The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allo...
The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not prope...
The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displ...
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue aff...
Unauthenticated Arbitrary File Download in WP Media folder Addon
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for R...
Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.
Unauthenticated Privilege Escalation in Registration Form for WooCommerce
Unauthenticated PHP Object Injection in WP Activity Log
Subscriber Privilege Escalation in Falang multilanguage
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.