions":"<=3.9.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/c647beda-cf73-4372-975f-a8c8ed05217f/tutor-pro","title":"Tutor LMS Pro <= 2.7.0 - Missing Authorization to SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"c647beda-cf73-4372-975f-a8c8ed05217f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c647beda-cf73-4372-975f-a8c8ed05217f?source=api-prod","cve":"CVE-2024-4352","affectedVersions":"<=2.7.0","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/4b41d134-be9e-469f-b26b-ac30d95db0a3/tutor-pro","title":"Tutor LMS Pro – eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-12 18:27:44","sources":[{"name":"Wordfence","remoteId":"4b41d134-be9e-469f-b26b-ac30d95db0a3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4b41d134-be9e-469f-b26b-ac30d95db0a3?source=api-prod","cve":"CVE-2025-6184","affectedVersions":"<=3.7.0","severity":"high"},{"advisoryId":"WPSECADV/WF/59859583-49e5-4a80-8659-b9ca7ddc089d/tutor-pro","title":"Tutor LMS Pro <= 2.7.0 - Missing Authorization to Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"59859583-49e5-4a80-8659-b9ca7ddc089d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/59859583-49e5-4a80-8659-b9ca7ddc089d?source=api-prod","cve":"CVE-2024-4351","affectedVersions":"<=2.7.0","severity":"high"},{"advisoryId":"WPSECADV/WF/8dc16ba4-3c2e-43e2-82a0-b742276b9640/tutor-pro","title":"Tutor LMS Pro – eLearning and online course solution <= 3.8.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to View/Edit Other Assignments\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-24 17:30:42","sources":[{"name":"Wordfence","remoteId":"8dc16ba4-3c2e-43e2-82a0-b742276b9640"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8dc16ba4-3c2e-43e2-82a0-b742276b9640?source=api-prod","cve":"CVE-2025-6639","affectedVersions":"<=3.8.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/92a120ac-66ae-4678-a87a-e62da885d50b/tutor-pro","title":"Tutor LMS Pro <= 3.9.5 - Authentication Bypass via Social Login\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-09 16:33:12","sources":[{"name":"Wordfence","remoteId":"92a120ac-66ae-4678-a87a-e62da885d50b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/92a120ac-66ae-4678-a87a-e62da885d50b?source=api-prod","cve":"CVE-2026-0953","affectedVersions":"<=3.9.5","severity":"critical"},{"advisoryId":"WPSECADV/WF/942fffb6-2719-4b70-9759-21b2d50002c5/tutor-pro","title":"Tutor LMS Pro <= 2.7.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"942fffb6-2719-4b70-9759-21b2d50002c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/942fffb6-2719-4b70-9759-21b2d50002c5?source=api-prod","cve":"CVE-2024-4222","affectedVersions":"<=2.7.0","severity":"high"},{"advisoryId":"WPSECADV/WF/97fdd2f9-02ad-492c-88d1-1e7bd9c404a5/tutor-pro","title":"Tutor LMS Pro <= 3.9.6 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"97fdd2f9-02ad-492c-88d1-1e7bd9c404a5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/97fdd2f9-02ad-492c-88d1-1e7bd9c404a5?source=api-prod","cve":"CVE-2026-22332","affectedVersions":"<=3.9.6","severity":"high"},{"advisoryId":"WPSECADV/WF/aa5c23ed-7239-40e1-a795-1ae8d4c2d6c8/tutor-pro","title":"Tutor LMS Pro <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"aa5c23ed-7239-40e1-a795-1ae8d4c2d6c8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa5c23ed-7239-40e1-a795-1ae8d4c2d6c8?source=api-prod","cve":"CVE-2024-5784","affectedVersions":"<=2.7.2","severity":"high"},{"advisoryId":"WPSECADV/WF/ad4e5243-e41a-4624-b9cd-47ab79637560/tutor-pro","title":"Tutor LMS Pro <= 3.9.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"ad4e5243-e41a-4624-b9cd-47ab79637560"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ad4e5243-e41a-4624-b9cd-47ab79637560?source=api-prod","cve":"CVE-2026-25406","affectedVersions":"<=3.9.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/c647beda-cf73-4372-975f-a8c8ed05217f/tutor-pro","title":"Tutor LMS Pro <= 2.7.0 - Missing Authorization to SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"c647beda-cf73-4372-975f-a8c8ed05217f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c647beda-cf73-4372-975f-a8c8ed05217f?source=api-prod","cve":"CVE-2024-4352","affectedVersions":"<=2.7.0","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_757365722d726567697374726174696f6e811c9dc5_gen.json b/internal/data/assets/plugin_757365722d726567697374726174696f6e811c9dc5_gen.json index 6bb7afbb..d3554c13 100644 --- a/internal/data/assets/plugin_757365722d726567697374726174696f6e811c9dc5_gen.json +++ b/internal/data/assets/plugin_757365722d726567697374726174696f6e811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/020bed37-9544-49b7-941d-3b7f509fdfdf/user-registration","title":"User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-13 09:51:38","sources":[{"name":"Wordfence","remoteId":"020bed37-9544-49b7-941d-3b7f509fdfdf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/020bed37-9544-49b7-941d-3b7f509fdfdf?source=api-prod","cve":"CVE-2026-6203","affectedVersions":"<=5.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/07c79459-66b8-4c93-a1cd-6e3ede95643f/user-registration","title":"User Registration & Membership <= 5.1.2 - Authenticated (Subscriber+) SQL Injection via membership_ids[]\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-07 23:11:46","sources":[{"name":"Wordfence","remoteId":"07c79459-66b8-4c93-a1cd-6e3ede95643f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/07c79459-66b8-4c93-a1cd-6e3ede95643f?source=api-prod","cve":"CVE-2026-1865","affectedVersions":"<=5.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/0e0bee7c-8dce-421c-af16-7e5152797e6c/user-registration","title":"User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.0.4 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-27 16:48:16","sources":[{"name":"Wordfence","remoteId":"0e0bee7c-8dce-421c-af16-7e5152797e6c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e0bee7c-8dce-421c-af16-7e5152797e6c?source=api-prod","cve":"CVE-2025-1511","affectedVersions":"<=4.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/1b70b9b1-bde9-4a32-ae7b-a4c8d73abbc4/user-registration","title":"User Registration – Custom Registration Form, Login Form And User Profile For WordPress <= 3.0.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"1b70b9b1-bde9-4a32-ae7b-a4c8d73abbc4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b70b9b1-bde9-4a32-ae7b-a4c8d73abbc4?source=api-prod","cve":"CVE-2023-5228","affectedVersions":"<=3.0.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/2244945a-5b3a-463d-9910-46a6f7afaf6c/user-registration","title":"User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 02:13:58","sources":[{"name":"Wordfence","remoteId":"2244945a-5b3a-463d-9910-46a6f7afaf6c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2244945a-5b3a-463d-9910-46a6f7afaf6c?source=api-prod","cve":"CVE-2025-13367","affectedVersions":"<=4.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/26529849-c52c-40e5-8085-6764c22a03e7/user-registration","title":"User Registration <= 2.3.0 - Authenticated (Administrator+) Stored Cross Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"26529849-c52c-40e5-8085-6764c22a03e7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/26529849-c52c-40e5-8085-6764c22a03e7?source=api-prod","cve":"CVE-2023-23987","affectedVersions":"<=2.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/30339ff6-b6bf-4c56-b6cd-db0b8a6ce8b6/user-registration","title":"User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.2.1 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"30339ff6-b6bf-4c56-b6cd-db0b8a6ce8b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/30339ff6-b6bf-4c56-b6cd-db0b8a6ce8b6?source=api-prod","cve":"CVE-2025-3281","affectedVersions":"<=4.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/3590277a-3319-4707-b728-d75ea59e8ad9/user-registration","title":"User Registration <= 3.0.1 - Authenticated (Subscriber+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"3590277a-3319-4707-b728-d75ea59e8ad9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3590277a-3319-4707-b728-d75ea59e8ad9?source=api-prod","cve":"CVE-2023-3343","affectedVersions":"<=3.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/50f3e469-f788-45da-95e7-aa6da1e87fd1/user-registration","title":"User Registration <= 4.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via urcr_restrict Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-21 12:46:27","sources":[{"name":"Wordfence","remoteId":"50f3e469-f788-45da-95e7-aa6da1e87fd1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/50f3e469-f788-45da-95e7-aa6da1e87fd1?source=api-prod","cve":"CVE-2025-6831","affectedVersions":"<=4.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/5835fed0-5b9d-47b5-82ae-f0f19830ae2a/user-registration","title":"User Registration <= 2.3.2.1 - PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"5835fed0-5b9d-47b5-82ae-f0f19830ae2a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5835fed0-5b9d-47b5-82ae-f0f19830ae2a?source=api-prod","cve":"CVE-2023-27459","affectedVersions":"<=2.3.2.1","severity":"high"},{"advisoryId":"WPSECADV/WF/59a63cd8-9d33-4a2c-a499-5b1ee38c07d6/user-registration","title":"User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Password Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 17:44:06","sources":[{"name":"Wordfence","remoteId":"59a63cd8-9d33-4a2c-a499-5b1ee38c07d6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/59a63cd8-9d33-4a2c-a499-5b1ee38c07d6?source=api-prod","cve":"CVE-2025-3292","affectedVersions":"<=4.1.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/6193139b-52bf-425c-b1d3-c6fbd9185f06/user-registration","title":"User Registration <= 4.4.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"6193139b-52bf-425c-b1d3-c6fbd9185f06"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6193139b-52bf-425c-b1d3-c6fbd9185f06?source=api-prod","cve":"CVE-2025-67956","affectedVersions":"<=4.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/62b809dc-4089-4822-8aeb-7049fcfe376e/user-registration","title":"User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.4 - Unauthenticated Stored Self-Based Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"62b809dc-4089-4822-8aeb-7049fcfe376e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62b809dc-4089-4822-8aeb-7049fcfe376e?source=api-prod","cve":"CVE-2024-1720","affectedVersions":"<=3.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/710574a8-a6e2-4ee6-9ea7-03a34994fec7/user-registration","title":"User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.2.0.1 - Missing Authorization to Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-31 18:57:59","sources":[{"name":"Wordfence","remoteId":"710574a8-a6e2-4ee6-9ea7-03a34994fec7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/710574a8-a6e2-4ee6-9ea7-03a34994fec7?source=api-prod","cve":"CVE-2024-4958","affectedVersions":"<=3.2.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/761a4801-fc4a-40a0-b5aa-303d88a87062/user-registration","title":"User Registration <= 1.5.5 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"761a4801-fc4a-40a0-b5aa-303d88a87062"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/761a4801-fc4a-40a0-b5aa-303d88a87062?source=api-prod","affectedVersions":"<=1.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/7bb5a5a2-9644-4850-a5f9-7c925af000c8/user-registration","title":"User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Content Access Rule Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 11:24:15","sources":[{"name":"Wordfence","remoteId":"7bb5a5a2-9644-4850-a5f9-7c925af000c8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7bb5a5a2-9644-4850-a5f9-7c925af000c8?source=api-prod","cve":"CVE-2026-4056","affectedVersions":"<=5.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/7e9fec92-f471-4ce9-9138-1c58ad658da2/user-registration","title":"User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 16:05:18","sources":[{"name":"Wordfence","remoteId":"7e9fec92-f471-4ce9-9138-1c58ad658da2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7e9fec92-f471-4ce9-9138-1c58ad658da2?source=api-prod","cve":"CVE-2026-1492","affectedVersions":"<=5.1.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/864a3444-0479-4b9f-beca-584a4a9b8682/user-registration","title":"User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Unauthenticated Media Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"864a3444-0479-4b9f-beca-584a4a9b8682"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/864a3444-0479-4b9f-beca-584a4a9b8682?source=api-prod","cve":"CVE-2024-3295","affectedVersions":"<=3.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/98345631-45df-419b-aada-b7053a31b68c/user-registration","title":"User Registration <= 4.1.5 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"98345631-45df-419b-aada-b7053a31b68c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/98345631-45df-419b-aada-b7053a31b68c?source=api-prod","cve":"CVE-2025-39400","affectedVersions":"<=4.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/a4149783-ffa3-4efd-af55-5aa1c0e44443/user-registration","title":"User Registration & Membership <= 4.1.2 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"a4149783-ffa3-4efd-af55-5aa1c0e44443"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4149783-ffa3-4efd-af55-5aa1c0e44443?source=api-prod","cve":"CVE-2025-2594","affectedVersions":"<=4.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/a5a1ccb2-4f78-4855-a01d-b15f73407822/user-registration","title":"User Registration & Membership <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-25 13:29:35","sources":[{"name":"Wordfence","remoteId":"a5a1ccb2-4f78-4855-a01d-b15f73407822"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a5a1ccb2-4f78-4855-a01d-b15f73407822?source=api-prod","cve":"CVE-2026-2356","affectedVersions":"<=5.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/a671128a-74e6-4f92-94af-9e5e37ed7b7a/user-registration","title":"User Registration <= 2.3.2.1 - Missing Authorization via send_test_email\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"a671128a-74e6-4f92-94af-9e5e37ed7b7a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a671128a-74e6-4f92-94af-9e5e37ed7b7a?source=api-prod","cve":"CVE-2023-29429","affectedVersions":"<=2.3.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/a979e885-f7dd-4616-a881-64f3d97c309d/user-registration","title":"User Registration <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"a979e885-f7dd-4616-a881-64f3d97c309d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a979e885-f7dd-4616-a881-64f3d97c309d?source=api-prod","cve":"CVE-2023-3342","affectedVersions":"<=3.0.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/ba326241-46a3-4891-a180-d7977f4e83ed/user-registration","title":"User Registration & Membership <= 4.3.0 - Authenticated (Admin+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"ba326241-46a3-4891-a180-d7977f4e83ed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ba326241-46a3-4891-a180-d7977f4e83ed?source=api-prod","cve":"CVE-2025-9085","affectedVersions":"<=4.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c07ea205-5a05-43f5-993e-c6e30f660ac8/user-registration","title":"User Registration <= 2.2.4 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"c07ea205-5a05-43f5-993e-c6e30f660ac8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c07ea205-5a05-43f5-993e-c6e30f660ac8?source=api-prod","cve":"CVE-2022-3912","affectedVersions":"<=2.2.4","severity":"high"},{"advisoryId":"WPSECADV/WF/c525b41c-dca5-442a-927e-4583cb303ed1/user-registration","title":"User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Unauthenticated Membership Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"c525b41c-dca5-442a-927e-4583cb303ed1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c525b41c-dca5-442a-927e-4583cb303ed1?source=api-prod","cve":"CVE-2025-3282","affectedVersions":"<=4.1.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8798fb2-4cab-4960-9e32-fd74bb4a5091/user-registration","title":"User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Limited Page Content Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 19:57:08","sources":[{"name":"Wordfence","remoteId":"c8798fb2-4cab-4960-9e32-fd74bb4a5091"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8798fb2-4cab-4960-9e32-fd74bb4a5091?source=api-prod","cve":"CVE-2026-3601","affectedVersions":"<=5.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/cd4c2c11-2d73-48b4-8e7e-e281451973a2/user-registration","title":"User Registration <= 4.4.9 - Authenticated (Subscriber+) Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"cd4c2c11-2d73-48b4-8e7e-e281451973a2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cd4c2c11-2d73-48b4-8e7e-e281451973a2?source=api-prod","cve":"CVE-2026-24353","affectedVersions":"<=4.4.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/d03459d8-b1f2-4270-a294-403754db1f2f/user-registration","title":"User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"d03459d8-b1f2-4270-a294-403754db1f2f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d03459d8-b1f2-4270-a294-403754db1f2f?source=api-prod","cve":"CVE-2024-2417","affectedVersions":"<=3.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/d99bc021-ba9e-4294-8dd2-c25bc8007d05/user-registration","title":"User Registration & Membership <= 5.1.2 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-25 13:29:34","sources":[{"name":"Wordfence","remoteId":"d99bc021-ba9e-4294-8dd2-c25bc8007d05"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d99bc021-ba9e-4294-8dd2-c25bc8007d05?source=api-prod","cve":"CVE-2026-1779","affectedVersions":"<=5.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/e5495b4c-a1ac-4860-83a7-686d9436d983/user-registration","title":"User Registration & Membership <= 4.4.8 - Cross-Site Request Forgery to Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-09 20:16:56","sources":[{"name":"Wordfence","remoteId":"e5495b4c-a1ac-4860-83a7-686d9436d983"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e5495b4c-a1ac-4860-83a7-686d9436d983?source=api-prod","cve":"CVE-2025-14976","affectedVersions":"<=4.4.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/ea59d04e-b332-49f8-bf3f-6e0cda3be712/user-registration","title":"User Registration <= 4.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"ea59d04e-b332-49f8-bf3f-6e0cda3be712"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ea59d04e-b332-49f8-bf3f-6e0cda3be712?source=api-prod","cve":"CVE-2025-30899","affectedVersions":"<=4.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/ffd9cbd1-f8a9-401e-8cdd-1ff16f438b4a/user-registration","title":"User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"ffd9cbd1-f8a9-401e-8cdd-1ff16f438b4a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ffd9cbd1-f8a9-401e-8cdd-1ff16f438b4a?source=api-prod","cve":"CVE-2025-2563","affectedVersions":"<=4.1.1","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/020bed37-9544-49b7-941d-3b7f509fdfdf/user-registration","title":"User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-13 09:51:38","sources":[{"name":"Wordfence","remoteId":"020bed37-9544-49b7-941d-3b7f509fdfdf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/020bed37-9544-49b7-941d-3b7f509fdfdf?source=api-prod","cve":"CVE-2026-6203","affectedVersions":"<=5.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/07c79459-66b8-4c93-a1cd-6e3ede95643f/user-registration","title":"User Registration & Membership <= 5.1.2 - Authenticated (Subscriber+) SQL Injection via membership_ids[]\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-07 23:11:46","sources":[{"name":"Wordfence","remoteId":"07c79459-66b8-4c93-a1cd-6e3ede95643f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/07c79459-66b8-4c93-a1cd-6e3ede95643f?source=api-prod","cve":"CVE-2026-1865","affectedVersions":"<=5.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/0e0bee7c-8dce-421c-af16-7e5152797e6c/user-registration","title":"User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.0.4 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-27 16:48:16","sources":[{"name":"Wordfence","remoteId":"0e0bee7c-8dce-421c-af16-7e5152797e6c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e0bee7c-8dce-421c-af16-7e5152797e6c?source=api-prod","cve":"CVE-2025-1511","affectedVersions":"<=4.