The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled, then interpolates that str...
Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce
Unauthenticated Broken Access Control in Japanized For WooCommerce
Unauthenticated Broken Access Control in Business Directory
Subscriber Broken Access Control in Ads by WPQuads
Unauthenticated Broken Access Control in WP User Frontend
Subscriber Cross Site Scripting (XSS) in MasterStudy LMS
Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro
Subscriber Cross Site Scripting (XSS) in Business Directory
Subscriber Broken Access Control in MainWP
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.