CVE-2025-4963
- EPSS 0.06%
- Veröffentlicht 28.05.2025 09:22:13
- Zuletzt bearbeitet 28.05.2025 15:01:30
The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...
CVE-2024-13554
- EPSS 0.09%
- Veröffentlicht 12.02.2025 04:15:09
- Zuletzt bearbeitet 25.02.2025 03:52:20
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reorder_route() function in all versions up to, and including, 3.0.13. This makes it pos...
CVE-2024-11916
- EPSS 0.04%
- Veröffentlicht 08.01.2025 04:15:06
- Zuletzt bearbeitet 14.04.2025 12:27:30
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on several functions in all versions up to, and including, 3.0.11. This makes it ...
CVE-2024-47386
- EPSS 0.14%
- Veröffentlicht 05.10.2024 15:15:15
- Zuletzt bearbeitet 07.10.2024 17:47:48
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended allows Reflected XSS.This issue affects The Ultimate WordPress Toolkit – WP Extended...
CVE-2024-8123
- EPSS 0.13%
- Veröffentlicht 04.09.2024 07:15:05
- Zuletzt bearbeitet 06.09.2024 17:20:28
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.8 via the duplicate_post function due to missing validation on a user controlled key. Th...
CVE-2024-8106
- EPSS 0.39%
- Veröffentlicht 04.09.2024 07:15:04
- Zuletzt bearbeitet 05.09.2024 13:05:52
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 via the download_user_ajax function. This makes it possible for authenticated attackers,...
CVE-2024-8117
- EPSS 1.17%
- Veröffentlicht 04.09.2024 07:15:04
- Zuletzt bearbeitet 06.09.2024 16:04:23
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘selected_option’ parameter in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output es...
CVE-2024-8119
- EPSS 1.17%
- Veröffentlicht 04.09.2024 07:15:04
- Zuletzt bearbeitet 06.09.2024 16:11:02
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This ...
CVE-2024-8121
- EPSS 0.13%
- Veröffentlicht 04.09.2024 07:15:04
- Zuletzt bearbeitet 06.09.2024 16:20:59
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user names due to a missing capability check on the wpext_change_admin_name() function in all versions up to, and including, 3.0.8. Th...
CVE-2024-8102
- EPSS 0.23%
- Veröffentlicht 04.09.2024 07:15:03
- Zuletzt bearbeitet 05.09.2024 13:28:54
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the module_all_toggle_ajax() function in all versions ...