For users, it may feel like one more registration step. For app developers and businesses, however, phone verification solves several …
The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via ‘order[0][dir]’ …
The User Login History plugin for WordPress is vulnerable to SQL Injection via the ‘blog_id’ parameter in all versions up to, and …
A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. …
The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a …
The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with …
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request …
The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API …
The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing …
The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants …
The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user’s actual earned …
The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources …
●●●

NVD
EXPLOITS
SECURELIST