A vulnerability classified as very critical has been found in scriptsbundle CarSpot Plugin up to 2.4.3 on WordPress. This affects an unknown part. The manipulation leads to unverified password change.
This vulnerability is uniquely identified as CVE-2024-12860. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in wpdesk Flexible Wishlist for WooCommerce Plugin up to 1.2.26 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-13718. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in kerryoco Threepress Plugin up to 1.7.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-13395. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Cordaware bestinformed Web up to 6.2.2.4. It has been classified as problematic. Affected is an unknown function. The manipulation leads to code injection.
This vulnerability is traded as CVE-2025-0422. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in akashmalik Scratch and Win Plugin up to 2.8.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-13316. The attack can be initiated remotely. There is no exploit available.
A vulnerability classified as very critical has been found in scriptsbundle CarSpot Plugin up to 2.4.3 on WordPress. This affects an unknown part. The manipulation leads to unverified password change.
This vulnerability is uniquely identified as CVE-2024-12860. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in wpdesk Flexible Wishlist for WooCommerce Plugin up to 1.2.26 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-13718. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in kerryoco Threepress Plugin up to 1.7.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-13395. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Cordaware bestinformed Web up to 6.2.2.4. It has been classified as problematic. Affected is an unknown function. The manipulation leads to code injection.
This vulnerability is traded as CVE-2025-0422. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.