CVEs-lər
28 vulnerabilities discovered.
28 zəiflik tapılıb.
PublishedAçıqlanmış Zəifliklər
The plugin does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected, or otherwise access-restricted galleries.
Plugin AJAX action-larından birində giriş nəzarəti (access control) yoxlanışı aparmır. Bu zəiflik autentifikasiyadan keçməmiş istifadəçilərə şifrə ilə qorunan və məhdudlaşdırılmış qalereyalara aid şəkil şərhlərini oxumağa imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account.
Plugin ikinci addım (2FA) doğrulama cəhdlərinin sayını düzgün məhdudlaşdırmır — cəhdlər hər girişdə yenidən verilən, müştəri tərəfindən göndərilən identifikatora əsasən izlənilir. Bu, artıq istifadəçinin şifrəsini bilən hücumçuya birdəfəlik kodu limitsiz təxmin edərək hesabı ələ keçirməyə imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor to change the amount of a payment intent that the plugin then updates server-side through the Stripe API using the store's secret key. An ownership check added in 8.5.0 was applied to only one handler, leaving the pricing-recalculation and payment-intent-update actions unprotected.
Plugin, autentifikasiya olunmamış iki ödəniş forması AJAX action-unda istinad edilən Stripe payment intent-inin çağırana aid olduğunu yoxlamır. Bu, autentifikasiyasız ziyarətçiyə ödəniş məbləğini dəyişməyə imkan verir — plugin bunu mağazanın gizli Stripe açarı ilə server tərəfində tətbiq edir. 8.5.0 versiyasında əlavə olunan sahiblik yoxlaması yalnız bir handler-ə tətbiq edilib, qiymət-yenidənhesablama və payment-intent-update əməliyyatları qorunmaz qalıb.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.
Plugin öz REST API route-larından birində icazə (authorization) yoxlaması aparmır. Bu, autentifikasiyasız istifadəçilərə fayl fəaliyyət jurnalını oxumağa imkan verir — saytda aparılan fayl əməliyyatları, əlaqəli fayl yolları və əməliyyatı icra edən istifadəçinin adı bununla açıqlanır.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does not cover them, allowing unauthenticated attackers to read arbitrary columns of the database table the affected front-end form is bound to, including user password hashes where that table is the users table.
Plugin, autentifikasiyasız AJAX action-larından birində qəbul etdiyi sütun adlarını doğrulamır, üstəlik həmin əməliyyatı qoruyan nonce bu sütunları əhatə etmir. Bu, autentifikasiyasız hücumçulara aidiyyəti front-end formasının bağlı olduğu verilənlər bazası cədvəlinin istənilən sütununu — cədvəl users cədvəli olduqda istifadəçi şifrə hash-ləri daxil olmaqla — oxumağa imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.
Plugin giriş məhdudiyyətlərini REST API sorğularına tətbiq etmir. Bu, autentifikasiyasız hücumçulara müəyyən istifadəçi qruplarına məhdudlaşdırılmış yazı, səhifə və xüsusi post tiplərinin məzmununu oxumağa imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, order IDs and statuses, fee amounts and order dates.
Plugin öz hesabat funksiyalarından birində icazə (authorization) və ya nonce yoxlaması aparmır. Bu, autentifikasiyasız hücumçulara mağazanın istənilən müştərisinə aid həssas sifariş məlumatlarını — hesab-faktura adları, sifariş ID-ləri və statusları, komissiya məbləğləri və sifariş tarixləri kimi — əldə etməyə imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level access and above to permanently delete the posts created by another user's import job, reset its deduplication and scheduling state, disable it, or clear its error log. One of the affected actions performs no object-type check either, so arbitrary posts and pages can also be unpublished regardless of who owns them.
Plugin, sorğuda göstərilən idxal (import) tapşırığının həqiqətən sorğunu göndərən istifadəçiyə aid olduğunu və ya onun tərəfindən redaktə edilə biləcəyini yoxlamır. Bu, "author" səviyyəsi və yuxarı hüquqlara malik istifadəçilərə başqa istifadəçinin idxal tapşırığı tərəfindən yaradılmış yazıları həmişəlik silməyə, onun təkrarlanma-nəzarəti və planlaşdırma vəziyyətini sıfırlamağa, deaktiv etməyə və ya xəta jurnalını təmizləməyə imkan verir. Təsirlənən əməliyyatlardan birində obyekt tipi yoxlaması ümumiyyətlə aparılmır, ona görə də sahibindən asılı olmayaraq istənilən yazı və ya səhifə də dərcdən çıxarıla bilər.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators.