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/1b70b9b1-bde9-4a32-ae7b-a4c8d73abbc4/user-registration","title":"User Registration – Custom Registration Form, Login Form And User Profile For WordPress <= 3.0.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-10-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"1b70b9b1-bde9-4a32-ae7b-a4c8d73abbc4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1b70b9b1-bde9-4a32-ae7b-a4c8d73abbc4?source=api-prod","cve":"CVE-2023-5228","affectedVersions":"<=3.0.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/2244945a-5b3a-463d-9910-46a6f7afaf6c/user-registration","title":"User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 02:13:58","sources":[{"name":"Wordfence","remoteId":"2244945a-5b3a-463d-9910-46a6f7afaf6c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2244945a-5b3a-463d-9910-46a6f7afaf6c?source=api-prod","cve":"CVE-2025-13367","affectedVersions":"<=4.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/26529849-c52c-40e5-8085-6764c22a03e7/user-registration","title":"User Registration <= 2.3.0 - Authenticated (Administrator+) Stored Cross Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"26529849-c52c-40e5-8085-6764c22a03e7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/26529849-c52c-40e5-8085-6764c22a03e7?source=api-prod","cve":"CVE-2023-23987","affectedVersions":"<=2.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/30339ff6-b6bf-4c56-b6cd-db0b8a6ce8b6/user-registration","title":"User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.2.1 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"30339ff6-b6bf-4c56-b6cd-db0b8a6ce8b6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/30339ff6-b6bf-4c56-b6cd-db0b8a6ce8b6?source=api-prod","cve":"CVE-2025-3281","affectedVersions":"<=4.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/3590277a-3319-4707-b728-d75ea59e8ad9/user-registration","title":"User Registration <= 3.0.1 - Authenticated (Subscriber+) PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"3590277a-3319-4707-b728-d75ea59e8ad9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3590277a-3319-4707-b728-d75ea59e8ad9?source=api-prod","cve":"CVE-2023-3343","affectedVersions":"<=3.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/37e1a755-7c17-4cb4-acca-9f26238230f3/user-registration","title":"User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 4.4.9 - Unauthenticated Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"37e1a755-7c17-4cb4-acca-9f26238230f3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/37e1a755-7c17-4cb4-acca-9f26238230f3?source=api-prod","cve":"CVE-2026-32488","affectedVersions":"<=4.4.9","severity":"critical"},{"advisoryId":"WPSECADV/WF/50f3e469-f788-45da-95e7-aa6da1e87fd1/user-registration","title":"User Registration <= 4.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via urcr_restrict Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-21 12:46:27","sources":[{"name":"Wordfence","remoteId":"50f3e469-f788-45da-95e7-aa6da1e87fd1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/50f3e469-f788-45da-95e7-aa6da1e87fd1?source=api-prod","cve":"CVE-2025-6831","affectedVersions":"<=4.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/5835fed0-5b9d-47b5-82ae-f0f19830ae2a/user-registration","title":"User Registration <= 2.3.2.1 - PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"5835fed0-5b9d-47b5-82ae-f0f19830ae2a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5835fed0-5b9d-47b5-82ae-f0f19830ae2a?source=api-prod","cve":"CVE-2023-27459","affectedVersions":"<=2.3.2.1","severity":"high"},{"advisoryId":"WPSECADV/WF/59a63cd8-9d33-4a2c-a499-5b1ee38c07d6/user-registration","title":"User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Password Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 17:44:06","sources":[{"name":"Wordfence","remoteId":"59a63cd8-9d33-4a2c-a499-5b1ee38c07d6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/59a63cd8-9d33-4a2c-a499-5b1ee38c07d6?source=api-prod","cve":"CVE-2025-3292","affectedVersions":"<=4.1.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/6193139b-52bf-425c-b1d3-c6fbd9185f06/user-registration","title":"User Registration <= 4.4.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"6193139b-52bf-425c-b1d3-c6fbd9185f06"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6193139b-52bf-425c-b1d3-c6fbd9185f06?source=api-prod","cve":"CVE-2025-67956","affectedVersions":"<=4.4.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/62b809dc-4089-4822-8aeb-7049fcfe376e/user-registration","title":"User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.4 - Unauthenticated Stored Self-Based Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"62b809dc-4089-4822-8aeb-7049fcfe376e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/62b809dc-4089-4822-8aeb-7049fcfe376e?source=api-prod","cve":"CVE-2024-1720","affectedVersions":"<=3.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/710574a8-a6e2-4ee6-9ea7-03a34994fec7/user-registration","title":"User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.2.0.1 - Missing Authorization to Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-05-31 18:57:59","sources":[{"name":"Wordfence","remoteId":"710574a8-a6e2-4ee6-9ea7-03a34994fec7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/710574a8-a6e2-4ee6-9ea7-03a34994fec7?source=api-prod","cve":"CVE-2024-4958","affectedVersions":"<=3.2.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/761a4801-fc4a-40a0-b5aa-303d88a87062/user-registration","title":"User Registration <= 1.5.5 - Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2019-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"761a4801-fc4a-40a0-b5aa-303d88a87062"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/761a4801-fc4a-40a0-b5aa-303d88a87062?source=api-prod","affectedVersions":"<=1.5.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/7bb5a5a2-9644-4850-a5f9-7c925af000c8/user-registration","title":"User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Content Access Rule Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 11:24:15","sources":[{"name":"Wordfence","remoteId":"7bb5a5a2-9644-4850-a5f9-7c925af000c8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7bb5a5a2-9644-4850-a5f9-7c925af000c8?source=api-prod","cve":"CVE-2026-4056","affectedVersions":"<=5.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/7e9fec92-f471-4ce9-9138-1c58ad658da2/user-registration","title":"User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 16:05:18","sources":[{"name":"Wordfence","remoteId":"7e9fec92-f471-4ce9-9138-1c58ad658da2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7e9fec92-f471-4ce9-9138-1c58ad658da2?source=api-prod","cve":"CVE-2026-1492","affectedVersions":"<=5.1.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/864a3444-0479-4b9f-beca-584a4a9b8682/user-registration","title":"User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Unauthenticated Media Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"864a3444-0479-4b9f-beca-584a4a9b8682"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/864a3444-0479-4b9f-beca-584a4a9b8682?source=api-prod","cve":"CVE-2024-3295","affectedVersions":"<=3.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/98345631-45df-419b-aada-b7053a31b68c/user-registration","title":"User Registration <= 4.1.5 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"98345631-45df-419b-aada-b7053a31b68c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/98345631-45df-419b-aada-b7053a31b68c?source=api-prod","cve":"CVE-2025-39400","affectedVersions":"<=4.1.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/a4149783-ffa3-4efd-af55-5aa1c0e44443/user-registration","title":"User Registration & Membership <= 4.1.2 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"a4149783-ffa3-4efd-af55-5aa1c0e44443"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a4149783-ffa3-4efd-af55-5aa1c0e44443?source=api-prod","cve":"CVE-2025-2594","affectedVersions":"<=4.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/a5a1ccb2-4f78-4855-a01d-b15f73407822/user-registration","title":"User Registration & Membership <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-25 13:29:35","sources":[{"name":"Wordfence","remoteId":"a5a1ccb2-4f78-4855-a01d-b15f73407822"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a5a1ccb2-4f78-4855-a01d-b15f73407822?source=api-prod","cve":"CVE-2026-2356","affectedVersions":"<=5.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/a671128a-74e6-4f92-94af-9e5e37ed7b7a/user-registration","title":"User Registration <= 2.3.2.1 - Missing Authorization via send_test_email\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"a671128a-74e6-4f92-94af-9e5e37ed7b7a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a671128a-74e6-4f92-94af-9e5e37ed7b7a?source=api-prod","cve":"CVE-2023-29429","affectedVersions":"<=2.3.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/a979e885-f7dd-4616-a881-64f3d97c309d/user-registration","title":"User Registration <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"a979e885-f7dd-4616-a881-64f3d97c309d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a979e885-f7dd-4616-a881-64f3d97c309d?source=api-prod","cve":"CVE-2023-3342","affectedVersions":"<=3.0.2","severity":"critical"},{"advisoryId":"WPSECADV/WF/ba326241-46a3-4891-a180-d7977f4e83ed/user-registration","title":"User Registration & Membership <= 4.3.0 - Authenticated (Admin+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"ba326241-46a3-4891-a180-d7977f4e83ed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ba326241-46a3-4891-a180-d7977f4e83ed?source=api-prod","cve":"CVE-2025-9085","affectedVersions":"<=4.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/c07ea205-5a05-43f5-993e-c6e30f660ac8/user-registration","title":"User Registration <= 2.2.4 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-11-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"c07ea205-5a05-43f5-993e-c6e30f660ac8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c07ea205-5a05-43f5-993e-c6e30f660ac8?source=api-prod","cve":"CVE-2022-3912","affectedVersions":"<=2.2.4","severity":"high"},{"advisoryId":"WPSECADV/WF/c525b41c-dca5-442a-927e-4583cb303ed1/user-registration","title":"User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Unauthenticated Membership Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"c525b41c-dca5-442a-927e-4583cb303ed1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c525b41c-dca5-442a-927e-4583cb303ed1?source=api-prod","cve":"CVE-2025-3282","affectedVersions":"<=4.1.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/c8798fb2-4cab-4960-9e32-fd74bb4a5091/user-registration","title":"User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Limited Page Content Modification\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-04 19:57:08","sources":[{"name":"Wordfence","remoteId":"c8798fb2-4cab-4960-9e32-fd74bb4a5091"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8798fb2-4cab-4960-9e32-fd74bb4a5091?source=api-prod","cve":"CVE-2026-3601","affectedVersions":"<=5.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/cd4c2c11-2d73-48b4-8e7e-e281451973a2/user-registration","title":"User Registration <= 4.4.9 - Authenticated (Subscriber+) Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"cd4c2c11-2d73-48b4-8e7e-e281451973a2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cd4c2c11-2d73-48b4-8e7e-e281451973a2?source=api-prod","cve":"CVE-2026-24353","affectedVersions":"<=4.4.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/d03459d8-b1f2-4270-a294-403754db1f2f/user-registration","title":"User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"d03459d8-b1f2-4270-a294-403754db1f2f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d03459d8-b1f2-4270-a294-403754db1f2f?source=api-prod","cve":"CVE-2024-2417","affectedVersions":"<=3.1.5","severity":"high"},{"advisoryId":"WPSECADV/WF/d99bc021-ba9e-4294-8dd2-c25bc8007d05/user-registration","title":"User Registration & Membership <= 5.1.2 - Authentication Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-25 13:29:34","sources":[{"name":"Wordfence","remoteId":"d99bc021-ba9e-4294-8dd2-c25bc8007d05"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d99bc021-ba9e-4294-8dd2-c25bc8007d05?source=api-prod","cve":"CVE-2026-1779","affectedVersions":"<=5.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/e5495b4c-a1ac-4860-83a7-686d9436d983/user-registration","title":"User Registration & Membership <= 4.4.8 - Cross-Site Request Forgery to Arbitrary Post Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-09 20:16:56","sources":[{"name":"Wordfence","remoteId":"e5495b4c-a1ac-4860-83a7-686d9436d983"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e5495b4c-a1ac-4860-83a7-686d9436d983?source=api-prod","cve":"CVE-2025-14976","affectedVersions":"<=4.4.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/ea59d04e-b332-49f8-bf3f-6e0cda3be712/user-registration","title":"User Registration <= 4.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"ea59d04e-b332-49f8-bf3f-6e0cda3be712"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ea59d04e-b332-49f8-bf3f-6e0cda3be712?source=api-prod","cve":"CVE-2025-30899","affectedVersions":"<=4.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/ffd9cbd1-f8a9-401e-8cdd-1ff16f438b4a/user-registration","title":"User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"ffd9cbd1-f8a9-401e-8cdd-1ff16f438b4a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ffd9cbd1-f8a9-401e-8cdd-1ff16f438b4a?source=api-prod","cve":"CVE-2025-2563","affectedVersions":"<=4.1.1","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_76697375616c2d6c696e6b2d70726576696577811c9dc5_gen.json b/internal/data/assets/plugin_76697375616c2d6c696e6b2d70726576696577811c9dc5_gen.json index 16195e11..85ac6e05 100644 --- a/internal/data/assets/plugin_76697375616c2d6c696e6b2d70726576696577811c9dc5_gen.json +++ b/internal/data/assets/plugin_76697375616c2d6c696e6b2d70726576696577811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/012e019f-9146-45bc-b4d7-aa724dbebdc6/visual-link-preview","title":"Visual Link Preview <= 2.2.2 - Unauthorised AJAX Calls\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-08-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"012e019f-9146-45bc-b4d7-aa724dbebdc6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/012e019f-9146-45bc-b4d7-aa724dbebdc6?source=api-prod","cve":"CVE-2021-24635","affectedVersions":"<2.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ed28379-1fc0-4cf4-a507-7d0bdc9f7f4a/visual-link-preview","title":"Visual Link Preview <= 2.2.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"2ed28379-1fc0-4cf4-a507-7d0bdc9f7f4a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ed28379-1fc0-4cf4-a507-7d0bdc9f7f4a?source=api-prod","cve":"CVE-2026-24984","affectedVersions":"<=2.2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/65ae3119-61d1-4ec0-8ba2-352aae5cc834/visual-link-preview","title":"Visual Link Preview <= 2.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via visual-link-preview Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-04 21:24:01","sources":[{"name":"Wordfence","remoteId":"65ae3119-61d1-4ec0-8ba2-352aae5cc834"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/65ae3119-61d1-4ec0-8ba2-352aae5cc834?source=api-prod","cve":"CVE-2025-11987","affectedVersions":"<=2.2.7","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/012e019f-9146-45bc-b4d7-aa724dbebdc6/visual-link-preview","title":"Visual Link Preview <= 2.2.2 - Unauthorised AJAX Calls\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-08-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"012e019f-9146-45bc-b4d7-aa724dbebdc6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/012e019f-9146-45bc-b4d7-aa724dbebdc6?source=api-prod","cve":"CVE-2021-24635","affectedVersions":"<2.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/2ed28379-1fc0-4cf4-a507-7d0bdc9f7f4a/visual-link-preview","title":"Visual Link Preview <= 2.2.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"2ed28379-1fc0-4cf4-a507-7d0bdc9f7f4a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ed28379-1fc0-4cf4-a507-7d0bdc9f7f4a?source=api-prod","cve":"CVE-2026-24984","affectedVersions":"<=2.2.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/347ba90e-b65f-46ea-bc82-8b5eb5dd5bdd/visual-link-preview","title":"Visual Link Preview <= 2.3.0 - Authenticated (Contributor+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"347ba90e-b65f-46ea-bc82-8b5eb5dd5bdd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/347ba90e-b65f-46ea-bc82-8b5eb5dd5bdd?source=api-prod","cve":"CVE-2026-39670","affectedVersions":"<=2.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/65ae3119-61d1-4ec0-8ba2-352aae5cc834/visual-link-preview","title":"Visual Link Preview <= 2.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via visual-link-preview Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-04 21:24:01","sources":[{"name":"Wordfence","remoteId":"65ae3119-61d1-4ec0-8ba2-352aae5cc834"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/65ae3119-61d1-4ec0-8ba2-352aae5cc834?source=api-prod","cve":"CVE-2025-11987","affectedVersions":"<=2.2.7","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7765646576732d70726f6a6563742d6d616e61676572811c9dc5_gen.json b/internal/data/assets/plugin_7765646576732d70726f6a6563742d6d616e61676572811c9dc5_gen.json index 8b3f696c..17cfb42e 100644 --- a/internal/data/assets/plugin_7765646576732d70726f6a6563742d6d616e61676572811c9dc5_gen.json +++ b/internal/data/assets/plugin_7765646576732d70726f6a6563742d6d616e61676572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0d1456bb-9ecb-406e-b1c8-b582bee094a9/wedevs-project-manager","title":"Project Manager <= 3.0.1 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d1456bb-9ecb-406e-b1c8-b582bee094a9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d1456bb-9ecb-406e-b1c8-b582bee094a9?source=api-prod","cve":"CVE-2025-68040","affectedVersions":"<=3.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/42aa9614-3403-422c-a4b7-0f4b2d17b371/wedevs-project-manager","title":"WP Project Manager <= 2.6.22 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"42aa9614-3403-422c-a4b7-0f4b2d17b371"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/42aa9614-3403-422c-a4b7-0f4b2d17b371?source=api-prod","cve":"CVE-2025-22649","affectedVersions":"<=2.6.22","severity":"medium"},{"advisoryId":"WPSECADV/WF/456c13f5-4a8b-4eea-a2a0-f37f8508551b/wedevs-project-manager","title":"WP Project Manager <= 2.4.0 - Cross-Site Request Forgery Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-09-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"456c13f5-4a8b-4eea-a2a0-f37f8508551b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/456c13f5-4a8b-4eea-a2a0-f37f8508551b?source=api-prod","cve":"CVE-2020-36745","affectedVersions":"<2.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/497760a8-7d4a-45a0-91e4-a8ee27bcdb02/wedevs-project-manager","title":"WP Project Manager <= 2.6.14 - Missing Authorization to Project Milestone and Task Creation/Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"497760a8-7d4a-45a0-91e4-a8ee27bcdb02"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/497760a8-7d4a-45a0-91e4-a8ee27bcdb02?source=api-prod","cve":"CVE-2024-10520","affectedVersions":"<=2.6.