|
3921
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de Asignación Incorrecta de Privilegios en Bit Apps Bit SMTP bit-smtp permite la escalada de privilegios. Este problema afecta a Bit SMTP: desde n/a hasta <= 1.2.2.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-32519
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3922
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects RewardsWP: from n/a through <= 1.0.4.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-32520
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3923
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de Asignación Incorrecta de Privilegios en Andrew Munro / AffiliateWP RewardsWP rewardswp permite la escalada de privilegios. Este problema afecta a RewardsWP: desde n/d hasta <= 1.…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-32520
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3924
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows DOM-Based XS…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32521
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3925
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface p…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32521
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3926
|
8.6 |
HIGH
Network
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerce-support-ticket-system allows Path Traversal.This…
|
CWE-22
Path Traversal
|
CVE-2026-32522
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3927
|
8.6 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Limitación Incorrecta de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') en vanquish WooCommerce Support Ticket System woocommerce-support-ticket-system permite Salt…
|
CWE-22
Path Traversal
|
CVE-2026-32522
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3928
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJAM Basic: from n/a through <= 6.9.2.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-32523
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3929
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de carga sin restricciones de archivo con tipo peligroso en denishua WPJAM Basic wpjam-basic permite el uso de archivos maliciosos. Este problema afecta a WPJAM Basic: desde n/a hasta …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-32523
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3930
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This issue affects Photo Engine: from n/a through <= 6.4.9.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-32524
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|