|
2761
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versions up to, and including, 3.1.2. This is due to th…
|
CWE-862
Missing Authorization
|
CVE-2026-3138
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2762
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Product Filter for WooCommerce by WBW para WordPress es vulnerable a la pérdida de datos no autorizada debido a una comprobación de capacidad faltante en todas las versiones hasta la 3.1.2,…
|
CWE-862
Missing Authorization
|
CVE-2026-3138
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2763
|
9.1 |
CRITICAL
Network
|
-
|
-
|
The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accep…
|
CWE-862
Missing Authorization
|
CVE-2026-4283
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2764
|
7.2 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_time of the file libdeuteron_modules.so of the component NTP Service. The manipula…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4627
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2765
|
7.2 |
HIGH
Network
|
-
|
-
|
Se encontró una vulnerabilidad en D-Link DIR-825 y DIR-825R 1.0.5/4.5.1. Afecta a la función handler_update_system_time del archivo libdeuteron_modules.so del componente Servicio NTP. La manipulación…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4627
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2766
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of the file /sms/user/index.php?view=add of the component Parameter Handler. Execu…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4632
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2767
|
7.3 |
HIGH
Network
|
-
|
-
|
Una debilidad ha sido identificada en itsourcecode Online Enrollment System 1.0. Esta vulnerabilidad afecta código desconocido del archivo /sms/user/index.php?view=add del componente Gestor de Paráme…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4632
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2768
|
9.1 |
CRITICAL
Network
|
-
|
-
|
El plugin WP DSGVO Tools (GDPR) para WordPress es vulnerable a la destrucción no autorizada de cuentas en todas las versiones hasta la 3.1.38, inclusive. Esto se debe a que la acción AJAX 'super-unsu…
|
CWE-862
Missing Authorization
|
CVE-2026-4283
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2769
|
7.5 |
HIGH
Network
|
-
|
-
|
The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter …
|
CWE-89
SQL Injection
|
CVE-2026-4662
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2770
|
7.5 |
HIGH
Network
|
-
|
-
|
El plugin JetEngine para WordPress es vulnerable a inyección SQL a través de la acción AJAX 'listing_load_more' en todas las versiones hasta la 3.8.6.1, inclusive. Esto se debe a que el parámetro 'fi…
|
CWE-89
SQL Injection
|
CVE-2026-4662
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|