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/4d62b087-b0ca-4fa8-921b-5eeb3fa76596/wedevs-project-manager","title":"WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-08 15:42:30","sources":[{"name":"Wordfence","remoteId":"4d62b087-b0ca-4fa8-921b-5eeb3fa76596"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d62b087-b0ca-4fa8-921b-5eeb3fa76596?source=api-prod","cve":"CVE-2025-3100","affectedVersions":"<=2.6.22","severity":"medium"},{"advisoryId":"WPSECADV/WF/6a5e4708-db3e-483c-852f-1a487825cf92/wedevs-project-manager","title":"WP Project Manager <= 2.6.4 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"6a5e4708-db3e-483c-852f-1a487825cf92"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6a5e4708-db3e-483c-852f-1a487825cf92?source=api-prod","cve":"CVE-2023-3636","affectedVersions":"<=2.6.4","severity":"high"},{"advisoryId":"WPSECADV/WF/70083f93-f110-4029-a3d3-ce8a77799a31/wedevs-project-manager","title":"WP Project Manager <= 2.6.17 - Authenticated (Subscriber+) SQL Injection via orderby Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-14 23:02:19","sources":[{"name":"Wordfence","remoteId":"70083f93-f110-4029-a3d3-ce8a77799a31"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/70083f93-f110-4029-a3d3-ce8a77799a31?source=api-prod","cve":"CVE-2024-13500","affectedVersions":"<=2.6.17","severity":"medium"},{"advisoryId":"WPSECADV/WF/74984cc6-06b1-4c3a-a3e6-9e104c71e9c5/wedevs-project-manager","title":"WP Project Manager <= 2.6.26 - Authenticated (Subscriber+) SQL Injection via 'completed_at_operator'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"74984cc6-06b1-4c3a-a3e6-9e104c71e9c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/74984cc6-06b1-4c3a-a3e6-9e104c71e9c5?source=api-prod","cve":"CVE-2025-8994","affectedVersions":"<=2.6.26","severity":"medium"},{"advisoryId":"WPSECADV/WF/798d120a-edec-4af9-b574-46f9beabc491/wedevs-project-manager","title":"WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"798d120a-edec-4af9-b574-46f9beabc491"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/798d120a-edec-4af9-b574-46f9beabc491?source=api-prod","cve":"CVE-2024-12195","affectedVersions":"<=2.6.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/79dabaa6-d907-4fa6-bc6f-f28f39578256/wedevs-project-manager","title":"WP Project Manager <= 2.6.0 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"79dabaa6-d907-4fa6-bc6f-f28f39578256"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/79dabaa6-d907-4fa6-bc6f-f28f39578256?source=api-prod","cve":"CVE-2023-34383","affectedVersions":"<=2.6.0","severity":"high"},{"advisoryId":"WPSECADV/WF/84003388-c47c-41db-8d2d-4643aa375a89/wedevs-project-manager","title":"Appsero <= 1.2.1 - Missing Authorization\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"84003388-c47c-41db-8d2d-4643aa375a89"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/84003388-c47c-41db-8d2d-4643aa375a89?source=api-prod","affectedVersions":"<=2.6.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/91758857-87ef-458a-bd19-e102fc0f3a6a/wedevs-project-manager","title":"WP Project Manager <= 2.6.25 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"91758857-87ef-458a-bd19-e102fc0f3a6a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91758857-87ef-458a-bd19-e102fc0f3a6a?source=api-prod","cve":"CVE-2025-58269","affectedVersions":"<=2.6.25","severity":"medium"},{"advisoryId":"WPSECADV/WF/a21b7c40-2090-4262-9105-346db2325612/wedevs-project-manager","title":"WP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST API\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"a21b7c40-2090-4262-9105-346db2325612"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a21b7c40-2090-4262-9105-346db2325612?source=api-prod","cve":"CVE-2024-10548","affectedVersions":"<=2.6.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/bd54a50b-13ce-43ce-bce1-8fe132abc07e/wedevs-project-manager","title":"WP Project Manager <= 2.6.17 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-14 20:28:29","sources":[{"name":"Wordfence","remoteId":"bd54a50b-13ce-43ce-bce1-8fe132abc07e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bd54a50b-13ce-43ce-bce1-8fe132abc07e?source=api-prod","cve":"CVE-2024-13752","affectedVersions":"<=2.6.17","severity":"medium"},{"advisoryId":"WPSECADV/WF/bd625d24-c1e9-465d-896a-bff75d8c534f/wedevs-project-manager","title":"WP Project Manager <= 2.6.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"bd625d24-c1e9-465d-896a-bff75d8c534f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bd625d24-c1e9-465d-896a-bff75d8c534f?source=api-prod","cve":"CVE-2023-49860","affectedVersions":"<=2.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/c093ed6a-0f3d-4ad9-a57c-cec1c2e7bd8e/wedevs-project-manager","title":"WP Project Manager <= 2.6.26 - Authenticated (Project Manager+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"c093ed6a-0f3d-4ad9-a57c-cec1c2e7bd8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c093ed6a-0f3d-4ad9-a57c-cec1c2e7bd8e?source=api-prod","cve":"CVE-2024-12015","affectedVersions":"<=2.6.26","severity":"medium"},{"advisoryId":"WPSECADV/WF/dcc68b62-7dd1-47d4-bbc5-d0237b7c85e7/wedevs-project-manager","title":"WP Project Manager <= 2.6.22 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-10 22:38:47","sources":[{"name":"Wordfence","remoteId":"dcc68b62-7dd1-47d4-bbc5-d0237b7c85e7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dcc68b62-7dd1-47d4-bbc5-d0237b7c85e7?source=api-prod","cve":"CVE-2025-2541","affectedVersions":"<=2.6.22","severity":"medium"},{"advisoryId":"WPSECADV/WF/dea2d045-d3b4-4b55-8b4f-5baa82a18834/wedevs-project-manager","title":"WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 - Insecure Direct Object Reference to Unauthenticated Authorization Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"dea2d045-d3b4-4b55-8b4f-5baa82a18834"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dea2d045-d3b4-4b55-8b4f-5baa82a18834?source=api-prod","cve":"CVE-2024-10174","affectedVersions":"<=2.6.13","severity":"high"},{"advisoryId":"WPSECADV/WF/e869800a-6fbc-4a1a-97fd-92ecbf3305ff/wedevs-project-manager","title":"Appsero <= 1.2.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"e869800a-6fbc-4a1a-97fd-92ecbf3305ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e869800a-6fbc-4a1a-97fd-92ecbf3305ff?source=api-prod","cve":"CVE-2022-47150","affectedVersions":"<=2.6.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/ef5859b7-0f15-43ad-9f45-aa846d045f5d/wedevs-project-manager","title":"WP Project Manager <= 2.4.13 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-11 13:37:00","sources":[{"name":"Wordfence","remoteId":"ef5859b7-0f15-43ad-9f45-aa846d045f5d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ef5859b7-0f15-43ad-9f45-aa846d045f5d?source=api-prod","cve":"CVE-2021-36826","affectedVersions":"<=2.4.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/f83a6631-ff6c-422e-8b6c-49576fadb89f/wedevs-project-manager","title":"WP Project Manager <= 2.6.7 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"f83a6631-ff6c-422e-8b6c-49576fadb89f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f83a6631-ff6c-422e-8b6c-49576fadb89f?source=api-prod","cve":"CVE-2023-40003","affectedVersions":"<=2.6.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/f9e7acc4-8b17-44a8-b20f-4c8f2a36180a/wedevs-project-manager","title":"WP Project Manager <= 2.6.24 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"f9e7acc4-8b17-44a8-b20f-4c8f2a36180a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f9e7acc4-8b17-44a8-b20f-4c8f2a36180a?source=api-prod","cve":"CVE-2025-32280","affectedVersions":"<=2.6.24","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0d1456bb-9ecb-406e-b1c8-b582bee094a9/wedevs-project-manager","title":"Project Manager <= 3.0.1 - Authenticated (Subscriber+) Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d1456bb-9ecb-406e-b1c8-b582bee094a9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d1456bb-9ecb-406e-b1c8-b582bee094a9?source=api-prod","cve":"CVE-2025-68040","affectedVersions":"<=3.0.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/42aa9614-3403-422c-a4b7-0f4b2d17b371/wedevs-project-manager","title":"WP Project Manager <= 2.6.22 - Authenticated (Administrator+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"42aa9614-3403-422c-a4b7-0f4b2d17b371"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/42aa9614-3403-422c-a4b7-0f4b2d17b371?source=api-prod","cve":"CVE-2025-22649","affectedVersions":"<=2.6.22","severity":"medium"},{"advisoryId":"WPSECADV/WF/456c13f5-4a8b-4eea-a2a0-f37f8508551b/wedevs-project-manager","title":"WP Project Manager <= 2.4.0 - Cross-Site Request Forgery Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-09-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"456c13f5-4a8b-4eea-a2a0-f37f8508551b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/456c13f5-4a8b-4eea-a2a0-f37f8508551b?source=api-prod","cve":"CVE-2020-36745","affectedVersions":"<2.4.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/497760a8-7d4a-45a0-91e4-a8ee27bcdb02/wedevs-project-manager","title":"WP Project Manager <= 2.6.14 - Missing Authorization to Project Milestone and Task Creation/Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"497760a8-7d4a-45a0-91e4-a8ee27bcdb02"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/497760a8-7d4a-45a0-91e4-a8ee27bcdb02?source=api-prod","cve":"CVE-2024-10520","affectedVersions":"<=2.6.14","severity":"medium"},{"advisoryId":"WPSECADV/WF/4d62b087-b0ca-4fa8-921b-5eeb3fa76596/wedevs-project-manager","title":"WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-08 15:42:30","sources":[{"name":"Wordfence","remoteId":"4d62b087-b0ca-4fa8-921b-5eeb3fa76596"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4d62b087-b0ca-4fa8-921b-5eeb3fa76596?source=api-prod","cve":"CVE-2025-3100","affectedVersions":"<=2.6.22","severity":"medium"},{"advisoryId":"WPSECADV/WF/6a5e4708-db3e-483c-852f-1a487825cf92/wedevs-project-manager","title":"WP Project Manager <= 2.6.4 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"6a5e4708-db3e-483c-852f-1a487825cf92"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6a5e4708-db3e-483c-852f-1a487825cf92?source=api-prod","cve":"CVE-2023-3636","affectedVersions":"<=2.6.4","severity":"high"},{"advisoryId":"WPSECADV/WF/70083f93-f110-4029-a3d3-ce8a77799a31/wedevs-project-manager","title":"WP Project Manager <= 2.6.17 - Authenticated (Subscriber+) SQL Injection via orderby Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-14 23:02:19","sources":[{"name":"Wordfence","remoteId":"70083f93-f110-4029-a3d3-ce8a77799a31"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/70083f93-f110-4029-a3d3-ce8a77799a31?source=api-prod","cve":"CVE-2024-13500","affectedVersions":"<=2.6.17","severity":"medium"},{"advisoryId":"WPSECADV/WF/74984cc6-06b1-4c3a-a3e6-9e104c71e9c5/wedevs-project-manager","title":"WP Project Manager <= 2.6.26 - Authenticated (Subscriber+) SQL Injection via 'completed_at_operator'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-11-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"74984cc6-06b1-4c3a-a3e6-9e104c71e9c5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/74984cc6-06b1-4c3a-a3e6-9e104c71e9c5?source=api-prod","cve":"CVE-2025-8994","affectedVersions":"<=2.6.26","severity":"medium"},{"advisoryId":"WPSECADV/WF/798d120a-edec-4af9-b574-46f9beabc491/wedevs-project-manager","title":"WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-01-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"798d120a-edec-4af9-b574-46f9beabc491"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/798d120a-edec-4af9-b574-46f9beabc491?source=api-prod","cve":"CVE-2024-12195","affectedVersions":"<=2.6.16","severity":"medium"},{"advisoryId":"WPSECADV/WF/79dabaa6-d907-4fa6-bc6f-f28f39578256/wedevs-project-manager","title":"WP Project Manager <= 2.6.0 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"79dabaa6-d907-4fa6-bc6f-f28f39578256"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/79dabaa6-d907-4fa6-bc6f-f28f39578256?source=api-prod","cve":"CVE-2023-34383","affectedVersions":"<=2.6.0","severity":"high"},{"advisoryId":"WPSECADV/WF/84003388-c47c-41db-8d2d-4643aa375a89/wedevs-project-manager","title":"Appsero <= 1.2.1 - Missing Authorization\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"84003388-c47c-41db-8d2d-4643aa375a89"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/84003388-c47c-41db-8d2d-4643aa375a89?source=api-prod","affectedVersions":"<=2.6.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/91758857-87ef-458a-bd19-e102fc0f3a6a/wedevs-project-manager","title":"WP Project Manager <= 2.6.25 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-09-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"91758857-87ef-458a-bd19-e102fc0f3a6a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91758857-87ef-458a-bd19-e102fc0f3a6a?source=api-prod","cve":"CVE-2025-58269","affectedVersions":"<=2.6.25","severity":"medium"},{"advisoryId":"WPSECADV/WF/a21b7c40-2090-4262-9105-346db2325612/wedevs-project-manager","title":"WP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST API\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"a21b7c40-2090-4262-9105-346db2325612"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a21b7c40-2090-4262-9105-346db2325612?source=api-prod","cve":"CVE-2024-10548","affectedVersions":"<=2.6.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/bd54a50b-13ce-43ce-bce1-8fe132abc07e/wedevs-project-manager","title":"WP Project Manager <= 2.6.17 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-14 20:28:29","sources":[{"name":"Wordfence","remoteId":"bd54a50b-13ce-43ce-bce1-8fe132abc07e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bd54a50b-13ce-43ce-bce1-8fe132abc07e?source=api-prod","cve":"CVE-2024-13752","affectedVersions":"<=2.6.17","severity":"medium"},{"advisoryId":"WPSECADV/WF/bd625d24-c1e9-465d-896a-bff75d8c534f/wedevs-project-manager","title":"WP Project Manager <= 2.6.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"bd625d24-c1e9-465d-896a-bff75d8c534f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bd625d24-c1e9-465d-896a-bff75d8c534f?source=api-prod","cve":"CVE-2023-49860","affectedVersions":"<=2.6.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/c093ed6a-0f3d-4ad9-a57c-cec1c2e7bd8e/wedevs-project-manager","title":"WP Project Manager <= 2.6.31 - Authenticated (Project Manager+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"c093ed6a-0f3d-4ad9-a57c-cec1c2e7bd8e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c093ed6a-0f3d-4ad9-a57c-cec1c2e7bd8e?source=api-prod","cve":"CVE-2024-12015","affectedVersions":"<=2.6.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/dcc68b62-7dd1-47d4-bbc5-d0237b7c85e7/wedevs-project-manager","title":"WP Project Manager <= 2.6.22 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-10 22:38:47","sources":[{"name":"Wordfence","remoteId":"dcc68b62-7dd1-47d4-bbc5-d0237b7c85e7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dcc68b62-7dd1-47d4-bbc5-d0237b7c85e7?source=api-prod","cve":"CVE-2025-2541","affectedVersions":"<=2.6.22","severity":"medium"},{"advisoryId":"WPSECADV/WF/dea2d045-d3b4-4b55-8b4f-5baa82a18834/wedevs-project-manager","title":"WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 - Insecure Direct Object Reference to Unauthenticated Authorization Bypass\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"dea2d045-d3b4-4b55-8b4f-5baa82a18834"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dea2d045-d3b4-4b55-8b4f-5baa82a18834?source=api-prod","cve":"CVE-2024-10174","affectedVersions":"<=2.6.13","severity":"high"},{"advisoryId":"WPSECADV/WF/e869800a-6fbc-4a1a-97fd-92ecbf3305ff/wedevs-project-manager","title":"Appsero <= 1.2.0 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-12-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"e869800a-6fbc-4a1a-97fd-92ecbf3305ff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e869800a-6fbc-4a1a-97fd-92ecbf3305ff?source=api-prod","cve":"CVE-2022-47150","affectedVersions":"<=2.6.12","severity":"medium"},{"advisoryId":"WPSECADV/WF/ef5859b7-0f15-43ad-9f45-aa846d045f5d/wedevs-project-manager","title":"WP Project Manager <= 2.4.13 - Authenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-11 13:37:00","sources":[{"name":"Wordfence","remoteId":"ef5859b7-0f15-43ad-9f45-aa846d045f5d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ef5859b7-0f15-43ad-9f45-aa846d045f5d?source=api-prod","cve":"CVE-2021-36826","affectedVersions":"<=2.4.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/f83a6631-ff6c-422e-8b6c-49576fadb89f/wedevs-project-manager","title":"WP Project Manager <= 2.6.7 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"f83a6631-ff6c-422e-8b6c-49576fadb89f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f83a6631-ff6c-422e-8b6c-49576fadb89f?source=api-prod","cve":"CVE-2023-40003","affectedVersions":"<=2.6.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/f9e7acc4-8b17-44a8-b20f-4c8f2a36180a/wedevs-project-manager","title":"WP Project Manager <= 2.6.24 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"f9e7acc4-8b17-44a8-b20f-4c8f2a36180a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f9e7acc4-8b17-44a8-b20f-4c8f2a36180a?source=api-prod","cve":"CVE-2025-32280","affectedVersions":"<=2.6.24","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_776f6f2d70726f647563742d66696c746572811c9dc5_gen.json b/internal/data/assets/plugin_776f6f2d70726f647563742d66696c746572811c9dc5_gen.json index 10c0d555..4428a407 100644 --- a/internal/data/assets/plugin_776f6f2d70726f647563742d66696c746572811c9dc5_gen.json +++ b/internal/data/assets/plugin_776f6f2d70726f647563742d66696c746572811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/03b1d518-0e5d-4c28-af04-52611ad583a8/woo-product-filter","title":"Product Filter by WBW <= 3.0.0 - Missing Authorization to Unauthenticated Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-24 17:28:32","sources":[{"name":"Wordfence","remoteId":"03b1d518-0e5d-4c28-af04-52611ad583a8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/03b1d518-0e5d-4c28-af04-52611ad583a8?source=api-prod","cve":"CVE-2025-11269","affectedVersions":"<=3.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/085a4fae-c3f4-45f9-ab30-846c6297d04e/woo-product-filter","title":"Product Filter for WooCommerce by WBW <= 3.1.2 - Missing Authorization to Unauthenticated Filter Data Deletion via TRUNCATE TABLE\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 16:11:48","sources":[{"name":"Wordfence","remoteId":"085a4fae-c3f4-45f9-ab30-846c6297d04e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/085a4fae-c3f4-45f9-ab30-846c6297d04e?source=api-prod","cve":"CVE-2026-3138","affectedVersions":"<=3.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/1057b1ee-9bcb-4b3b-bbc0-3262e658bb97/woo-product-filter","title":"Product Filter for WooCommerce by WBW < 3.1.3 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"1057b1ee-9bcb-4b3b-bbc0-3262e658bb97"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1057b1ee-9bcb-4b3b-bbc0-3262e658bb97?source=api-prod","cve":"CVE-2026-3830","affectedVersions":"<3.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/30b6b0bf-e632-4e83-89ee-a424382534da/woo-product-filter","title":"Product Filter by WooBeWoo <= 1.4.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"30b6b0bf-e632-4e83-89ee-a424382534da"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/30b6b0bf-e632-4e83-89ee-a424382534da?source=api-prod","cve":"CVE-2021-4444","affectedVersions":"<=1.4.9","severity":"high"},{"advisoryId":"WPSECADV/WF/329aae11-a141-4c61-8198-1cd8e4e6bfea/woo-product-filter","title":"Product Filter by WBW <= 2.7.9 - Unauthenticated SQL Injection via filtersDataBackend Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-03 16:22:47","sources":[{"name":"Wordfence","remoteId":"329aae11-a141-4c61-8198-1cd8e4e6bfea"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/329aae11-a141-4c61-8198-1cd8e4e6bfea?source=api-prod","cve":"CVE-2025-2317","affectedVersions":"<=2.7.9","severity":"high"},{"advisoryId":"WPSECADV/WF/463da3d5-f2ec-4cf5-a545-c4ea7b8e7fb3/woo-product-filter","title":"Product Filter for WooCommerce by WBW <= 3.1.2 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"463da3d5-f2ec-4cf5-a545-c4ea7b8e7fb3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/463da3d5-f2ec-4cf5-a545-c4ea7b8e7fb3?source=api-prod","cve":"CVE-2026-39494","affectedVersions":"<=3.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/732311d9-8155-42e0-90e7-faf4668d91ca/woo-product-filter","title":"Product Filter by WBW <= 2.7.0 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"732311d9-8155-42e0-90e7-faf4668d91ca"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/732311d9-8155-42e0-90e7-faf4668d91ca?source=api-prod","cve":"CVE-2024-49691","affectedVersions":"<=2.