CVE-2024-13418
- EPSS 1.36%
- Veröffentlicht 02.05.2025 03:21:20
- Zuletzt bearbeitet 06.05.2025 15:25:54
Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() function in various versions. This makes it possible for authenticated attackers, with Subscriber-level a...
CVE-2024-13420
- EPSS 0.17%
- Veröffentlicht 02.05.2025 03:21:19
- Zuletzt bearbeitet 06.05.2025 15:26:47
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in variou...
CVE-2024-13419
- EPSS 0.12%
- Veröffentlicht 02.05.2025 03:21:17
- Zuletzt bearbeitet 06.05.2025 14:57:41
Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for...