CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
In GalliumOS 3.0, CONFIG_SECURITY_YAMA is disabled but /etc/sysctl.d/10-ptrace.conf tries to set /proc/sys/kernel/yama/ptrace_scope to 1, which might increase risk because of the appearance that a protection mechanism is present when actually it is not.
The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.
The ad-inserter plugin before 2.4.20 for WordPress has path traversal.
The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion.
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.