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/77acb885-1776-4a74-96d0-4edbf1a92917/woo-product-filter","title":"Product Filter by WBW <= 2.5.0 - Missing Authorization via getListForTbl\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"77acb885-1776-4a74-96d0-4edbf1a92917"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/77acb885-1776-4a74-96d0-4edbf1a92917?source=api-prod","cve":"CVE-2023-50877","affectedVersions":"<=2.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/d1533e9a-dcb9-4fbb-a1a7-7f4dafd3a1c8/woo-product-filter","title":"Product Filter by WBW <= 2.9.7 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"d1533e9a-dcb9-4fbb-a1a7-7f4dafd3a1c8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d1533e9a-dcb9-4fbb-a1a7-7f4dafd3a1c8?source=api-prod","cve":"CVE-2025-8416","affectedVersions":"<=2.9.7","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/03b1d518-0e5d-4c28-af04-52611ad583a8/woo-product-filter","title":"Product Filter by WBW <= 3.0.0 - Missing Authorization to Unauthenticated Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-24 17:28:32","sources":[{"name":"Wordfence","remoteId":"03b1d518-0e5d-4c28-af04-52611ad583a8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/03b1d518-0e5d-4c28-af04-52611ad583a8?source=api-prod","cve":"CVE-2025-11269","affectedVersions":"<=3.0.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/085a4fae-c3f4-45f9-ab30-846c6297d04e/woo-product-filter","title":"Product Filter for WooCommerce by WBW <= 3.1.2 - Missing Authorization to Unauthenticated Filter Data Deletion via TRUNCATE TABLE\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 16:11:48","sources":[{"name":"Wordfence","remoteId":"085a4fae-c3f4-45f9-ab30-846c6297d04e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/085a4fae-c3f4-45f9-ab30-846c6297d04e?source=api-prod","cve":"CVE-2026-3138","affectedVersions":"<=3.1.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/1057b1ee-9bcb-4b3b-bbc0-3262e658bb97/woo-product-filter","title":"Product Filter for WooCommerce by WBW < 3.1.3 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"1057b1ee-9bcb-4b3b-bbc0-3262e658bb97"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1057b1ee-9bcb-4b3b-bbc0-3262e658bb97?source=api-prod","cve":"CVE-2026-3830","affectedVersions":"<3.1.3","severity":"high"},{"advisoryId":"WPSECADV/WF/30b6b0bf-e632-4e83-89ee-a424382534da/woo-product-filter","title":"Product Filter by WooBeWoo <= 1.4.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"30b6b0bf-e632-4e83-89ee-a424382534da"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/30b6b0bf-e632-4e83-89ee-a424382534da?source=api-prod","cve":"CVE-2021-4444","affectedVersions":"<=1.4.9","severity":"high"},{"advisoryId":"WPSECADV/WF/329aae11-a141-4c61-8198-1cd8e4e6bfea/woo-product-filter","title":"Product Filter by WBW <= 2.7.9 - Unauthenticated SQL Injection via filtersDataBackend Parameter\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-04-03 16:22:47","sources":[{"name":"Wordfence","remoteId":"329aae11-a141-4c61-8198-1cd8e4e6bfea"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/329aae11-a141-4c61-8198-1cd8e4e6bfea?source=api-prod","cve":"CVE-2025-2317","affectedVersions":"<=2.7.9","severity":"high"},{"advisoryId":"WPSECADV/WF/463da3d5-f2ec-4cf5-a545-c4ea7b8e7fb3/woo-product-filter","title":"Product Filter for WooCommerce by WBW <= 3.1.2 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"463da3d5-f2ec-4cf5-a545-c4ea7b8e7fb3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/463da3d5-f2ec-4cf5-a545-c4ea7b8e7fb3?source=api-prod","cve":"CVE-2026-39494","affectedVersions":"<=3.1.2","severity":"high"},{"advisoryId":"WPSECADV/WF/732311d9-8155-42e0-90e7-faf4668d91ca/woo-product-filter","title":"Product Filter by WBW <= 2.7.0 - Authenticated (Administrator+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"732311d9-8155-42e0-90e7-faf4668d91ca"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/732311d9-8155-42e0-90e7-faf4668d91ca?source=api-prod","cve":"CVE-2024-49691","affectedVersions":"<=2.7.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/77acb885-1776-4a74-96d0-4edbf1a92917/woo-product-filter","title":"Product Filter by WBW <= 2.5.0 - Missing Authorization via getListForTbl\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"77acb885-1776-4a74-96d0-4edbf1a92917"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/77acb885-1776-4a74-96d0-4edbf1a92917?source=api-prod","cve":"CVE-2023-50877","affectedVersions":"<=2.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/d1533e9a-dcb9-4fbb-a1a7-7f4dafd3a1c8/woo-product-filter","title":"Product Filter by WBW <= 2.9.7 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"d1533e9a-dcb9-4fbb-a1a7-7f4dafd3a1c8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d1533e9a-dcb9-4fbb-a1a7-7f4dafd3a1c8?source=api-prod","cve":"CVE-2025-8416","affectedVersions":"<=2.9.7","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_776f6f2d77616c6c6574811c9dc5_gen.json b/internal/data/assets/plugin_776f6f2d77616c6c6574811c9dc5_gen.json index 909bb53b..50d9ce00 100644 --- a/internal/data/assets/plugin_776f6f2d77616c6c6574811c9dc5_gen.json +++ b/internal/data/assets/plugin_776f6f2d77616c6c6574811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/18e24a2e-cbc6-4285-b846-bea513b6ff69/woo-wallet","title":"TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds <= 1.4.10 - Missing Authorization to Authenticated (Subscriber+) User Email Export\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"18e24a2e-cbc6-4285-b846-bea513b6ff69"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/18e24a2e-cbc6-4285-b846-bea513b6ff69?source=api-prod","cve":"CVE-2024-1690","affectedVersions":"<=1.4.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/1e35b077-8bb4-49fb-bd79-d9086d9a26dc/woo-wallet","title":"TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds <= 1.5.0 - Authenticated (Shop Manager+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1e35b077-8bb4-49fb-bd79-d9086d9a26dc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1e35b077-8bb4-49fb-bd79-d9086d9a26dc?source=api-prod","cve":"CVE-2024-32584","affectedVersions":"<=1.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/65189c49-600d-4a69-a687-0ff9e327783e/woo-wallet","title":"TeraWallet – For WooCommerce <= 1.3.24 - Cross-Site Request Forgery via lock_unlock_terawallet\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"65189c49-600d-4a69-a687-0ff9e327783e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/65189c49-600d-4a69-a687-0ff9e327783e?source=api-prod","cve":"CVE-2022-36401","affectedVersions":"<=1.3.24","severity":"high"},{"advisoryId":"WPSECADV/WF/d274f8b1-0f7c-44cc-8063-3d04a33a9404/woo-wallet","title":"TeraWallet – For WooCommerce <= 1.3.24 - Cross-Site Request Forgery via admin_options\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"d274f8b1-0f7c-44cc-8063-3d04a33a9404"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d274f8b1-0f7c-44cc-8063-3d04a33a9404?source=api-prod","cve":"CVE-2022-40198","affectedVersions":"<=1.3.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/ec57e0b2-61b0-4b67-9784-dbb4e6c4e4a6/woo-wallet","title":"TeraWallet – For WooCommerce <= 1.4.3 - Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"ec57e0b2-61b0-4b67-9784-dbb4e6c4e4a6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ec57e0b2-61b0-4b67-9784-dbb4e6c4e4a6?source=api-prod","cve":"CVE-2022-3995","affectedVersions":"<=1.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/f7d5a077-8836-4c28-8884-5047585a99e5/woo-wallet","title":"Wallet for WooCommerce <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'search[value]'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-11 19:55:32","sources":[{"name":"Wordfence","remoteId":"f7d5a077-8836-4c28-8884-5047585a99e5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f7d5a077-8836-4c28-8884-5047585a99e5?source=api-prod","cve":"CVE-2024-6353","affectedVersions":"<=1.5.4","severity":"high"},{"advisoryId":"WPSECADV/WF/fd8f3eb7-ac60-46c4-b41f-5d89e3133042/woo-wallet","title":"Wallet for WooCommerce <= 1.5.6 - Authenticated (Subscriber+) Incorrect Conversion between Numeric Types\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd8f3eb7-ac60-46c4-b41f-5d89e3133042"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd8f3eb7-ac60-46c4-b41f-5d89e3133042?source=api-prod","cve":"CVE-2024-7747","affectedVersions":"<=1.5.6","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/18e24a2e-cbc6-4285-b846-bea513b6ff69/woo-wallet","title":"TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds <= 1.4.10 - Missing Authorization to Authenticated (Subscriber+) User Email Export\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-03-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"18e24a2e-cbc6-4285-b846-bea513b6ff69"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/18e24a2e-cbc6-4285-b846-bea513b6ff69?source=api-prod","cve":"CVE-2024-1690","affectedVersions":"<=1.4.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/1e35b077-8bb4-49fb-bd79-d9086d9a26dc/woo-wallet","title":"TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds <= 1.5.0 - Authenticated (Shop Manager+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1e35b077-8bb4-49fb-bd79-d9086d9a26dc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1e35b077-8bb4-49fb-bd79-d9086d9a26dc?source=api-prod","cve":"CVE-2024-32584","affectedVersions":"<=1.5.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/65189c49-600d-4a69-a687-0ff9e327783e/woo-wallet","title":"TeraWallet – For WooCommerce <= 1.3.24 - Cross-Site Request Forgery via lock_unlock_terawallet\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"65189c49-600d-4a69-a687-0ff9e327783e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/65189c49-600d-4a69-a687-0ff9e327783e?source=api-prod","cve":"CVE-2022-36401","affectedVersions":"<=1.3.24","severity":"high"},{"advisoryId":"WPSECADV/WF/d274f8b1-0f7c-44cc-8063-3d04a33a9404/woo-wallet","title":"TeraWallet – For WooCommerce <= 1.3.24 - Cross-Site Request Forgery via admin_options\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"d274f8b1-0f7c-44cc-8063-3d04a33a9404"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d274f8b1-0f7c-44cc-8063-3d04a33a9404?source=api-prod","cve":"CVE-2022-40198","affectedVersions":"<=1.3.24","severity":"medium"},{"advisoryId":"WPSECADV/WF/e15d7310-90b0-410e-b758-6b142c70d111/woo-wallet","title":"TeraWallet – For WooCommerce <= 1.5.15 - Authenticated (Customer+) Race Condition\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"e15d7310-90b0-410e-b758-6b142c70d111"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e15d7310-90b0-410e-b758-6b142c70d111?source=api-prod","cve":"CVE-2026-32398","affectedVersions":"<=1.5.15","severity":"medium"},{"advisoryId":"WPSECADV/WF/ec57e0b2-61b0-4b67-9784-dbb4e6c4e4a6/woo-wallet","title":"TeraWallet – For WooCommerce <= 1.4.3 - Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2022-10-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"ec57e0b2-61b0-4b67-9784-dbb4e6c4e4a6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ec57e0b2-61b0-4b67-9784-dbb4e6c4e4a6?source=api-prod","cve":"CVE-2022-3995","affectedVersions":"<=1.4.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/f7d5a077-8836-4c28-8884-5047585a99e5/woo-wallet","title":"Wallet for WooCommerce <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'search[value]'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-11 19:55:32","sources":[{"name":"Wordfence","remoteId":"f7d5a077-8836-4c28-8884-5047585a99e5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f7d5a077-8836-4c28-8884-5047585a99e5?source=api-prod","cve":"CVE-2024-6353","affectedVersions":"<=1.5.4","severity":"high"},{"advisoryId":"WPSECADV/WF/fd8f3eb7-ac60-46c4-b41f-5d89e3133042/woo-wallet","title":"Wallet for WooCommerce <= 1.5.6 - Authenticated (Subscriber+) Incorrect Conversion between Numeric Types\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-11-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"fd8f3eb7-ac60-46c4-b41f-5d89e3133042"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fd8f3eb7-ac60-46c4-b41f-5d89e3133042?source=api-prod","cve":"CVE-2024-7747","affectedVersions":"<=1.5.6","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_776f6f636f6d6d657263652d6d65726361646f7061676f811c9dc5_gen.json b/internal/data/assets/plugin_776f6f636f6d6d657263652d6d65726361646f7061676f811c9dc5_gen.json index 591143fe..3d52785e 100644 --- a/internal/data/assets/plugin_776f6f636f6d6d657263652d6d65726361646f7061676f811c9dc5_gen.json +++ b/internal/data/assets/plugin_776f6f636f6d6d657263652d6d65726361646f7061676f811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/1674e81e-6a75-436c-b219-8ec0a484a134/woocommerce-mercadopago","title":"Mercado Pago payments for WooCommerce 7.3.0 - 7.6.1 - Authenticated (Subscriber+) Arbitrary File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-19 15:14:26","sources":[{"name":"Wordfence","remoteId":"1674e81e-6a75-436c-b219-8ec0a484a134"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1674e81e-6a75-436c-b219-8ec0a484a134?source=api-prod","cve":"CVE-2024-3934","affectedVersions":">=7.3.0,<=7.6.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/b20b4eba-54df-4e08-ba4c-96f8bb463125/woocommerce-mercadopago","title":"Mercado Pago payments for WooCommerce <= 6.6.0 - Cross-Site Request Forgery\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"b20b4eba-54df-4e08-ba4c-96f8bb463125"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b20b4eba-54df-4e08-ba4c-96f8bb463125?source=api-prod","affectedVersions":"<=6.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/ce30649a-c1a0-42d5-b2e7-1ebe7989efa3/woocommerce-mercadopago","title":"Mercado Pago payments for WooCommerce <= 6.3.1 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"ce30649a-c1a0-42d5-b2e7-1ebe7989efa3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ce30649a-c1a0-42d5-b2e7-1ebe7989efa3?source=api-prod","cve":"CVE-2022-45068","affectedVersions":"<=6.3.1","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/1674e81e-6a75-436c-b219-8ec0a484a134/woocommerce-mercadopago","title":"Mercado Pago payments for WooCommerce 7.3.0 - 7.6.1 - Authenticated (Subscriber+) Arbitrary File Download\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-07-19 15:14:26","sources":[{"name":"Wordfence","remoteId":"1674e81e-6a75-436c-b219-8ec0a484a134"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1674e81e-6a75-436c-b219-8ec0a484a134?source=api-prod","cve":"CVE-2024-3934","affectedVersions":">=7.3.0,<=7.6.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/986e0252-b94d-4ac8-9083-0218fa8a651e/woocommerce-mercadopago","title":"Mercado Pago payments for WooCommerce <= 8.7.11 - Missing Authorization to Unauthenticated PIX Payment QR Code Image Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-05 15:16:10","sources":[{"name":"Wordfence","remoteId":"986e0252-b94d-4ac8-9083-0218fa8a651e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/986e0252-b94d-4ac8-9083-0218fa8a651e?source=api-prod","cve":"CVE-2026-3208","affectedVersions":"<=8.7.11","severity":"medium"},{"advisoryId":"WPSECADV/WF/b20b4eba-54df-4e08-ba4c-96f8bb463125/woocommerce-mercadopago","title":"Mercado Pago payments for WooCommerce <= 6.6.0 - Cross-Site Request Forgery\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"b20b4eba-54df-4e08-ba4c-96f8bb463125"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b20b4eba-54df-4e08-ba4c-96f8bb463125?source=api-prod","affectedVersions":"<=6.6.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/ce30649a-c1a0-42d5-b2e7-1ebe7989efa3/woocommerce-mercadopago","title":"Mercado Pago payments for WooCommerce <= 6.3.1 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"ce30649a-c1a0-42d5-b2e7-1ebe7989efa3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ce30649a-c1a0-42d5-b2e7-1ebe7989efa3?source=api-prod","cve":"CVE-2022-45068","affectedVersions":"<=6.3.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_776f6f636f6d6d657263652d70686f746f2d72657669657773811c9dc5_gen.json b/internal/data/assets/plugin_776f6f636f6d6d657263652d70686f746f2d72657669657773811c9dc5_gen.json index d16968ab..8d5cbef8 100644 --- a/internal/data/assets/plugin_776f6f636f6d6d657263652d70686f746f2d72657669657773811c9dc5_gen.json +++ b/internal/data/assets/plugin_776f6f636f6d6d657263652d70686f746f2d72657669657773811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/360fee18-5b5c-4aef-958b-915691e939bc/woocommerce-photo-reviews","title":"WooCommerce Photo Reviews - Review Reminders - Review for Discounts <= 1.3.13 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"360fee18-5b5c-4aef-958b-915691e939bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/360fee18-5b5c-4aef-958b-915691e939bc?source=api-prod","cve":"CVE-2025-47570","affectedVersions":"<=1.3.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/a1e2d370-a716-4d6b-8e23-74db2fbd0760/woocommerce-photo-reviews","title":"WooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-10 20:00:49","sources":[{"name":"Wordfence","remoteId":"a1e2d370-a716-4d6b-8e23-74db2fbd0760"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a1e2d370-a716-4d6b-8e23-74db2fbd0760?source=api-prod","cve":"CVE-2024-8277","affectedVersions":"<=1.3.13.2","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/1c874d4a-7ec0-4024-bc05-80160388507c/woocommerce-photo-reviews","title":"WooCommerce Photo Reviews <= 1.4.4 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"1c874d4a-7ec0-4024-bc05-80160388507c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c874d4a-7ec0-4024-bc05-80160388507c?source=api-prod","cve":"CVE-2026-28132","affectedVersions":"<=1.4.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/360fee18-5b5c-4aef-958b-915691e939bc/woocommerce-photo-reviews","title":"WooCommerce Photo Reviews - Review Reminders - Review for Discounts <= 1.3.13 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-03 00:00:00","sources":[{"name":"Wordfence","remoteId":"360fee18-5b5c-4aef-958b-915691e939bc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/360fee18-5b5c-4aef-958b-915691e939bc?source=api-prod","cve":"CVE-2025-47570","affectedVersions":"<=1.3.13","severity":"medium"},{"advisoryId":"WPSECADV/WF/a1e2d370-a716-4d6b-8e23-74db2fbd0760/woocommerce-photo-reviews","title":"WooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-10 20:00:49","sources":[{"name":"Wordfence","remoteId":"a1e2d370-a716-4d6b-8e23-74db2fbd0760"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a1e2d370-a716-4d6b-8e23-74db2fbd0760?source=api-prod","cve":"CVE-2024-8277","affectedVersions":"<=1.3.13.2","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_776f6f7a6f6e65811c9dc5_gen.json b/internal/data/assets/plugin_776f6f7a6f6e65811c9dc5_gen.json index 534a74a2..a513503d 100644 --- a/internal/data/assets/plugin_776f6f7a6f6e65811c9dc5_gen.json +++ b/internal/data/assets/plugin_776f6f7a6f6e65811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0d1ff67c-f644-46d1-abad-e5fc2b177786/woozone","title":"WZone <= 14.0.31 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d1ff67c-f644-46d1-abad-e5fc2b177786"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d1ff67c-f644-46d1-abad-e5fc2b177786?source=api-prod","cve":"CVE-2026-25473","affectedVersions":"<=14.0.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.31 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3?source=api-prod","cve":"CVE-2026-27039","affectedVersions":"<=14.0.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/2621d2f1-7ce3-4858-9633-080ef916d374/woozone","title":"WZone < 14.1.00 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"2621d2f1-7ce3-4858-9633-080ef916d374"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2621d2f1-7ce3-4858-9633-080ef916d374?source=api-prod","cve":"CVE-2024-33547","affectedVersions":"<14.1.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/7193052f-1bef-426c-b0fe-4d70931f47ed/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin < 14.1.00 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7193052f-1bef-426c-b0fe-4d70931f47ed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7193052f-1bef-426c-b0fe-4d70931f47ed?source=api-prod","cve":"CVE-2024-33545","affectedVersions":"<14.1.