|
223051
|
5.4 |
MEDIUM
Network
|
onesignal
|
onesignal-free-web-push-notifications
|
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15827
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223052
|
9.8 |
CRITICAL
Network
|
wpserveur
|
wps_hide_login
|
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.
|
NVD-CWE-noinfo
|
CVE-2019-15826
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223053
|
9.8 |
CRITICAL
Network
|
wpserveur
|
wps_hide_login
|
The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.
|
NVD-CWE-noinfo
|
CVE-2019-15825
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223054
|
9.8 |
CRITICAL
Network
|
wpserveur
|
wps_hide_login
|
The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.
|
NVD-CWE-noinfo
|
CVE-2019-15824
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223055
|
9.8 |
CRITICAL
Network
|
wpserveur
|
wps_hide_login
|
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.
|
NVD-CWE-noinfo
|
CVE-2019-15823
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223056
|
9.8 |
CRITICAL
Network
|
wpserveur
|
wps_child_theme_generator
|
The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.
|
CWE-22
Path Traversal
|
CVE-2019-15822
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223057
|
7.5 |
HIGH
Network
|
bold-themes
|
bold_page_builder
|
The bold-page-builder plugin before 2.3.2 for WordPress has no protection against modifying settings and importing data.
|
NVD-CWE-noinfo
|
CVE-2019-15821
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223058
|
6.1 |
MEDIUM
Network
|
login_or_logout_menu_item_project
|
login_or_logout_menu_item
|
The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authentication.
|
CWE-601
Open Redirect
|
CVE-2019-15820
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223059
|
9.8 |
CRITICAL
Network
|
restaurant_reservations_project
|
restaurant_reservations
|
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15819
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223060
|
6.1 |
MEDIUM
Network
|
webcraftic
|
simple_301_redirects
|
The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.
|
CWE-601
Open Redirect
|
CVE-2019-15818
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|