|
2911
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in activity-log.com WP System Log winterlock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP System Log: from n/a thr…
|
CWE-862
Missing Authorization
|
CVE-2026-24987
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2912
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en activity-log.com WP System Log winterlock permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema af…
|
CWE-862
Missing Authorization
|
CVE-2026-24987
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2913
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24989
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2914
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en FantasticPlugins SUMO Affiliates Pro affs permite la inyección de objetos. Este problema afecta a SUMO Affiliates Pro: desde n/a hasta <…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24989
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2915
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statis…
|
CWE-89
SQL Injection
|
CVE-2026-24993
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2916
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Neutralización incorrecta de elementos especiales utilizados en un comando SQL ('inyección SQL') vulnerabilidad en WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-rep…
|
CWE-89
SQL Injection
|
CVE-2026-24993
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2917
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: from n/a through <= 4.…
|
CWE-94
Code Injection
|
CVE-2026-25001
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2918
|
8.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de control inadecuado de la generación de código ('Inyección de Código') en Saad Iqbal Post Snippets post-snippets permite la Inclusión Remota de Código. Este problema afecta a Post Sn…
|
CWE-94
Code Injection
|
CVE-2026-25001
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2919
|
7.5 |
HIGH
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpress-sepay-payment allows Authentication Abuse.This issue affects LearnPress…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-25002
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2920
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de omisión de autenticación usando una ruta o canal alternativo en ThimPress LearnPress – Sepay Payment learnpress-sepay-payment permite el abuso de autenticación. Este problema afecta…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-25002
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|