A vulnerability, which was classified as problematic, was found in Royal Elementor Addons Plugin up to 1.3.70 on WordPress. Affected by this vulnerability is an unknown functionality of the component MailChimp API Key Handler. Such manipulation leads to information disclosure.
This vulnerability is listed as CVE-2023-3709. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in Jupiter X Core Plugin up to 2.5.0 on WordPress. It has been classified as problematic. Affected by this issue is some unknown functionality. This manipulation causes information disclosure.
This vulnerability appears as CVE-2023-3813. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Video Conferencing with Zoom Plugin up to 4.2.1 on WordPress. It has been rated as problematic. The affected element is the function vczapi_encrypt_decrypt. This manipulation causes use of hard-coded cryptographic key
.
This vulnerability is tracked as CVE-2023-3947. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in ACF Photo Gallery Field Plugin up to 1.9 on WordPress. It has been declared as critical. The impacted element is an unknown function of the component Usermeta Update Handler. Executing a manipulation can lead to improper access controls.
This vulnerability appears as CVE-2023-3957. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in InstaWP Connect Plugin up to 0.0.9.18 on WordPress. It has been classified as critical. This issue affects the function events_receiver of the component Setting Handler. Performing a manipulation results in missing authorization.
This vulnerability is cataloged as CVE-2023-3956. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Bus Ticket Booking with Seat Reservation Plugin up to 5.2.3 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2023-4067. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in WP Ultimate CSV Importer Plugin up to 7.9.8 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in code injection.
This vulnerability is identified as CVE-2023-4142. The attack can be initiated remotely. There is not any exploit available.
A vulnerability categorized as problematic has been discovered in WP Ultimate CSV Importer Plugin up to 7.9.8 on WordPress. This affects an unknown part. Executing a manipulation can lead to information disclosure.
This vulnerability is tracked as CVE-2023-4139. The attack is only possible within the local network. No exploit exists.
A vulnerability identified as critical has been detected in WP Ultimate CSV Importer Plugin up to 7.9.8 on WordPress. This vulnerability affects unknown code of the component Usermeta Update Handler. The manipulation leads to improper access controls.
This vulnerability is listed as CVE-2023-4140. The attack may be initiated remotely. There is no available exploit.
A vulnerability marked as critical has been reported in WP Ultimate CSV Importer up to 7.9.8 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to code injection.
This vulnerability is listed as CVE-2023-4141. The attack may be initiated remotely. There is no available exploit.
Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta.
The public availability is currently limited to Windows users on Chrome 146, with macOS expansion planned in an upcoming Chrome release.
"This project represents a significant