The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment credentials in all versions up to, and including, 1.1.1. This is due to missing capability checks and nonce verification on the `wpf_stripe_callback_success()` and `wpf_stripe_disconnect()` functions, both hooked to `admin_init`. The `admin_init` hook fires [truncated]
The Gutena Forms plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.9.0. This allows unauthenticated attackers to modify form submission entries, potentially leading to data tampering. The plugin's vulnerability is attributed to the nonce issued by check_ajax_referer() not functioning as an authorization barrier. Affected product deployments should be conf [truncated]
The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the status of arbitrary posts and pages to 'd [truncated]
The User Management plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.2. This allows unauthenticated attackers to modify the plugin's export field configuration, potentially leading to data exposure and integrity risks. Administrators of WordPress installations using the User Management plugin should assess and mitigate this vulnerability. The vulnerabili [truncated]
The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitra [truncated]