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin < 14.1.00 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6?source=api-prod","cve":"CVE-2024-33548","affectedVersions":"<14.1.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca88c62d-0f27-40e0-9dd2-21d3d133fda3/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.10 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca88c62d-0f27-40e0-9dd2-21d3d133fda3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca88c62d-0f27-40e0-9dd2-21d3d133fda3?source=api-prod","cve":"CVE-2024-33544","affectedVersions":"<=14.0.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/d1a14fc2-cebe-4a0e-92b0-af2a9c805401/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.10 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d1a14fc2-cebe-4a0e-92b0-af2a9c805401"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d1a14fc2-cebe-4a0e-92b0-af2a9c805401?source=api-prod","cve":"CVE-2024-33546","affectedVersions":"<=14.0.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/d5b110a5-4027-4c98-a348-325c8b9c8405/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin < 14.1.00 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d5b110a5-4027-4c98-a348-325c8b9c8405"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d5b110a5-4027-4c98-a348-325c8b9c8405?source=api-prod","cve":"CVE-2024-33549","affectedVersions":"<14.1.00","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0d1ff67c-f644-46d1-abad-e5fc2b177786/woozone","title":"WZone <= 14.0.31 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"0d1ff67c-f644-46d1-abad-e5fc2b177786"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0d1ff67c-f644-46d1-abad-e5fc2b177786?source=api-prod","cve":"CVE-2026-25473","affectedVersions":"<=14.0.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.31 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3?source=api-prod","cve":"CVE-2026-27039","affectedVersions":"<=14.0.31","severity":"medium"},{"advisoryId":"WPSECADV/WF/2621d2f1-7ce3-4858-9633-080ef916d374/woozone","title":"WZone < 14.1.00 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"2621d2f1-7ce3-4858-9633-080ef916d374"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2621d2f1-7ce3-4858-9633-080ef916d374?source=api-prod","cve":"CVE-2024-33547","affectedVersions":"<14.1.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/7193052f-1bef-426c-b0fe-4d70931f47ed/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin < 14.1.00 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"7193052f-1bef-426c-b0fe-4d70931f47ed"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7193052f-1bef-426c-b0fe-4d70931f47ed?source=api-prod","cve":"CVE-2024-33545","affectedVersions":"<14.1.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/8167b8c1-d365-4b52-9be0-28cbd0f4c36a/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.31 - Authenticated (Subscriber+) Arbitrary File Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"8167b8c1-d365-4b52-9be0-28cbd0f4c36a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8167b8c1-d365-4b52-9be0-28cbd0f4c36a?source=api-prod","cve":"CVE-2026-27040","affectedVersions":"<=14.0.31","severity":"high"},{"advisoryId":"WPSECADV/WF/8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin < 14.1.00 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8abe5885-0f04-4545-a2fe-7aa2a1dcbbe6?source=api-prod","cve":"CVE-2024-33548","affectedVersions":"<14.1.00","severity":"medium"},{"advisoryId":"WPSECADV/WF/ca88c62d-0f27-40e0-9dd2-21d3d133fda3/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.10 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca88c62d-0f27-40e0-9dd2-21d3d133fda3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca88c62d-0f27-40e0-9dd2-21d3d133fda3?source=api-prod","cve":"CVE-2024-33544","affectedVersions":"<=14.0.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/d1a14fc2-cebe-4a0e-92b0-af2a9c805401/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin <= 14.0.10 - Authenticated (Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d1a14fc2-cebe-4a0e-92b0-af2a9c805401"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d1a14fc2-cebe-4a0e-92b0-af2a9c805401?source=api-prod","cve":"CVE-2024-33546","affectedVersions":"<=14.0.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/d5b110a5-4027-4c98-a348-325c8b9c8405/woozone","title":"WooCommerce Amazon Affiliates - Wordpress Plugin < 14.1.00 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d5b110a5-4027-4c98-a348-325c8b9c8405"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d5b110a5-4027-4c98-a348-325c8b9c8405?source=api-prod","cve":"CVE-2024-33549","affectedVersions":"<14.1.00","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77705f657374696d6174696f6e5f666f726d811c9dc5_gen.json b/internal/data/assets/plugin_77705f657374696d6174696f6e5f666f726d811c9dc5_gen.json new file mode 100644 index 00000000..49de825a --- /dev/null +++ b/internal/data/assets/plugin_77705f657374696d6174696f6e5f666f726d811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/0c79e795-0f96-4b20-b4d0-d78fa1aea0f1/wp_estimation_form","title":"WP Cost Estimation < 10.3.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"0c79e795-0f96-4b20-b4d0-d78fa1aea0f1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0c79e795-0f96-4b20-b4d0-d78fa1aea0f1?source=api-prod","cve":"CVE-2026-24363","affectedVersions":"<10.3.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_7770626f6f6b69742d70726f811c9dc5_gen.json b/internal/data/assets/plugin_7770626f6f6b69742d70726f811c9dc5_gen.json index d45b0236..cf00b5db 100644 --- a/internal/data/assets/plugin_7770626f6f6b69742d70726f811c9dc5_gen.json +++ b/internal/data/assets/plugin_7770626f6f6b69742d70726f811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/553f2cd8-9868-4190-91ea-88e03b9ddc3d/wpbookit-pro","title":"WPBookit Pro <= 1.6.18 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"553f2cd8-9868-4190-91ea-88e03b9ddc3d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/553f2cd8-9868-4190-91ea-88e03b9ddc3d?source=api-prod","cve":"CVE-2026-25414","affectedVersions":"<=1.6.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/91c79862-cf85-42ad-9996-f679edab678e/wpbookit-pro","title":"WPBookit Pro <= 1.6.18 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"91c79862-cf85-42ad-9996-f679edab678e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91c79862-cf85-42ad-9996-f679edab678e?source=api-prod","cve":"CVE-2026-25415","affectedVersions":"<=1.6.18","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/528a28e7-cdf9-4dfa-b710-8b934863de91/wpbookit-pro","title":"WPBookit Pro <= 1.6.18 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"528a28e7-cdf9-4dfa-b710-8b934863de91"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/528a28e7-cdf9-4dfa-b710-8b934863de91?source=api-prod","cve":"CVE-2026-25413","affectedVersions":"<=1.6.18","severity":"high"},{"advisoryId":"WPSECADV/WF/553f2cd8-9868-4190-91ea-88e03b9ddc3d/wpbookit-pro","title":"WPBookit Pro <= 1.6.18 - Authenticated (Subscriber+) Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"553f2cd8-9868-4190-91ea-88e03b9ddc3d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/553f2cd8-9868-4190-91ea-88e03b9ddc3d?source=api-prod","cve":"CVE-2026-25414","affectedVersions":"<=1.6.18","severity":"medium"},{"advisoryId":"WPSECADV/WF/91c79862-cf85-42ad-9996-f679edab678e/wpbookit-pro","title":"WPBookit Pro <= 1.6.18 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"91c79862-cf85-42ad-9996-f679edab678e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/91c79862-cf85-42ad-9996-f679edab678e?source=api-prod","cve":"CVE-2026-25415","affectedVersions":"<=1.6.18","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_777073747265616d811c9dc5_gen.json b/internal/data/assets/plugin_777073747265616d811c9dc5_gen.json index 6a7ae040..caef1f10 100644 --- a/internal/data/assets/plugin_777073747265616d811c9dc5_gen.json +++ b/internal/data/assets/plugin_777073747265616d811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/0219851f-7fce-42e0-ba82-77af84b17d9f/wpstream","title":"WpStream – Live Streaming, Video on Demand, Pay Per View <= 4.4.10 - Cross-Site Request Forgery via wpstream_settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"0219851f-7fce-42e0-ba82-77af84b17d9f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0219851f-7fce-42e0-ba82-77af84b17d9f?source=api-prod","cve":"CVE-2023-27458","affectedVersions":"<=4.4.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/3f421fcc-f2e4-43d4-b170-2e3383fe0ad7/wpstream","title":"WpStream <= 4.9.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"3f421fcc-f2e4-43d4-b170-2e3383fe0ad7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3f421fcc-f2e4-43d4-b170-2e3383fe0ad7?source=api-prod","cve":"CVE-2025-68521","affectedVersions":"<=4.9.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/c0ed65f8-a2af-476e-a3f5-51f7b01724f2/wpstream","title":"WpStream <= 4.9.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"c0ed65f8-a2af-476e-a3f5-51f7b01724f2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c0ed65f8-a2af-476e-a3f5-51f7b01724f2?source=api-prod","cve":"CVE-2025-68522","affectedVersions":"<=4.9.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/cf4efae5-d8ea-4c94-bc8a-c73615f2fe62/wpstream","title":"WpStream – Live Streaming, Video on Demand, Pay Per View < 4.11.2 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"cf4efae5-d8ea-4c94-bc8a-c73615f2fe62"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cf4efae5-d8ea-4c94-bc8a-c73615f2fe62?source=api-prod","cve":"CVE-2026-39527","affectedVersions":"<4.11.2","severity":"high"},{"advisoryId":"WPSECADV/WF/d0c91a58-31e9-4f6e-81fb-0681fb9ce4d6/wpstream","title":"WpStream – Live Streaming, Video on Demand, Pay Per View <= 4.5.4 - Cross-Site Request Forgery via wpstream_update_local_event_settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"d0c91a58-31e9-4f6e-81fb-0681fb9ce4d6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d0c91a58-31e9-4f6e-81fb-0681fb9ce4d6?source=api-prod","cve":"CVE-2023-38512","affectedVersions":"<=4.5.4","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/0219851f-7fce-42e0-ba82-77af84b17d9f/wpstream","title":"WpStream – Live Streaming, Video on Demand, Pay Per View <= 4.4.10 - Cross-Site Request Forgery via wpstream_settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"0219851f-7fce-42e0-ba82-77af84b17d9f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0219851f-7fce-42e0-ba82-77af84b17d9f?source=api-prod","cve":"CVE-2023-27458","affectedVersions":"<=4.4.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/3f421fcc-f2e4-43d4-b170-2e3383fe0ad7/wpstream","title":"WpStream <= 4.9.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-29 00:00:00","sources":[{"name":"Wordfence","remoteId":"3f421fcc-f2e4-43d4-b170-2e3383fe0ad7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3f421fcc-f2e4-43d4-b170-2e3383fe0ad7?source=api-prod","cve":"CVE-2025-68521","affectedVersions":"<=4.9.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/6940cfbb-2592-47bf-8e73-6a7cb34ff448/wpstream","title":"WpStream < 4.11.2 - Authenticated (Subscriber+) Insecure Direct Object Reference\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"6940cfbb-2592-47bf-8e73-6a7cb34ff448"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6940cfbb-2592-47bf-8e73-6a7cb34ff448?source=api-prod","cve":"CVE-2026-39526","affectedVersions":"<4.11.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/c0ed65f8-a2af-476e-a3f5-51f7b01724f2/wpstream","title":"WpStream <= 4.9.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-30 00:00:00","sources":[{"name":"Wordfence","remoteId":"c0ed65f8-a2af-476e-a3f5-51f7b01724f2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c0ed65f8-a2af-476e-a3f5-51f7b01724f2?source=api-prod","cve":"CVE-2025-68522","affectedVersions":"<=4.9.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/cf4efae5-d8ea-4c94-bc8a-c73615f2fe62/wpstream","title":"WpStream – Live Streaming, Video on Demand, Pay Per View < 4.11.2 - Authenticated (Subscriber+) Arbitrary File Upload\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-04-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"cf4efae5-d8ea-4c94-bc8a-c73615f2fe62"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cf4efae5-d8ea-4c94-bc8a-c73615f2fe62?source=api-prod","cve":"CVE-2026-39527","affectedVersions":"<4.11.2","severity":"high"},{"advisoryId":"WPSECADV/WF/d0c91a58-31e9-4f6e-81fb-0681fb9ce4d6/wpstream","title":"WpStream – Live Streaming, Video on Demand, Pay Per View <= 4.5.4 - Cross-Site Request Forgery via wpstream_update_local_event_settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"d0c91a58-31e9-4f6e-81fb-0681fb9ce4d6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d0c91a58-31e9-4f6e-81fb-0681fb9ce4d6?source=api-prod","cve":"CVE-2023-38512","affectedVersions":"<=4.5.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_796d6c2d666f722d79616e6465782d6d61726b6574811c9dc5_gen.json b/internal/data/assets/plugin_796d6c2d666f722d79616e6465782d6d61726b6574811c9dc5_gen.json index 6db090f5..53064f90 100644 --- a/internal/data/assets/plugin_796d6c2d666f722d79616e6465782d6d61726b6574811c9dc5_gen.json +++ b/internal/data/assets/plugin_796d6c2d666f722d79616e6465782d6d61726b6574811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/24118410-e5a5-46fa-ac33-ce58cb2f75a3/yml-for-yandex-market","title":"YML for Yandex Market < 5.0.26 - Authenticated (Shop Manager+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"24118410-e5a5-46fa-ac33-ce58cb2f75a3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/24118410-e5a5-46fa-ac33-ce58cb2f75a3?source=api-prod","cve":"CVE-2025-14545","affectedVersions":"<5.0.26","severity":"high"},{"advisoryId":"WPSECADV/WF/a463c5be-13d9-45d8-b43e-54ab188c151a/yml-for-yandex-market","title":"YML for Yandex Market <= 4.7.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"a463c5be-13d9-45d8-b43e-54ab188c151a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a463c5be-13d9-45d8-b43e-54ab188c151a?source=api-prod","cve":"CVE-2024-9378","affectedVersions":"<=4.7.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/a823a21e-78b5-4186-bb67-88799509970d/yml-for-yandex-market","title":"Yml for Yandex Market <= 3.10.7 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"a823a21e-78b5-4186-bb67-88799509970d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a823a21e-78b5-4186-bb67-88799509970d?source=api-prod","cve":"CVE-2023-30473","affectedVersions":"<3.10.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/c343cee6-909d-4c1a-a6e4-f916a2ae223e/yml-for-yandex-market","title":"YML for Yandex Market <= 4.2.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"c343cee6-909d-4c1a-a6e4-f916a2ae223e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c343cee6-909d-4c1a-a6e4-f916a2ae223e?source=api-prod","cve":"CVE-2024-1365","affectedVersions":"<=4.2.3","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/24118410-e5a5-46fa-ac33-ce58cb2f75a3/yml-for-yandex-market","title":"YML for Yandex Market < 5.0.26 - Authenticated (Shop Manager+) Remote Code Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"24118410-e5a5-46fa-ac33-ce58cb2f75a3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/24118410-e5a5-46fa-ac33-ce58cb2f75a3?source=api-prod","cve":"CVE-2025-14545","affectedVersions":"<5.0.26","severity":"high"},{"advisoryId":"WPSECADV/WF/58cc0a13-cda1-499b-b29a-e0b358a2e8e5/yml-for-yandex-market","title":"YML for Yandex Market < 5.3.0 - Authenticated (Shop Manager+) Arbitrary File Deletion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"58cc0a13-cda1-499b-b29a-e0b358a2e8e5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/58cc0a13-cda1-499b-b29a-e0b358a2e8e5?source=api-prod","cve":"CVE-2026-32567","affectedVersions":"<5.3.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/a463c5be-13d9-45d8-b43e-54ab188c151a/yml-for-yandex-market","title":"YML for Yandex Market <= 4.7.2 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-10-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"a463c5be-13d9-45d8-b43e-54ab188c151a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a463c5be-13d9-45d8-b43e-54ab188c151a?source=api-prod","cve":"CVE-2024-9378","affectedVersions":"<=4.7.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/a823a21e-78b5-4186-bb67-88799509970d/yml-for-yandex-market","title":"Yml for Yandex Market <= 3.10.7 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"a823a21e-78b5-4186-bb67-88799509970d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a823a21e-78b5-4186-bb67-88799509970d?source=api-prod","cve":"CVE-2023-30473","affectedVersions":"<3.10.8","severity":"medium"},{"advisoryId":"WPSECADV/WF/c343cee6-909d-4c1a-a6e4-f916a2ae223e/yml-for-yandex-market","title":"YML for Yandex Market <= 4.2.3 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-02-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"c343cee6-909d-4c1a-a6e4-f916a2ae223e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c343cee6-909d-4c1a-a6e4-f916a2ae223e?source=api-prod","cve":"CVE-2024-1365","affectedVersions":"<=4.2.3","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_61726d616e6961811c9dc5_gen.json b/internal/data/assets/theme_61726d616e6961811c9dc5_gen.json new file mode 100644 index 00000000..b9a6b86f --- /dev/null +++ b/internal/data/assets/theme_61726d616e6961811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/bca9d9a2-6c96-4653-9408-2e20f4a9d5f4/armania","title":"Armania <= 1.4.8 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"bca9d9a2-6c96-4653-9408-2e20f4a9d5f4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bca9d9a2-6c96-4653-9408-2e20f4a9d5f4?source=api-prod","cve":"CVE-2026-39626","affectedVersions":"<=1.4.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_626967686561727473811c9dc5_gen.json b/internal/data/assets/theme_626967686561727473811c9dc5_gen.json new file mode 100644 index 00000000..d04a9d75 --- /dev/null +++ b/internal/data/assets/theme_626967686561727473811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/f563b9ee-f33c-4d51-9db7-a3005c290fa7/bighearts","title":"BigHearts <= 3.1.14 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"f563b9ee-f33c-4d51-9db7-a3005c290fa7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f563b9ee-f33c-4d51-9db7-a3005c290fa7?source=api-prod","cve":"CVE-2026-32439","affectedVersions":"<=3.1.14","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_62696f6c696665811c9dc5_gen.json b/internal/data/assets/theme_62696f6c696665811c9dc5_gen.json new file mode 100644 index 00000000..37b9baca --- /dev/null +++ b/internal/data/assets/theme_62696f6c696665811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/84598365-dd46-424b-b6ff-6b8880cadb57/biolife","title":"Biolife <= 3.2.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"84598365-dd46-424b-b6ff-6b8880cadb57"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/84598365-dd46-424b-b6ff-6b8880cadb57?source=api-prod","cve":"CVE-2026-39624","affectedVersions":"<=3.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/c6571ebd-1b28-4670-ad87-3919577f01ad/biolife","title":"Biolife <= 3.2.3 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"c6571ebd-1b28-4670-ad87-3919577f01ad"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c6571ebd-1b28-4670-ad87-3919577f01ad?source=api-prod","cve":"CVE-2026-39623","affectedVersions":"<=3.2.3","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_626c61636b66797265811c9dc5_gen.json b/internal/data/assets/theme_626c61636b66797265811c9dc5_gen.json new file mode 100644 index 00000000..bf26ccf5 --- /dev/null +++ b/internal/data/assets/theme_626c61636b66797265811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/3624f8d7-1dcd-46df-8d9f-b51bb09719f2/blackfyre","title":"Blackfyre <= 2.5.4 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"3624f8d7-1dcd-46df-8d9f-b51bb09719f2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3624f8d7-1dcd-46df-8d9f-b51bb09719f2?source=api-prod","cve":"CVE-2026-39641","affectedVersions":"<=2.5.4","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_626f6c646d616e811c9dc5_gen.json b/internal/data/assets/theme_626f6c646d616e811c9dc5_gen.json new file mode 100644 index 00000000..47de343c --- /dev/null +++ b/internal/data/assets/theme_626f6c646d616e811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/8b411b23-1bf9-4f9f-9791-59dabbd2ce0c/boldman","title":"Boldman <= 7.7 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"8b411b23-1bf9-4f9f-9791-59dabbd2ce0c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8b411b23-1bf9-4f9f-9791-59dabbd2ce0c?source=api-prod","cve":"CVE-2026-32400","affectedVersions":"<=7.7","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_64756b616d61726b6574811c9dc5_gen.json b/internal/data/assets/theme_64756b616d61726b6574811c9dc5_gen.json new file mode 100644 index 00000000..b0be0bbb --- /dev/null +++ b/internal/data/assets/theme_64756b616d61726b6574811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/11e7617d-6d45-4e8d-a82f-fc9da4aeabcf/dukamarket","title":"DukaMarket <= 1.3.0 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"11e7617d-6d45-4e8d-a82f-fc9da4aeabcf"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/11e7617d-6d45-4e8d-a82f-fc9da4aeabcf?source=api-prod","cve":"CVE-2026-39628","affectedVersions":"<=1.3.