The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allo...
The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displ...
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue aff...
Subscriber Privilege Escalation in JetFormBuilder
Unauthenticated Broken Access Control in WooCommerce Anti-Fraud
Unauthenticated Broken Authentication in WooCommerce Dropshipping
Subscriber Broken Access Control in WPBakery Page Builder
CP Client Arbitrary File Download in Client Portal (Pro)
Subscriber Broken Access Control in Bricks Builder
Author Broken Access Control in W3 Total Cache
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.