Total
9924 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-3213 | 1 Wpforms | 1 Wp Mail Smtp | 2026-06-17 | N/A | 5.3 MEDIUM |
| The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_print_page function in versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to disclose potentially sensitive email information. | |||||
| CVE-2023-3204 | 1 Extendthemes | 1 Materialis | 2026-06-17 | N/A | 6.5 MEDIUM |
| The Materialis theme for WordPress is vulnerable to limited arbitrary options updates in versions up to, and including, 1.1.24. This is due to missing authorization checks on the companion_disable_popup() function called via an AJAX action. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to modify any option on the site to a numerical value. | |||||
| CVE-2023-3126 | 1 Webwizards | 1 B2bking | 2026-06-17 | N/A | 4.3 MEDIUM |
| The B2BKing plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'b2bkingdownloadpricelist' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with subscriber or customer-level permissions to retrieve the full pricing list of all products on the site. | |||||
| CVE-2023-3125 | 1 Webwizards | 1 B2bking | 2026-06-17 | N/A | 6.5 MEDIUM |
| The B2BKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'b2bking_save_price_import' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with subscriber or customer-level permissions to modify the pricing of any product on the site. | |||||
| CVE-2023-3124 | 1 Elementor | 1 Elementor Pro | 2026-06-17 | N/A | 8.8 HIGH |
| The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation. | |||||
| CVE-2023-3076 | 1 Inspireui | 1 Mstore Api | 2026-06-17 | N/A | 9.8 CRITICAL |
| The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features. | |||||
| CVE-2023-3072 | 1 Hashicorp | 1 Nomad | 2026-06-17 | N/A | 4.1 MEDIUM |
| HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11. | |||||
| CVE-2023-3053 | 1 Azexo | 1 Page Builder With Image Map By Azexo | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Page Builder by AZEXO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'azh_add_post' function in versions up to, and including, 1.27.133. This makes it possible for authenticated attackers to create a post with any post type and post status. | |||||
| CVE-2023-39998 | 1 Muffingroup | 1 Betheme | 2026-06-17 | N/A | 8.2 HIGH |
| Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 27.1.1. | |||||
| CVE-2023-39997 | 1 Supsystic | 1 Popup | 2026-06-17 | N/A | 5.3 MEDIUM |
| Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through 1.10.19. | |||||
| CVE-2023-39996 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Accordion and Accordion Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion and Accordion Slider: from n/a through 1.2.4. | |||||
| CVE-2023-39995 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Portfolio and Projects allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio and Projects: from n/a through 1.3.7. | |||||
| CVE-2023-39994 | 1 Reputeinfosystems | 1 Armember | 2026-06-17 | N/A | 4.3 MEDIUM |
| Missing Authorization vulnerability in Repute InfoSystems ARMember Premium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ARMember Premium: from n/a through 5.9.2. | |||||
| CVE-2023-39993 | 1 Wpmet | 1 Elements Kit Elementor Addons | 2026-06-17 | N/A | 4.3 MEDIUM |
| Missing Authorization vulnerability in Wpmet Elements kit Elementor addons.This issue affects Elements kit Elementor addons: from n/a through 2.9.0. | |||||
| CVE-2023-39990 | 1 Strangerstudios | 1 Paid Memberships Pro | 2026-06-17 | N/A | 5.4 MEDIUM |
| Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3. | |||||
| CVE-2023-39966 | 1 Fit2cloud | 1 1panel | 2026-06-17 | N/A | 7.5 HIGH |
| 1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file write vulnerability could lead to direct control of the server. In the `api/v1/file.go` file, there is a function called `SaveContentthat,It `recieves JSON data sent by users in the form of a POST request. And the lack of parameter filtering allows for arbitrary file write operations. Version 1.5.0 contains a patch for this issue. | |||||
| CVE-2023-39922 | 1 Theme-fusion | 1 Avada | 2026-06-17 | N/A | 4.3 MEDIUM |
| Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1. | |||||
| CVE-2023-39920 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Missing Authorization vulnerability in Themeisle Redirection for Contact Form 7 wpcf7-redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Redirection for Contact Form 7: from n/a through <= 2.9.2. | |||||
| CVE-2023-39544 | 1 Nec | 2 Expresscluster X, Expresscluster X Singleserversafe | 2026-06-17 | N/A | 8.8 HIGH |
| CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command. | |||||
| CVE-2023-39507 | 1 Recruit | 1 Rikunabi Next | 2026-06-17 | N/A | 6.1 MEDIUM |
| Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a malicious intent to lead the vulnerable App to access an arbitrary website. | |||||