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_656d706869726573811c9dc5_gen.json b/internal/data/assets/theme_656d706869726573811c9dc5_gen.json new file mode 100644 index 00000000..bd9ebb7d --- /dev/null +++ b/internal/data/assets/theme_656d706869726573811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/9fda8379-0bed-4eae-b3e3-06e35c541323/emphires","title":"Emphires <= 3.9 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"9fda8379-0bed-4eae-b3e3-06e35c541323"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9fda8379-0bed-4eae-b3e3-06e35c541323?source=api-prod","cve":"CVE-2026-39677","affectedVersions":"<=3.9","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_666c6173686d617274811c9dc5_gen.json b/internal/data/assets/theme_666c6173686d617274811c9dc5_gen.json new file mode 100644 index 00000000..5f0e8329 --- /dev/null +++ b/internal/data/assets/theme_666c6173686d617274811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/83d50e66-85d9-4514-9020-96cfcab50d96/flashmart","title":"FlashMart <= 2.0.15 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"83d50e66-85d9-4514-9020-96cfcab50d96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/83d50e66-85d9-4514-9020-96cfcab50d96?source=api-prod","cve":"CVE-2026-28048","affectedVersions":"<=2.0.15","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_666c69706d617274811c9dc5_gen.json b/internal/data/assets/theme_666c69706d617274811c9dc5_gen.json new file mode 100644 index 00000000..aa88bfd7 --- /dev/null +++ b/internal/data/assets/theme_666c69706d617274811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/0beed2f2-3d20-4e09-9db2-129824889839/flipmart","title":"Flipmart <= 2.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-05-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"0beed2f2-3d20-4e09-9db2-129824889839"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0beed2f2-3d20-4e09-9db2-129824889839?source=api-prod","cve":"CVE-2026-39716","affectedVersions":"<=2.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_66726565696f811c9dc5_gen.json b/internal/data/assets/theme_66726565696f811c9dc5_gen.json new file mode 100644 index 00000000..a182643b --- /dev/null +++ b/internal/data/assets/theme_66726565696f811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/54756a32-de66-43e4-9596-c55aaf77fd4e/freeio","title":"Freeio <= 1.3.21 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"54756a32-de66-43e4-9596-c55aaf77fd4e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/54756a32-de66-43e4-9596-c55aaf77fd4e?source=api-prod","cve":"CVE-2026-39679","affectedVersions":"<=1.3.21","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_6735706c75732d617072696c811c9dc5_gen.json b/internal/data/assets/theme_6735706c75732d617072696c811c9dc5_gen.json new file mode 100644 index 00000000..43a0d6aa --- /dev/null +++ b/internal/data/assets/theme_6735706c75732d617072696c811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/3c054aba-0da6-4884-a653-d8e13762d038/g5plus-april","title":"G5Plus April <= 6.8 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"3c054aba-0da6-4884-a653-d8e13762d038"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3c054aba-0da6-4884-a653-d8e13762d038?source=api-prod","cve":"CVE-2026-39714","affectedVersions":"<=6.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_676f6c6f811c9dc5_gen.json b/internal/data/assets/theme_676f6c6f811c9dc5_gen.json index debffcdc..ab915a0e 100644 --- a/internal/data/assets/theme_676f6c6f811c9dc5_gen.json +++ b/internal/data/assets/theme_676f6c6f811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/2c35a558-3915-4689-ab62-942792a93060/golo","title":"Golo <= 1.7.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"2c35a558-3915-4689-ab62-942792a93060"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2c35a558-3915-4689-ab62-942792a93060?source=api-prod","cve":"CVE-2025-54724","affectedVersions":"<=1.7.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/63ab6b17-360d-49b2-b1b5-652629eba3be/golo","title":"Golo - City Travel Guide WordPress Theme <= 1.7.0 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"63ab6b17-360d-49b2-b1b5-652629eba3be"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63ab6b17-360d-49b2-b1b5-652629eba3be?source=api-prod","cve":"CVE-2026-27051","affectedVersions":"<=1.7.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/ca4e2fa0-9b18-4318-b588-33d5bc3c5ab9/golo","title":"Golo < 1.7.5 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca4e2fa0-9b18-4318-b588-33d5bc3c5ab9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca4e2fa0-9b18-4318-b588-33d5bc3c5ab9?source=api-prod","cve":"CVE-2026-23975","affectedVersions":"<1.7.5","severity":"high"},{"advisoryId":"WPSECADV/WF/cf037a61-7e4d-4c20-b868-2fa78950bad3/golo","title":"Golo - City Travel Guide WordPress Theme < 1.3.3 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"cf037a61-7e4d-4c20-b868-2fa78950bad3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cf037a61-7e4d-4c20-b868-2fa78950bad3?source=api-prod","affectedVersions":"<1.3.3","severity":"high"},{"advisoryId":"WPSECADV/WF/e5c99252-ca42-4c93-8f24-c39326f26983/golo","title":"Golo < 1.7.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"e5c99252-ca42-4c93-8f24-c39326f26983"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e5c99252-ca42-4c93-8f24-c39326f26983?source=api-prod","cve":"CVE-2026-23974","affectedVersions":"<1.7.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/e6cb81e5-61a4-4b67-a668-d8a7d46b2cea/golo","title":"Golo - Directory & Listing, Travel WordPress Theme <= 1.6.10 - Missing Authorization to Privilege Escalation via Unauthenticated Arbitrary User Password Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"e6cb81e5-61a4-4b67-a668-d8a7d46b2cea"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e6cb81e5-61a4-4b67-a668-d8a7d46b2cea?source=api-prod","cve":"CVE-2024-12876","affectedVersions":"<=1.6.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/e7b56ec1-8735-4404-8069-219f5d8866d0/golo","title":"Golo <= 1.7.0 - Authentication Bypass to Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-02 16:21:57","sources":[{"name":"Wordfence","remoteId":"e7b56ec1-8735-4404-8069-219f5d8866d0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7b56ec1-8735-4404-8069-219f5d8866d0?source=api-prod","cve":"CVE-2025-4797","affectedVersions":"<=1.7.0","severity":"critical"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/2c35a558-3915-4689-ab62-942792a93060/golo","title":"Golo <= 1.7.1 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-08-26 00:00:00","sources":[{"name":"Wordfence","remoteId":"2c35a558-3915-4689-ab62-942792a93060"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2c35a558-3915-4689-ab62-942792a93060?source=api-prod","cve":"CVE-2025-54724","affectedVersions":"<=1.7.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/5adb9573-eb90-47a1-85c3-c2f60f69f545/golo","title":"Golo - City Travel Guide WordPress Theme < 1.7.5 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"5adb9573-eb90-47a1-85c3-c2f60f69f545"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5adb9573-eb90-47a1-85c3-c2f60f69f545?source=api-prod","cve":"CVE-2026-23973","affectedVersions":"<1.7.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/63ab6b17-360d-49b2-b1b5-652629eba3be/golo","title":"Golo - City Travel Guide WordPress Theme <= 1.7.0 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"63ab6b17-360d-49b2-b1b5-652629eba3be"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/63ab6b17-360d-49b2-b1b5-652629eba3be?source=api-prod","cve":"CVE-2026-27051","affectedVersions":"<=1.7.0","severity":"critical"},{"advisoryId":"WPSECADV/WF/ca4e2fa0-9b18-4318-b588-33d5bc3c5ab9/golo","title":"Golo < 1.7.5 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"ca4e2fa0-9b18-4318-b588-33d5bc3c5ab9"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca4e2fa0-9b18-4318-b588-33d5bc3c5ab9?source=api-prod","cve":"CVE-2026-23975","affectedVersions":"<1.7.5","severity":"high"},{"advisoryId":"WPSECADV/WF/cf037a61-7e4d-4c20-b868-2fa78950bad3/golo","title":"Golo - City Travel Guide WordPress Theme < 1.3.3 - Reflected Cross-Site Scripting\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2020-07-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"cf037a61-7e4d-4c20-b868-2fa78950bad3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cf037a61-7e4d-4c20-b868-2fa78950bad3?source=api-prod","affectedVersions":"<1.3.3","severity":"high"},{"advisoryId":"WPSECADV/WF/e5c99252-ca42-4c93-8f24-c39326f26983/golo","title":"Golo < 1.7.5 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"e5c99252-ca42-4c93-8f24-c39326f26983"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e5c99252-ca42-4c93-8f24-c39326f26983?source=api-prod","cve":"CVE-2026-23974","affectedVersions":"<1.7.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/e6cb81e5-61a4-4b67-a668-d8a7d46b2cea/golo","title":"Golo - Directory & Listing, Travel WordPress Theme <= 1.6.10 - Missing Authorization to Privilege Escalation via Unauthenticated Arbitrary User Password Change\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-03-06 00:00:00","sources":[{"name":"Wordfence","remoteId":"e6cb81e5-61a4-4b67-a668-d8a7d46b2cea"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e6cb81e5-61a4-4b67-a668-d8a7d46b2cea?source=api-prod","cve":"CVE-2024-12876","affectedVersions":"<=1.6.10","severity":"critical"},{"advisoryId":"WPSECADV/WF/e7b56ec1-8735-4404-8069-219f5d8866d0/golo","title":"Golo <= 1.7.0 - Authentication Bypass to Account Takeover\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-02 16:21:57","sources":[{"name":"Wordfence","remoteId":"e7b56ec1-8735-4404-8069-219f5d8866d0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7b56ec1-8735-4404-8069-219f5d8866d0?source=api-prod","cve":"CVE-2025-4797","affectedVersions":"<=1.7.0","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/theme_677261636579811c9dc5_gen.json b/internal/data/assets/theme_677261636579811c9dc5_gen.json new file mode 100644 index 00000000..ae04e48c --- /dev/null +++ b/internal/data/assets/theme_677261636579811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/40c1ff8f-5498-4542-ad3d-e0d44ebc62ce/gracey","title":"Gracey < 1.4 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"40c1ff8f-5498-4542-ad3d-e0d44ebc62ce"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/40c1ff8f-5498-4542-ad3d-e0d44ebc62ce?source=api-prod","cve":"CVE-2026-32509","affectedVersions":"<1.4","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_6772616e6463617272656e74616c811c9dc5_gen.json b/internal/data/assets/theme_6772616e6463617272656e74616c811c9dc5_gen.json new file mode 100644 index 00000000..a06c9465 --- /dev/null +++ b/internal/data/assets/theme_6772616e6463617272656e74616c811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/0a43cc7c-1918-4a5a-a878-52e5d02b784b/grandcarrental","title":"Grand Car Rental <= 3.6.9 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"0a43cc7c-1918-4a5a-a878-52e5d02b784b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0a43cc7c-1918-4a5a-a878-52e5d02b784b?source=api-prod","cve":"CVE-2026-39633","affectedVersions":"<=3.6.9","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_6772616e6470686f746f677261706879811c9dc5_gen.json b/internal/data/assets/theme_6772616e6470686f746f677261706879811c9dc5_gen.json new file mode 100644 index 00000000..f1b3a401 --- /dev/null +++ b/internal/data/assets/theme_6772616e6470686f746f677261706879811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/36c377cc-4169-4f9d-960f-518f7c4191d7/grandphotography","title":"Grand Photography <= 5.7.8 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"36c377cc-4169-4f9d-960f-518f7c4191d7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/36c377cc-4169-4f9d-960f-518f7c4191d7?source=api-prod","cve":"CVE-2026-39603","affectedVersions":"<=5.7.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_6772616e64706f7274666f6c696f811c9dc5_gen.json b/internal/data/assets/theme_6772616e64706f7274666f6c696f811c9dc5_gen.json new file mode 100644 index 00000000..ce7cdbd0 --- /dev/null +++ b/internal/data/assets/theme_6772616e64706f7274666f6c696f811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/206c386c-15c2-4701-a011-e54d0cb3596c/grandportfolio","title":"Grand Portfolio <= 3.3 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"206c386c-15c2-4701-a011-e54d0cb3596c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/206c386c-15c2-4701-a011-e54d0cb3596c?source=api-prod","cve":"CVE-2026-39634","affectedVersions":"<=3.3","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_677265656e6c79811c9dc5_gen.json b/internal/data/assets/theme_677265656e6c79811c9dc5_gen.json new file mode 100644 index 00000000..5bc2fb45 --- /dev/null +++ b/internal/data/assets/theme_677265656e6c79811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/bc84ca1f-747d-444e-b997-a79731b7ab51/greenly","title":"Greenly <= 8.1 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"bc84ca1f-747d-444e-b997-a79731b7ab51"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bc84ca1f-747d-444e-b997-a79731b7ab51?source=api-prod","cve":"CVE-2026-32392","affectedVersions":"<=8.1","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_686f6d656f811c9dc5_gen.json b/internal/data/assets/theme_686f6d656f811c9dc5_gen.json new file mode 100644 index 00000000..05435a76 --- /dev/null +++ b/internal/data/assets/theme_686f6d656f811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/19d12676-dbab-4954-90f7-cd8125bca881/homeo","title":"Homeo <= 1.2.59 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"19d12676-dbab-4954-90f7-cd8125bca881"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/19d12676-dbab-4954-90f7-cd8125bca881?source=api-prod","cve":"CVE-2026-39681","affectedVersions":"<=1.2.59","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_6c616274656368636f811c9dc5_gen.json b/internal/data/assets/theme_6c616274656368636f811c9dc5_gen.json new file mode 100644 index 00000000..dc3d2b7b --- /dev/null +++ b/internal/data/assets/theme_6c616274656368636f811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/e17b3cbe-3c87-4a40-8047-33dba0154f97/labtechco","title":"LabtechCO <= 8.3 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"e17b3cbe-3c87-4a40-8047-33dba0154f97"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e17b3cbe-3c87-4a40-8047-33dba0154f97?source=api-prod","cve":"CVE-2026-39544","affectedVersions":"<=8.3","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_6d6f6769811c9dc5_gen.json b/internal/data/assets/theme_6d6f6769811c9dc5_gen.json new file mode 100644 index 00000000..38041957 --- /dev/null +++ b/internal/data/assets/theme_6d6f6769811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/9ffc69f0-125d-4800-a21d-755219b7eb91/mogi","title":"Mogi <= 1.2.3 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"9ffc69f0-125d-4800-a21d-755219b7eb91"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9ffc69f0-125d-4800-a21d-755219b7eb91?source=api-prod","cve":"CVE-2026-39637","affectedVersions":"<=1.2.3","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_6e616e6f736f6674811c9dc5_gen.json b/internal/data/assets/theme_6e616e6f736f6674811c9dc5_gen.json new file mode 100644 index 00000000..9b593bff --- /dev/null +++ b/internal/data/assets/theme_6e616e6f736f6674811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/ded3a14d-f8ac-46f9-843b-591a6b558556/nanosoft","title":"Nanosoft < 1.3.2 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-19 00:00:00","sources":[{"name":"Wordfence","remoteId":"ded3a14d-f8ac-46f9-843b-591a6b558556"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ded3a14d-f8ac-46f9-843b-591a6b558556?source=api-prod","cve":"CVE-2026-32390","affectedVersions":"<1.3.2","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_6f7267616e6963666f6f64811c9dc5_gen.json b/internal/data/assets/theme_6f7267616e6963666f6f64811c9dc5_gen.json new file mode 100644 index 00000000..79908d8a --- /dev/null +++ b/internal/data/assets/theme_6f7267616e6963666f6f64811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/7065f038-2dd0-447d-bea6-385f6e9657d5/organicfood","title":"OrganicFood <= 3.6.4 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-21 00:00:00","sources":[{"name":"Wordfence","remoteId":"7065f038-2dd0-447d-bea6-385f6e9657d5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7065f038-2dd0-447d-bea6-385f6e9657d5?source=api-prod","cve":"CVE-2026-39684","affectedVersions":"<=3.6.4","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_726565626f78811c9dc5_gen.json b/internal/data/assets/theme_726565626f78811c9dc5_gen.json new file mode 100644 index 00000000..33350244 --- /dev/null +++ b/internal/data/assets/theme_726565626f78811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/773f2b16-3a70-4d06-9a9c-77a787596e37/reebox","title":"Reebox < 1.4.8 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"773f2b16-3a70-4d06-9a9c-77a787596e37"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/773f2b16-3a70-4d06-9a9c-77a787596e37?source=api-prod","cve":"CVE-2026-25354","affectedVersions":"<1.4.8","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_7374657068616e69652d6b696e67811c9dc5_gen.json b/internal/data/assets/theme_7374657068616e69652d6b696e67811c9dc5_gen.json new file mode 100644 index 00000000..fdb14ee1 --- /dev/null +++ b/internal/data/assets/theme_7374657068616e69652d6b696e67811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/46e4b441-651b-4755-a440-1a4496f5c79e/stephanie-king","title":"S.King <= 1.5.3 - Unauthenticated Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"46e4b441-651b-4755-a440-1a4496f5c79e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/46e4b441-651b-4755-a440-1a4496f5c79e?source=api-prod","cve":"CVE-2026-28060","affectedVersions":"<=1.5.3","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/theme_746563686f6e65811c9dc5_gen.json b/internal/data/assets/theme_746563686f6e65811c9dc5_gen.json new file mode 100644 index 00000000..e2eb404a --- /dev/null +++ b/internal/data/assets/theme_746563686f6e65811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/f23dd2d7-3b21-47d6-b6da-24c20c36ee7c/techone","title":"TechOne <= 3.0.3 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"f23dd2d7-3b21-47d6-b6da-24c20c36ee7c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f23dd2d7-3b21-47d6-b6da-24c20c36ee7c?source=api-prod","cve":"CVE-2026-39625","affectedVersions":"<=3.0.3","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_756d696e6578811c9dc5_gen.json b/internal/data/assets/theme_756d696e6578811c9dc5_gen.json new file mode 100644 index 00000000..a00a518c --- /dev/null +++ b/internal/data/assets/theme_756d696e6578811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/d4db7f56-41c7-497a-8e83-460450644d5b/uminex","title":"Uminex <= 1.0.9 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"d4db7f56-41c7-497a-8e83-460450644d5b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d4db7f56-41c7-497a-8e83-460450644d5b?source=api-prod","cve":"CVE-2026-39629","affectedVersions":"<=1.0.9","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_76772d656475636174696f6e2d6c697465811c9dc5_gen.json b/internal/data/assets/theme_76772d656475636174696f6e2d6c697465811c9dc5_gen.json new file mode 100644 index 00000000..5042a174 --- /dev/null +++ b/internal/data/assets/theme_76772d656475636174696f6e2d6c697465811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/b2fc119c-6545-48a5-aa27-852edce50b39/vw-education-lite","title":"VW Education Lite <= 2.2.