Vulnerabilities (CVE)

Filtered by CWE-863
Total 3392 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-1639 1 Wpexperts 1 License Manager For Woocommerce 2026-06-17 N/A 6.5 MEDIUM
The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLicenseKey() and showAllLicenseKeys() functions in all versions up to, and including, 3.0.6. This makes it possible for authenticated attackers, with admin dashboard access (contributors by default due to WooCommerce) to view arbitrary decrypted license keys. The functions contain a referrer nonce check. However, these can be retrieved via the dashboard through the "license" JS variable. Please note that the version in trunk is patched, however, the 3.0.7 tagged version is not.
CVE-2024-1479 1 Generatepress 1 Wp Show Posts 2026-06-17 N/A 5.3 MEDIUM
The WP Show Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the wpsp_display function. This makes it possible for authenticated attackers with contributor access and above to view the contents of draft, trash, future, private and pending posts and pages.
CVE-2024-1452 1 Generatepress 1 Generateblocks 2026-06-17 N/A 4.3 MEDIUM
The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.2 via Query Loop. This makes it possible for authenticated attackers, with contributor access and above, to see contents of posts and pages in draft or private status as well as those with scheduled publication dates.
CVE-2024-1307 1 Rednao 1 Smart Forms 2026-06-17 N/A 6.5 MEDIUM
The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a subscriber to call them and perform unauthorized actions
CVE-2024-1156 1 Emerson 8 Data Record Ad, Flexlogger, G Web Development Software and 5 more 2026-06-17 N/A 7.8 HIGH
Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.
CVE-2024-1155 1 Emerson 8 Data Record Ad, Flexlogger, G Web Development Software and 5 more 2026-06-17 N/A 7.8 HIGH
Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2024-13947 2026-06-17 N/A 6.0 MEDIUM
Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
CVE-2024-13302 1 Ciandt 1 Pages Restriction Access 2026-06-17 N/A 5.3 MEDIUM
Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2.0.0 before 2.0.3.
CVE-2024-13291 1 Basic Http Authentication Project 1 Basic Http Authentication 2026-06-17 N/A 7.3 HIGH
Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.
CVE-2024-13290 1 Ohdear 1 Ohdear Integration 2026-06-17 N/A 5.3 MEDIUM
Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear Integration: from 0.0.0 before 2.0.4.
CVE-2024-13282 1 Block Permissions Project 1 Block Permissions 2026-06-17 N/A 8.8 HIGH
Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.2.0.
CVE-2024-13281 1 Monster Menus Project 1 Monster Menus 2026-06-17 N/A 9.1 CRITICAL
Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2.
CVE-2024-13278 1 Diff Project 1 Diff 2026-06-17 N/A 9.1 CRITICAL
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.
CVE-2024-13277 1 Smart Ip Ban Project 1 Smart Ip Ban 2026-06-17 N/A 9.1 CRITICAL
Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1.
CVE-2024-13271 1 Content Entity Clone Project 1 Content Entity Clone 2026-06-17 N/A 4.3 MEDIUM
Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content Entity Clone: from 0.0.0 before 1.0.4.
CVE-2024-13270 1 Freelinking Project 1 Freelinking 2026-06-17 N/A 4.3 MEDIUM
Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: from 0.0.0 before 4.0.1.
CVE-2024-13266 1 Responsive And Off-canvas Menu Project 1 Responsive And Off-canvas Menu 2026-06-17 N/A 5.3 MEDIUM
Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affects Responsive and off-canvas menu: from 0.0.0 before 4.4.4.
CVE-2024-13258 1 Rest \& Json Api Authentication Project 1 Rest \& Json Api Authentication 2026-06-17 N/A 9.8 CRITICAL
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.
CVE-2024-13257 1 Commerce View Receipt Project 1 Commerce View Receipt 2026-06-17 N/A 5.3 MEDIUM
Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.
CVE-2024-13253 1 Advanced Pwa Inc Push Notifications Project 1 Advanced Pwa Inc Push Notifications 2026-06-17 N/A 9.1 CRITICAL
Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue affects Advanced PWA inc Push Notifications: from 0.0.0 before 1.5.0.