Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This is...
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic
Unauthenticated SQL Injection in InPost Gallery
Unauthenticated Broken Access Control in JupiterX Core
Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged ...
Unauthenticated Broken Access Control in WP Event SOlution
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action ...
The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' param...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.