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"b2fc119c-6545-48a5-aa27-852edce50b39"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b2fc119c-6545-48a5-aa27-852edce50b39?source=api-prod","cve":"CVE-2026-32427","affectedVersions":"<=2.2.0","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_776f6f646d617274811c9dc5_gen.json b/internal/data/assets/theme_776f6f646d617274811c9dc5_gen.json index 6540ac8e..65766a73 100644 --- a/internal/data/assets/theme_776f6f646d617274811c9dc5_gen.json +++ b/internal/data/assets/theme_776f6f646d617274811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/02fde6b1-d709-4329-ae9c-fea444c1aec8/woodmart","title":"Woodmart <= 7.1.1 - Cross-Site Request Forgery to License Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"02fde6b1-d709-4329-ae9c-fea444c1aec8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/02fde6b1-d709-4329-ae9c-fea444c1aec8?source=api-prod","cve":"CVE-2023-32500","affectedVersions":"<=7.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/0e0e0c15-caf6-4166-a365-a2a73cd9ebc4/woodmart","title":"WoodMart <= 7.2.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"0e0e0c15-caf6-4166-a365-a2a73cd9ebc4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e0e0c15-caf6-4166-a365-a2a73cd9ebc4?source=api-prod","cve":"CVE-2023-32240","affectedVersions":"<=7.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/1caa8baa-0783-4bc9-af03-46a3a2cf3538/woodmart","title":"WoodMart <= 8.0.3 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"1caa8baa-0783-4bc9-af03-46a3a2cf3538"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1caa8baa-0783-4bc9-af03-46a3a2cf3538?source=api-prod","cve":"CVE-2024-12333","affectedVersions":"<=8.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/3408895e-3418-4f70-8b7c-76f6ba899d11/woodmart","title":"WoodMart <= 8.2.5 - Unauthenticated Post Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"3408895e-3418-4f70-8b7c-76f6ba899d11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3408895e-3418-4f70-8b7c-76f6ba899d11?source=api-prod","cve":"CVE-2025-6745","affectedVersions":"<=8.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/38f84f31-5aeb-4f6f-9e10-33e365f6f2c8/woodmart","title":"WoodMart <= 8.3.7 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"38f84f31-5aeb-4f6f-9e10-33e365f6f2c8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/38f84f31-5aeb-4f6f-9e10-33e365f6f2c8?source=api-prod","cve":"CVE-2025-47600","affectedVersions":"<=8.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/4b881509-572b-4e2d-9e75-defaa2cc32dc/woodmart","title":"WoodMart <= 8.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-07 17:26:26","sources":[{"name":"Wordfence","remoteId":"4b881509-572b-4e2d-9e75-defaa2cc32dc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4b881509-572b-4e2d-9e75-defaa2cc32dc?source=api-prod","cve":"CVE-2025-6743","affectedVersions":"<=8.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/4ccc2f0c-07d5-45a5-86ec-1e6b6c5a316d/woodmart","title":"WoodMart < 8.3.2 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"4ccc2f0c-07d5-45a5-86ec-1e6b6c5a316d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ccc2f0c-07d5-45a5-86ec-1e6b6c5a316d?source=api-prod","cve":"CVE-2025-49935","affectedVersions":"<8.3.2","severity":"high"},{"advisoryId":"WPSECADV/WF/6fc92b8f-6794-461a-b6b6-598de21f5e2d/woodmart","title":"WoodMart <= 7.2.4 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"6fc92b8f-6794-461a-b6b6-598de21f5e2d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6fc92b8f-6794-461a-b6b6-598de21f5e2d?source=api-prod","cve":"CVE-2023-41872","affectedVersions":"<=7.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/73017e92-d95e-4b9c-a44a-779b498f58b7/woodmart","title":"WoodMart <= 7.1.1 - Missing Authorization to Shortcode Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"73017e92-d95e-4b9c-a44a-779b498f58b7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/73017e92-d95e-4b9c-a44a-779b498f58b7?source=api-prod","cve":"CVE-2023-25790","affectedVersions":"<=7.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8923d9c9-7af6-4109-9c39-b5faee57f8e1/woodmart","title":"Woodmart <= 8.3.8 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"8923d9c9-7af6-4109-9c39-b5faee57f8e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8923d9c9-7af6-4109-9c39-b5faee57f8e1?source=api-prod","cve":"CVE-2026-23971","affectedVersions":"<=8.3.8","severity":"high"},{"advisoryId":"WPSECADV/WF/98c1363e-b25d-46fc-b6bf-0285a37f748c/woodmart","title":"WoodMart <= 8.2.3 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-07 17:24:44","sources":[{"name":"Wordfence","remoteId":"98c1363e-b25d-46fc-b6bf-0285a37f748c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/98c1363e-b25d-46fc-b6bf-0285a37f748c?source=api-prod","cve":"CVE-2025-6746","affectedVersions":"<=8.2.3","severity":"high"},{"advisoryId":"WPSECADV/WF/b030aa28-5310-4f69-8b86-7e0b0bae741b/woodmart","title":"WoodMart - Multipurpose WooCommerce Theme <= 8.2.6 - Improper Input Validation Leading to Unauthenticated Cart Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"b030aa28-5310-4f69-8b86-7e0b0bae741b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b030aa28-5310-4f69-8b86-7e0b0bae741b?source=api-prod","cve":"CVE-2025-8097","affectedVersions":"<=8.2.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/cb1db880-0942-4fac-a548-8b6a28dce8c0/woodmart","title":"Woodmart <= 7.0.4 - Unauthenticated Arbitrary Content Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"cb1db880-0942-4fac-a548-8b6a28dce8c0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cb1db880-0942-4fac-a548-8b6a28dce8c0?source=api-prod","cve":"CVE-2023-25790","affectedVersions":"<=7.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/d9906492-971c-48c3-adb4-e408a7550fff/woodmart","title":"WoodMart < 8.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"d9906492-971c-48c3-adb4-e408a7550fff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d9906492-971c-48c3-adb4-e408a7550fff?source=api-prod","cve":"CVE-2025-49936","affectedVersions":"<8.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/dd056d29-3bd9-49e4-bcc4-fa487de8a27e/woodmart","title":"Woodmart <= 8.2.3 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"dd056d29-3bd9-49e4-bcc4-fa487de8a27e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dd056d29-3bd9-49e4-bcc4-fa487de8a27e?source=api-prod","cve":"CVE-2025-6744","affectedVersions":"<=8.2.3","severity":"high"},{"advisoryId":"WPSECADV/WF/f9a60c4e-a524-4a99-858a-14787f37d60c/woodmart","title":"WoodMart <= 7.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"f9a60c4e-a524-4a99-858a-14787f37d60c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f9a60c4e-a524-4a99-858a-14787f37d60c?source=api-prod","cve":"CVE-2023-32239","affectedVersions":"<=7.2.1","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/02fde6b1-d709-4329-ae9c-fea444c1aec8/woodmart","title":"Woodmart <= 7.1.1 - Cross-Site Request Forgery to License Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"02fde6b1-d709-4329-ae9c-fea444c1aec8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/02fde6b1-d709-4329-ae9c-fea444c1aec8?source=api-prod","cve":"CVE-2023-32500","affectedVersions":"<=7.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/0e0e0c15-caf6-4166-a365-a2a73cd9ebc4/woodmart","title":"WoodMart <= 7.2.1 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"0e0e0c15-caf6-4166-a365-a2a73cd9ebc4"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e0e0c15-caf6-4166-a365-a2a73cd9ebc4?source=api-prod","cve":"CVE-2023-32240","affectedVersions":"<=7.2.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/156581cb-f3d8-4253-af4d-cdc59b95d763/woodmart","title":"WoodMart <= 8.3.9 - Unauthenticated Sensitive Information Exposure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-22 00:00:00","sources":[{"name":"Wordfence","remoteId":"156581cb-f3d8-4253-af4d-cdc59b95d763"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/156581cb-f3d8-4253-af4d-cdc59b95d763?source=api-prod","cve":"CVE-2026-32405","affectedVersions":"<=8.3.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/1caa8baa-0783-4bc9-af03-46a3a2cf3538/woodmart","title":"WoodMart <= 8.0.3 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-12-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"1caa8baa-0783-4bc9-af03-46a3a2cf3538"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1caa8baa-0783-4bc9-af03-46a3a2cf3538?source=api-prod","cve":"CVE-2024-12333","affectedVersions":"<=8.0.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/3408895e-3418-4f70-8b7c-76f6ba899d11/woodmart","title":"WoodMart <= 8.2.5 - Unauthenticated Post Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"3408895e-3418-4f70-8b7c-76f6ba899d11"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3408895e-3418-4f70-8b7c-76f6ba899d11?source=api-prod","cve":"CVE-2025-6745","affectedVersions":"<=8.2.5","severity":"medium"},{"advisoryId":"WPSECADV/WF/38f84f31-5aeb-4f6f-9e10-33e365f6f2c8/woodmart","title":"WoodMart <= 8.3.7 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"38f84f31-5aeb-4f6f-9e10-33e365f6f2c8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/38f84f31-5aeb-4f6f-9e10-33e365f6f2c8?source=api-prod","cve":"CVE-2025-47600","affectedVersions":"<=8.3.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/4b881509-572b-4e2d-9e75-defaa2cc32dc/woodmart","title":"WoodMart <= 8.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-07 17:26:26","sources":[{"name":"Wordfence","remoteId":"4b881509-572b-4e2d-9e75-defaa2cc32dc"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4b881509-572b-4e2d-9e75-defaa2cc32dc?source=api-prod","cve":"CVE-2025-6743","affectedVersions":"<=8.2.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/4ccc2f0c-07d5-45a5-86ec-1e6b6c5a316d/woodmart","title":"WoodMart < 8.3.2 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"4ccc2f0c-07d5-45a5-86ec-1e6b6c5a316d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ccc2f0c-07d5-45a5-86ec-1e6b6c5a316d?source=api-prod","cve":"CVE-2025-49935","affectedVersions":"<8.3.2","severity":"high"},{"advisoryId":"WPSECADV/WF/6fc92b8f-6794-461a-b6b6-598de21f5e2d/woodmart","title":"WoodMart <= 7.2.4 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-09-05 00:00:00","sources":[{"name":"Wordfence","remoteId":"6fc92b8f-6794-461a-b6b6-598de21f5e2d"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6fc92b8f-6794-461a-b6b6-598de21f5e2d?source=api-prod","cve":"CVE-2023-41872","affectedVersions":"<=7.2.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/73017e92-d95e-4b9c-a44a-779b498f58b7/woodmart","title":"WoodMart <= 7.1.1 - Missing Authorization to Shortcode Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-03-01 00:00:00","sources":[{"name":"Wordfence","remoteId":"73017e92-d95e-4b9c-a44a-779b498f58b7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/73017e92-d95e-4b9c-a44a-779b498f58b7?source=api-prod","cve":"CVE-2023-25790","affectedVersions":"<=7.1.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8923d9c9-7af6-4109-9c39-b5faee57f8e1/woodmart","title":"Woodmart <= 8.3.8 - Unauthenticated PHP Object Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-23 00:00:00","sources":[{"name":"Wordfence","remoteId":"8923d9c9-7af6-4109-9c39-b5faee57f8e1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8923d9c9-7af6-4109-9c39-b5faee57f8e1?source=api-prod","cve":"CVE-2026-23971","affectedVersions":"<=8.3.8","severity":"high"},{"advisoryId":"WPSECADV/WF/98c1363e-b25d-46fc-b6bf-0285a37f748c/woodmart","title":"WoodMart <= 8.2.3 - Authenticated (Contributor+) Local File Inclusion\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-07 17:24:44","sources":[{"name":"Wordfence","remoteId":"98c1363e-b25d-46fc-b6bf-0285a37f748c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/98c1363e-b25d-46fc-b6bf-0285a37f748c?source=api-prod","cve":"CVE-2025-6746","affectedVersions":"<=8.2.3","severity":"high"},{"advisoryId":"WPSECADV/WF/b030aa28-5310-4f69-8b86-7e0b0bae741b/woodmart","title":"WoodMart - Multipurpose WooCommerce Theme <= 8.2.6 - Improper Input Validation Leading to Unauthenticated Cart Manipulation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"b030aa28-5310-4f69-8b86-7e0b0bae741b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b030aa28-5310-4f69-8b86-7e0b0bae741b?source=api-prod","cve":"CVE-2025-8097","affectedVersions":"<=8.2.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/cb1db880-0942-4fac-a548-8b6a28dce8c0/woodmart","title":"Woodmart <= 7.0.4 - Unauthenticated Arbitrary Content Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-02-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"cb1db880-0942-4fac-a548-8b6a28dce8c0"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cb1db880-0942-4fac-a548-8b6a28dce8c0?source=api-prod","cve":"CVE-2023-25790","affectedVersions":"<=7.0.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/d9906492-971c-48c3-adb4-e408a7550fff/woodmart","title":"WoodMart < 8.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-10-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"d9906492-971c-48c3-adb4-e408a7550fff"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d9906492-971c-48c3-adb4-e408a7550fff?source=api-prod","cve":"CVE-2025-49936","affectedVersions":"<8.3.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/dd056d29-3bd9-49e4-bcc4-fa487de8a27e/woodmart","title":"Woodmart <= 8.2.3 - Unauthenticated Arbitrary Shortcode Execution\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-07-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"dd056d29-3bd9-49e4-bcc4-fa487de8a27e"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/dd056d29-3bd9-49e4-bcc4-fa487de8a27e?source=api-prod","cve":"CVE-2025-6744","affectedVersions":"<=8.2.3","severity":"high"},{"advisoryId":"WPSECADV/WF/f9a60c4e-a524-4a99-858a-14787f37d60c/woodmart","title":"WoodMart <= 7.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-11 00:00:00","sources":[{"name":"Wordfence","remoteId":"f9a60c4e-a524-4a99-858a-14787f37d60c"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f9a60c4e-a524-4a99-858a-14787f37d60c?source=api-prod","cve":"CVE-2023-32239","affectedVersions":"<=7.2.1","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets/theme_796f62617a6172811c9dc5_gen.json b/internal/data/assets/theme_796f62617a6172811c9dc5_gen.json new file mode 100644 index 00000000..ada6f994 --- /dev/null +++ b/internal/data/assets/theme_796f62617a6172811c9dc5_gen.json @@ -0,0 +1 @@ +[{"advisoryId":"WPSECADV/WF/58afd7cf-1d17-41e7-9bd3-9485bd733c6b/yobazar","title":"Yobazar < 1.6.7 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-20 00:00:00","sources":[{"name":"Wordfence","remoteId":"58afd7cf-1d17-41e7-9bd3-9485bd733c6b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/58afd7cf-1d17-41e7-9bd3-9485bd733c6b?source=api-prod","cve":"CVE-2026-25356","affectedVersions":"<1.6.7","severity":"medium"}] \ No newline at end of file diff --git a/internal/data/assets_gen.go b/internal/data/assets_gen.go index a270ddf1..eebbb77e 100644 --- a/internal/data/assets_gen.go +++ b/internal/data/assets_gen.go @@ -240,6 +240,8 @@ var ( theme_61726b6865811c9dc5 []byte //go:embed assets/theme_61726c6f811c9dc5_gen.json theme_61726c6f811c9dc5 []byte + //go:embed assets/theme_61726d616e6961811c9dc5_gen.json + theme_61726d616e6961811c9dc5 []byte //go:embed assets/theme_61726f6d6174696361811c9dc5_gen.json theme_61726f6d6174696361811c9dc5 []byte //go:embed assets/theme_6172726976616c811c9dc5_gen.json @@ -402,6 +404,8 @@ var ( theme_62696379636c6573686f70811c9dc5 []byte //go:embed assets/theme_6269672d73746f7265811c9dc5_gen.json theme_6269672d73746f7265811c9dc5 []byte + //go:embed assets/theme_626967686561727473811c9dc5_gen.json + theme_626967686561727473811c9dc5 []byte //go:embed assets/theme_62696c6c6579811c9dc5_gen.json theme_62696c6c6579811c9dc5 []byte //go:embed assets/theme_62696d626572811c9dc5_gen.json @@ -410,12 +414,16 @@ var ( theme_62696e676c65811c9dc5 []byte //go:embed assets/theme_62696e676f7072657373811c9dc5_gen.json theme_62696e676f7072657373811c9dc5 []byte + //go:embed assets/theme_62696f6c696665811c9dc5_gen.json + theme_62696f6c696665811c9dc5 []byte //go:embed assets/theme_62697264696c79811c9dc5_gen.json theme_62697264696c79811c9dc5 []byte //go:embed assets/theme_626c6162626572811c9dc5_gen.json theme_626c6162626572811c9dc5 []byte //go:embed assets/theme_626c61636b2d6c657474657268656164811c9dc5_gen.json theme_626c61636b2d6c657474657268656164811c9dc5 []byte + //go:embed assets/theme_626c61636b66797265811c9dc5_gen.json + theme_626c61636b66797265811c9dc5 []byte //go:embed assets/theme_626c61696e811c9dc5_gen.json theme_626c61696e811c9dc5 []byte //go:embed assets/theme_626c616e6b612d7770811c9dc5_gen.json @@ -476,6 +484,8 @@ var ( theme_626c7565737472656574811c9dc5 []byte //go:embed assets/theme_626f647963656e746572811c9dc5_gen.json theme_626f647963656e746572811c9dc5 []byte + //go:embed assets/theme_626f6c646d616e811c9dc5_gen.json + theme_626f6c646d616e811c9dc5 []byte //go:embed assets/theme_626f6c6479811c9dc5_gen.json theme_626f6c6479811c9dc5 []byte //go:embed assets/theme_626f6c69696e811c9dc5_gen.json @@ -1076,6 +1086,8 @@ var ( theme_64742d63686f636f6c617465811c9dc5 []byte //go:embed assets/theme_64742d74686537811c9dc5_gen.json theme_64742d74686537811c9dc5 []byte + //go:embed assets/theme_64756b616d61726b6574811c9dc5_gen.json + theme_64756b616d61726b6574811c9dc5 []byte //go:embed assets/theme_6477656c6c811c9dc5_gen.json theme_6477656c6c811c9dc5 []byte //go:embed assets/theme_6477742d6c697374696e67811c9dc5_gen.json @@ -1192,6 +1204,8 @@ var ( theme_656d6d65742d6c697465811c9dc5 []byte //go:embed assets/theme_656d6f6a696e6174696f6e811c9dc5_gen.json theme_656d6f6a696e6174696f6e811c9dc5 []byte + //go:embed assets/theme_656d706869726573811c9dc5_gen.json + theme_656d706869726573811c9dc5 []byte //go:embed assets/theme_656d706f7765726d656e74811c9dc5_gen.json theme_656d706f7765726d656e74811c9dc5 []byte //go:embed assets/theme_656d706f7765727770811c9dc5_gen.json @@ -1364,6 +1378,8 @@ var ( theme_666c6170811c9dc5 []byte //go:embed assets/theme_666c6173686c69676874811c9dc5_gen.json theme_666c6173686c69676874811c9dc5 []byte + //go:embed assets/theme_666c6173686d617274811c9dc5_gen.json + theme_666c6173686d617274811c9dc5 []byte //go:embed assets/theme_666c6173686e657773811c9dc5_gen.json theme_666c6173686e657773811c9dc5 []byte //go:embed assets/theme_666c61736879811c9dc5_gen.json @@ -1376,6 +1392,8 @@ var ( theme_666c657572811c9dc5 []byte //go:embed assets/theme_666c65782d6d6167811c9dc5_gen.json theme_666c65782d6d6167811c9dc5 []byte + //go:embed assets/theme_666c69706d617274811c9dc5_gen.json + theme_666c69706d617274811c9dc5 []byte //go:embed assets/theme_666c6978697461811c9dc5_gen.json theme_666c6978697461811c9dc5 []byte //go:embed assets/theme_666c6f7a656e2d7468656d65811c9dc5_gen.json @@ -1422,6 +1440,8 @@ var ( theme_667261707065811c9dc5 []byte //go:embed assets/theme_667265656167656e74811c9dc5_gen.json theme_667265656167656e74811c9dc5 []byte + //go:embed assets/theme_66726565696f811c9dc5_gen.json + theme_66726565696f811c9dc5 []byte //go:embed assets/theme_667265657369612d656d70697265811c9dc5_gen.json theme_667265657369612d656d70697265811c9dc5 []byte //go:embed assets/theme_66726569676874636f811c9dc5_gen.json @@ -1444,6 +1464,8 @@ var ( theme_667573696f6e2d64656c6973746564811c9dc5 []byte //go:embed assets/theme_667764657670811c9dc5_gen.json theme_667764657670811c9dc5 []byte + //go:embed assets/theme_6735706c75732d617072696c811c9dc5_gen.json + theme_6735706c75732d617072696c811c9dc5 []byte //go:embed assets/theme_6761626c65811c9dc5_gen.json theme_6761626c65811c9dc5 []byte //go:embed assets/theme_67616561811c9dc5_gen.json @@ -1530,16 +1552,24 @@ var ( theme_676f7a612d7468656d65811c9dc5 []byte //go:embed assets/theme_67726163652d6d6167811c9dc5_gen.json theme_67726163652d6d6167811c9dc5 []byte + //go:embed assets/theme_677261636579811c9dc5_gen.json + theme_677261636579811c9dc5 []byte //go:embed assets/theme_67726163696f7a61811c9dc5_gen.json theme_67726163696f7a61811c9dc5 []byte //go:embed assets/theme_6772616e64626c6f67811c9dc5_gen.json theme_6772616e64626c6f67811c9dc5 []byte + //go:embed assets/theme_6772616e6463617272656e74616c811c9dc5_gen.json + theme_6772616e6463617272656e74616c811c9dc5 []byte //go:embed assets/theme_6772616e64636f6e666572656e6365811c9dc5_gen.json theme_6772616e64636f6e666572656e6365811c9dc5 []byte //go:embed assets/theme_6772616e646d6167617a696e65811c9dc5_gen.json theme_6772616e646d6167617a696e65811c9dc5 []byte //go:embed assets/theme_6772616e646e657773811c9dc5_gen.json theme_6772616e646e657773811c9dc5 []byte + //go:embed assets/theme_6772616e6470686f746f677261706879811c9dc5_gen.json + theme_6772616e6470686f746f677261706879811c9dc5 []byte + //go:embed assets/theme_6772616e64706f7274666f6c696f811c9dc5_gen.json + theme_6772616e64706f7274666f6c696f811c9dc5 []byte //go:embed assets/theme_6772616e6470726978811c9dc5_gen.json theme_6772616e6470726978811c9dc5 []byte //go:embed assets/theme_6772616e6472657374617572616e74811c9dc5_gen.json @@ -1562,6 +1592,8 @@ var ( theme_677265656e2d706c616e6574811c9dc5 []byte //go:embed assets/theme_677265656e696679811c9dc5_gen.json theme_677265656e696679811c9dc5 []byte + //go:embed assets/theme_677265656e6c79811c9dc5_gen.json + theme_677265656e6c79811c9dc5 []byte //go:embed assets/theme_677265656e6d617274811c9dc5_gen.json theme_677265656e6d617274811c9dc5 []byte //go:embed assets/theme_677265656e6f7267616e6963811c9dc5_gen.json @@ -1694,6 +1726,8 @@ var ( theme_686f6d652d7365727669636573811c9dc5 []byte //go:embed assets/theme_686f6d656c616e636572811c9dc5_gen.json theme_686f6d656c616e636572811c9dc5 []byte + //go:embed assets/theme_686f6d656f811c9dc5_gen.json + theme_686f6d656f811c9dc5 []byte //go:embed assets/theme_686f6d65726f6f666572811c9dc5_gen.json theme_686f6d65726f6f666572811c9dc5 []byte //go:embed assets/theme_686f6d657377656574811c9dc5_gen.json @@ -1998,6 +2032,8 @@ var ( theme_6c6162811c9dc5 []byte //go:embed assets/theme_6c61626f6f6d811c9dc5_gen.json theme_6c61626f6f6d811c9dc5 []byte + //go:embed assets/theme_6c616274656368636f811c9dc5_gen.json + theme_6c616274656368636f811c9dc5 []byte //go:embed assets/theme_6c61666b61811c9dc5_gen.json theme_6c61666b61811c9dc5 []byte //go:embed assets/theme_6c6172736f6e811c9dc5_gen.json @@ -2296,6 +2332,8 @@ var ( theme_6d6f64696e73811c9dc5 []byte //go:embed assets/theme_6d6f64756c6172811c9dc5_gen.json theme_6d6f64756c6172811c9dc5 []byte + //go:embed assets/theme_6d6f6769811c9dc5_gen.json + theme_6d6f6769811c9dc5 []byte //go:embed assets/theme_6d6f6c6c61811c9dc5_gen.json theme_6d6f6c6c61811c9dc5 []byte //go:embed assets/theme_6d6f6d656e7473811c9dc5_gen.json @@ -2392,6 +2430,8 @@ var ( theme_6e372d676f6c662d636c7562811c9dc5 []byte //go:embed assets/theme_6e616d616861811c9dc5_gen.json theme_6e616d616861811c9dc5 []byte + //go:embed assets/theme_6e616e6f736f6674811c9dc5_gen.json + theme_6e616e6f736f6674811c9dc5 []byte //go:embed assets/theme_6e6174697665636875726368811c9dc5_gen.json theme_6e6174697665636875726368811c9dc5 []byte //go:embed assets/theme_6e61747572656d61672d6c697465811c9dc5_gen.json @@ -2584,6 +2624,8 @@ var ( theme_6f72636869642d73746f7265811c9dc5 []byte //go:embed assets/theme_6f7267616e69632d626561757479811c9dc5_gen.json theme_6f7267616e69632d626561757479811c9dc5 []byte + //go:embed assets/theme_6f7267616e6963666f6f64811c9dc5_gen.json + theme_6f7267616e6963666f6f64811c9dc5 []byte //go:embed assets/theme_6f7267617269756d811c9dc5_gen.json theme_6f7267617269756d811c9dc5 []byte //go:embed assets/theme_6f7368696e811c9dc5_gen.json @@ -2928,6 +2970,8 @@ var ( theme_726564737465656c811c9dc5 []byte //go:embed assets/theme_72656479811c9dc5_gen.json theme_72656479811c9dc5 []byte + //go:embed assets/theme_726565626f78811c9dc5_gen.json + theme_726565626f78811c9dc5 []byte //go:embed assets/theme_72656672616374696f6e811c9dc5_gen.json theme_72656672616374696f6e811c9dc5 []byte //go:embed assets/theme_726567616e746f2d7468656d65811c9dc5_gen.json @@ -3356,6 +3400,8 @@ var ( theme_737461727475707a79811c9dc5 []byte //go:embed assets/theme_73746174666f7274811c9dc5_gen.json theme_73746174666f7274811c9dc5 []byte + //go:embed assets/theme_7374657068616e69652d6b696e67811c9dc5_gen.json + theme_7374657068616e69652d6b696e67811c9dc5 []byte //go:embed assets/theme_73746576656e7761746b696e73811c9dc5_gen.json theme_73746576656e7761746b696e73811c9dc5 []byte //go:embed assets/theme_73746f636b686f6c6d811c9dc5_gen.json @@ -3444,6 +3490,8 @@ var ( theme_7465617264726f70811c9dc5 []byte //go:embed assets/theme_746563686c696e6b811c9dc5_gen.json theme_746563686c696e6b811c9dc5 []byte + //go:embed assets/theme_746563686f6e65811c9dc5_gen.json + theme_746563686f6e65811c9dc5 []byte //go:embed assets/theme_746564697373811c9dc5_gen.json theme_746564697373811c9dc5 []byte //go:embed assets/theme_74656c75726f811c9dc5_gen.json @@ -3642,6 +3690,8 @@ var ( theme_756c7472617072657373811c9dc5 []byte //go:embed assets/theme_756d626572746f811c9dc5_gen.json theme_756d626572746f811c9dc5 []byte + //go:embed assets/theme_756d696e6578811c9dc5_gen.json + theme_756d696e6578811c9dc5 []byte //go:embed assets/theme_756e616b6974811c9dc5_gen.json theme_756e616b6974811c9dc5 []byte //go:embed assets/theme_756e636f6465811c9dc5_gen.json @@ -3780,6 +3830,8 @@ var ( theme_766f696365811c9dc5 []byte //go:embed assets/theme_76772d6175746f6d6f62696c652d6c697465811c9dc5_gen.json theme_76772d6175746f6d6f62696c652d6c697465811c9dc5 []byte + //go:embed assets/theme_76772d656475636174696f6e2d6c697465811c9dc5_gen.json + theme_76772d656475636174696f6e2d6c697465811c9dc5 []byte //go:embed assets/theme_76772d6669746e657373811c9dc5_gen.json theme_76772d6669746e657373811c9dc5 []byte //go:embed assets/theme_76772d7065742d73686f70811c9dc5_gen.json @@ -3962,6 +4014,8 @@ var ( theme_7961616275726e65652d7468656d6573811c9dc5 []byte //go:embed assets/theme_79616368742d72656e74616c811c9dc5_gen.json theme_79616368742d72656e74616c811c9dc5 []byte + //go:embed assets/theme_796f62617a6172811c9dc5_gen.json + theme_796f62617a6172811c9dc5 []byte //go:embed assets/theme_796f6769811c9dc5_gen.json theme_796f6769811c9dc5 []byte //go:embed assets/theme_796f6b6f6f811c9dc5_gen.json @@ -4258,6 +4312,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_61726b6865811c9dc5, nil case "arlo": return theme_61726c6f811c9dc5, nil + case "armania": + return theme_61726d616e6961811c9dc5, nil case "aromatica": return theme_61726f6d6174696361811c9dc5, nil case "arrival": @@ -4420,6 +4476,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_62696379636c6573686f70811c9dc5, nil case "big-store": return theme_6269672d73746f7265811c9dc5, nil + case "bighearts": + return theme_626967686561727473811c9dc5, nil case "billey": return theme_62696c6c6579811c9dc5, nil case "bimber": @@ -4428,12 +4486,16 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_62696e676c65811c9dc5, nil case "bingopress": return theme_62696e676f7072657373811c9dc5, nil + case "biolife": + return theme_62696f6c696665811c9dc5, nil case "birdily": return theme_62697264696c79811c9dc5, nil case "blabber": return theme_626c6162626572811c9dc5, nil case "black-letterhead": return theme_626c61636b2d6c657474657268656164811c9dc5, nil + case "blackfyre": + return theme_626c61636b66797265811c9dc5, nil case "blain": return theme_626c61696e811c9dc5, nil case "blanka-wp": @@ -4494,6 +4556,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_626c7565737472656574811c9dc5, nil case "bodycenter": return theme_626f647963656e746572811c9dc5, nil + case "boldman": + return theme_626f6c646d616e811c9dc5, nil case "boldy": return theme_626f6c6479811c9dc5, nil case "boliin": @@ -5094,6 +5158,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_64742d63686f636f6c617465811c9dc5, nil case "dt-the7": return theme_64742d74686537811c9dc5, nil + case "dukamarket": + return theme_64756b616d61726b6574811c9dc5, nil case "dwell": return theme_6477656c6c811c9dc5, nil case "dwt-listing": @@ -5210,6 +5276,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_656d6d65742d6c697465811c9dc5, nil case "emojination": return theme_656d6f6a696e6174696f6e811c9dc5, nil + case "emphires": + return theme_656d706869726573811c9dc5, nil case "empowerment": return theme_656d706f7765726d656e74811c9dc5, nil case "empowerwp": @@ -5382,6 +5450,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_666c6170811c9dc5, nil case "flashlight": return theme_666c6173686c69676874811c9dc5, nil + case "flashmart": + return theme_666c6173686d617274811c9dc5, nil case "flashnews": return theme_666c6173686e657773811c9dc5, nil case "flashy": @@ -5394,6 +5464,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_666c657572811c9dc5, nil case "flex-mag": return theme_666c65782d6d6167811c9dc5, nil + case "flipmart": + return theme_666c69706d617274811c9dc5, nil case "flixita": return theme_666c6978697461811c9dc5, nil case "flozen-theme": @@ -5440,6 +5512,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_667261707065811c9dc5, nil case "freeagent": return theme_667265656167656e74811c9dc5, nil + case "freeio": + return theme_66726565696f811c9dc5, nil case "freesia-empire": return theme_667265657369612d656d70697265811c9dc5, nil case "freightco": @@ -5462,6 +5536,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_667573696f6e2d64656c6973746564811c9dc5, nil case "fwdevp": return theme_667764657670811c9dc5, nil + case "g5plus-april": + return theme_6735706c75732d617072696c811c9dc5, nil case "gable": return theme_6761626c65811c9dc5, nil case "gaea": @@ -5548,16 +5624,24 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_676f7a612d7468656d65811c9dc5, nil case "grace-mag": return theme_67726163652d6d6167811c9dc5, nil + case "gracey": + return theme_677261636579811c9dc5, nil case "gracioza": return theme_67726163696f7a61811c9dc5, nil case "grandblog": return theme_6772616e64626c6f67811c9dc5, nil + case "grandcarrental": + return theme_6772616e6463617272656e74616c811c9dc5, nil case "grandconference": return theme_6772616e64636f6e666572656e6365811c9dc5, nil case "grandmagazine": return theme_6772616e646d6167617a696e65811c9dc5, nil case "grandnews": return theme_6772616e646e657773811c9dc5, nil + case "grandphotography": + return theme_6772616e6470686f746f677261706879811c9dc5, nil + case "grandportfolio": + return theme_6772616e64706f7274666f6c696f811c9dc5, nil case "grandprix": return theme_6772616e6470726978811c9dc5, nil case "grandrestaurant": @@ -5580,6 +5664,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_677265656e2d706c616e6574811c9dc5, nil case "greenify": return theme_677265656e696679811c9dc5, nil + case "greenly": + return theme_677265656e6c79811c9dc5, nil case "greenmart": return theme_677265656e6d617274811c9dc5, nil case "greenorganic": @@ -5712,6 +5798,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_686f6d652d7365727669636573811c9dc5, nil case "homelancer": return theme_686f6d656c616e636572811c9dc5, nil + case "homeo": + return theme_686f6d656f811c9dc5, nil case "homeroofer": return theme_686f6d65726f6f666572811c9dc5, nil case "homesweet": @@ -6016,6 +6104,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_6c6162811c9dc5, nil case "laboom": return theme_6c61626f6f6d811c9dc5, nil + case "labtechco": + return theme_6c616274656368636f811c9dc5, nil case "lafka": return theme_6c61666b61811c9dc5, nil case "larson": @@ -6314,6 +6404,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_6d6f64696e73811c9dc5, nil case "modular": return theme_6d6f64756c6172811c9dc5, nil + case "mogi": + return theme_6d6f6769811c9dc5, nil case "molla": return theme_6d6f6c6c61811c9dc5, nil case "moments": @@ -6410,6 +6502,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_6e372d676f6c662d636c7562811c9dc5, nil case "namaha": return theme_6e616d616861811c9dc5, nil + case "nanosoft": + return theme_6e616e6f736f6674811c9dc5, nil case "nativechurch": return theme_6e6174697665636875726368811c9dc5, nil case "naturemag-lite": @@ -6602,6 +6696,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_6f72636869642d73746f7265811c9dc5, nil case "organic-beauty": return theme_6f7267616e69632d626561757479811c9dc5, nil + case "organicfood": + return theme_6f7267616e6963666f6f64811c9dc5, nil case "orgarium": return theme_6f7267617269756d811c9dc5, nil case "oshin": @@ -6946,6 +7042,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_726564737465656c811c9dc5, nil case "redy": return theme_72656479811c9dc5, nil + case "reebox": + return theme_726565626f78811c9dc5, nil case "refraction": return theme_72656672616374696f6e811c9dc5, nil case "reganto-theme": @@ -7374,6 +7472,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_737461727475707a79811c9dc5, nil case "statfort": return theme_73746174666f7274811c9dc5, nil + case "stephanie-king": + return theme_7374657068616e69652d6b696e67811c9dc5, nil case "stevenwatkins": return theme_73746576656e7761746b696e73811c9dc5, nil case "stockholm": @@ -7462,6 +7562,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_7465617264726f70811c9dc5, nil case "techlink": return theme_746563686c696e6b811c9dc5, nil + case "techone": + return theme_746563686f6e65811c9dc5, nil case "tediss": return theme_746564697373811c9dc5, nil case "teluro": @@ -7660,6 +7762,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_756c7472617072657373811c9dc5, nil case "umberto": return theme_756d626572746f811c9dc5, nil + case "uminex": + return theme_756d696e6578811c9dc5, nil case "unakit": return theme_756e616b6974811c9dc5, nil case "uncode": @@ -7798,6 +7902,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_766f696365811c9dc5, nil case "vw-automobile-lite": return theme_76772d6175746f6d6f62696c652d6c697465811c9dc5, nil + case "vw-education-lite": + return theme_76772d656475636174696f6e2d6c697465811c9dc5, nil case "vw-fitness": return theme_76772d6669746e657373811c9dc5, nil case "vw-pet-shop": @@ -7980,6 +8086,8 @@ func themeAdvisories(slug string) ([]byte, error) { return theme_7961616275726e65652d7468656d6573811c9dc5, nil case "yacht-rental": return theme_79616368742d72656e74616c811c9dc5, nil + case "yobazar": + return theme_796f62617a6172811c9dc5, nil case "yogi": return theme_796f6769811c9dc5, nil case "yokoo": diff --git a/internal/data/assets_gen_test.go b/internal/data/assets_gen_test.go index 659bde4d..9744d4a8 100644 --- a/internal/data/assets_gen_test.go +++ b/internal/data/assets_gen_test.go @@ -596,6 +596,7 @@ func plugins() []string { "ai-content-writing-assistant", "ai-copilot", "ai-engine", + "ai-engine-pro", "ai-feeds", "ai-for-seo", "ai-image", @@ -717,6 +718,7 @@ func plugins() []string { "all-in-one-wp-migration-dropbox-extension", "all-in-one-wp-migration-gdrive-extension", "all-in-one-wp-migration-onedrive-extension", + "all-in-one-wp-migration-unlimited-extension", "all-in-one-wp-security-and-firewall", "all-push-notification", "all-social-share-options", @@ -1262,6 +1264,7 @@ func plugins() []string { "b-testimonial", "b-tiktok-feed", "b1-accounting", + "b2bking", "b2bking-wholesale-for-woocommerce", "b2i-investor-tools", "ba-book-everything", @@ -4057,6 +4060,7 @@ func plugins() []string { "elfsight-pricing-table", "elfsight-telegram-chat-cc", "elfsight-testimonials-slider", + "elfsight-whatsapp-chat", "elink-embed-content", "elisqlreports", "elite-notification", @@ -4064,6 +4068,7 @@ func plugins() []string { "elizaibot-chatbots", "ellipsis-human-presence-technology", "elo-rating-shortcode", + "eltd-listing", "eltdf-membership", "em-beer-manager", "emag-marketplace-connector", @@ -5207,6 +5212,7 @@ func plugins() []string { "getshop-ecommerce", "getsocial", "gettext-override-translations", + "getty-images", "getwid", "getwid-megamenu", "getyourguide-ticketing", @@ -5465,6 +5471,7 @@ func plugins() []string { "green-wp-telegram-bot-by-teplitsa", "greencon", "greenhouse-job-board", + "greenly-addons", "greenshift-animation-and-page-builder-blocks", "greenshiftquery", "greenshiftwoo", @@ -7084,6 +7091,7 @@ func plugins() []string { "mailclient", "mailcwp", "mailercloud-integrate-webforms-synchronize-contacts", + "mailerpress", "mailgun-subscriptions", "mailhawk", "mailin", @@ -7313,6 +7321,8 @@ func plugins() []string { "medibazar-core", "medical-addon-for-elementor", "medical-prescription-attachment-plugin-for-woocommerce", + "medilazar-core", + "medilink-core", "medinik-core", "medma-matix", "meenews", @@ -8763,6 +8773,7 @@ func plugins() []string { "podcasting", "podclankova-inzerce", "podiant", + "podigee", "podlove-podcasting-plugin-for-wordpress", "podlove-subscribe-button", "podlove-web-player", @@ -12039,6 +12050,7 @@ func plugins() []string { "tumult-hype-animations", "tune-library", "turbo-addons-elementor", + "turbo-manager", "turbo-widgets", "turbosmtp", "turisbook-booking-system", @@ -14853,6 +14865,7 @@ func plugins() []string { "wp2wb", "wp3d-model-import-block", "wp_attractivedonationssystem", + "wp_estimation_form", "wp_rokbox", "wp_rokintroscroller", "wp_rokmicronews", @@ -15546,6 +15559,7 @@ func themes() []string { "arilewp", "arkhe", "arlo", + "armania", "aromatica", "arrival", "art-theme", @@ -15627,13 +15641,16 @@ func themes() []string { "biagiotti", "bicycleshop", "big-store", + "bighearts", "billey", "bimber", "bingle", "bingopress", + "biolife", "birdily", "blabber", "black-letterhead", + "blackfyre", "blain", "blanka-wp", "blaze", @@ -15664,6 +15681,7 @@ func themes() []string { "blueprint", "bluestreet", "bodycenter", + "boldman", "boldy", "boliin", "bolster", @@ -15964,6 +15982,7 @@ func themes() []string { "dsk", "dt-chocolate", "dt-the7", + "dukamarket", "dwell", "dwt-listing", "dzonia-lite", @@ -16022,6 +16041,7 @@ func themes() []string { "emberlyn", "emmet-lite", "emojination", + "emphires", "empowerment", "empowerwp", "energia", @@ -16108,12 +16128,14 @@ func themes() []string { "fixteam", "flap", "flashlight", + "flashmart", "flashnews", "flashy", "flatnews", "flatsome", "fleur", "flex-mag", + "flipmart", "flixita", "flozen-theme", "fluer", @@ -16137,6 +16159,7 @@ func themes() []string { "frames", "frappe", "freeagent", + "freeio", "freesia-empire", "freightco", "freshio", @@ -16148,6 +16171,7 @@ func themes() []string { "fushion-theme", "fusion-delisted", "fwdevp", + "g5plus-april", "gable", "gaea", "gaga-lite", @@ -16191,11 +16215,15 @@ func themes() []string { "goya", "goza-theme", "grace-mag", + "gracey", "gracioza", "grandblog", + "grandcarrental", "grandconference", "grandmagazine", "grandnews", + "grandphotography", + "grandportfolio", "grandprix", "grandrestaurant", "grandspa", @@ -16207,6 +16235,7 @@ func themes() []string { "great-lotus", "green-planet", "greenify", + "greenly", "greenmart", "greenorganic", "greenthumb", @@ -16273,6 +16302,7 @@ func themes() []string { "holmes", "home-services", "homelancer", + "homeo", "homeroofer", "homesweet", "homevillas-real-estate", @@ -16425,6 +16455,7 @@ func themes() []string { "kuteshop", "lab", "laboom", + "labtechco", "lafka", "larson", "lasa", @@ -16574,6 +16605,7 @@ func themes() []string { "modernize", "modins", "modular", + "mogi", "molla", "moments", "monalisa", @@ -16622,6 +16654,7 @@ func themes() []string { "mystique", "n7-golf-club", "namaha", + "nanosoft", "nativechurch", "naturemag-lite", "navian", @@ -16718,6 +16751,7 @@ func themes() []string { "optimizewp", "orchid-store", "organic-beauty", + "organicfood", "orgarium", "oshin", "ostende", @@ -16890,6 +16924,7 @@ func themes() []string { "redline", "redsteel", "redy", + "reebox", "refraction", "reganto-theme", "regina-lite", @@ -17104,6 +17139,7 @@ func themes() []string { "startup-blog", "startupzy", "statfort", + "stephanie-king", "stevenwatkins", "stockholm", "store-commerce", @@ -17148,6 +17184,7 @@ func themes() []string { "tax-help", "teardrop", "techlink", + "techone", "tediss", "teluro", "temp-mail-x", @@ -17247,6 +17284,7 @@ func themes() []string { "ultra-seven", "ultrapress", "umberto", + "uminex", "unakit", "uncode", "uncode-lite", @@ -17316,6 +17354,7 @@ func themes() []string { "vocal", "voice", "vw-automobile-lite", + "vw-education-lite", "vw-fitness", "vw-pet-shop", "vw-photography", @@ -17407,6 +17446,7 @@ func themes() []string { "xts-hitek", "yaaburnee-themes", "yacht-rental", + "yobazar", "yogi", "yokoo", "yolox",