Plugin öz AJAX action-larından birində icazə yoxlaması aparmır. Bu, subscriber qədər aşağı rola malik istifadəçilərə inzibatçılara aid olanlar daxil olmaqla istənilən istifadəçi, yazı və termin metadata-sını oxumağa imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders. Exploitation requires WooCommerce to be active and the plugin's optional order confirmation page module to be enabled.
Plugin öz xüsusi sifariş təsdiq səhifəsini göstərərkən və ya əlaqəli AJAX action-larını icra edərkən sifariş açarını (order key) doğrulamır. Bu, autentifikasiyasız istifadəçilərə şəxsi məlumatlar daxil olmaqla başqa müştərilərin sifariş detallarını görməyə, həmçinin istənilən sifarişin vəziyyətini dəyişməyə imkan verir. İstismar üçün WooCommerce aktiv olmalı və plugin-in könüllü sifariş təsdiq səhifəsi modulu aktivləşdirilməlidir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.
Plugin, əlaqə formaları vasitəsilə yüklənən faylları ictimaiyyətə açıq qovluğa köçürərkən təsadüfi fayl adından istifadə etmir. Bu, autentifikasiyasız hücumçulara digər istifadəçilər tərəfindən göndərilmiş faylları siyahıya alıb yükləməyə imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.
Plugin hesab blokunu bütün autentifikasiya yollarında tətbiq etmir. Bu, blokdan əvvəl yaradılmış application password-ə sahib olan bloklanmış istifadəçiyə REST API vasitəsilə öz rolunun tam oxuma və yazma hüquqlarını saxlamağa imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other users or by the administrator. Exploitation requires the plugin's front-end user upload feature to be enabled, which is not the default.
Plugin, front-end yükləməni emal edərkən cari istifadəçinin hədəflədiyi albuma yükləməyə icazəsi olub-olmadığını yoxlamır. Bu, Subscriber kimi istənilən autentifikasiya olunmuş istifadəçiyə başqa istifadəçilərə və ya administratora aid albomlara fayl yükləməyə imkan verir. İstismar üçün plugin-in front-end istifadəçi yükləmə funksiyası aktiv olmalıdır, bu isə default deyil.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and readable by the attacker.
Plugin öz autentifikasiya endpoint-lərindən birini CSRF-dən qorumur. Bu, hücumçuya qurbanı hücumçunun idarə etdiyi hesaba daxil etməyə imkan verir, nəticədə qurbanın checkout zamanı daxil etdiyi hesab-faktura və çatdırılma məlumatları hücumçunun hesabında saxlanılır və onun tərəfindən oxuna bilir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules.
Plugin, qəbul edilən fayl tipləri sahəsi boş qoyulduqda yüklənən faylların tipini doğrulamır — sənədləşmə bunu "bütün faylları qəbul edir" kimi təqdim edir. Bu, autentifikasiyasız hücumçulara istənilən faylı yükləməyə imkan verir və qovluğun giriş qaydalarını tətbiq etməyən serverlərdə uzaqdan kod icrasına (RCE) səbəb ola bilər.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.
Plugin geri çəkilmə (withdrawal) sorğusunu sorğu göndərən istifadəçinin faktiki qazanılmış balansına qarşı doğrulamır. Bu, heç bir satışı olmayan subscriber daxil olmaqla istənilən autentifikasiya olunmuş istifadəçiyə istənilən məbləğ üçün ödəniş sorğusu göndərməyə imkan verir, administrator isə bunu təsdiqləyib ödəyə bilər.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross-Site Scripting attacks against any visitor of the affected page, including administrators. This affects default single-site installations; sites running multisite, or defining DISALLOW_UNFILTERED_HTML, are not affected as the capability is not granted there.
Plugin bir quiz sahəsini səhifəyə geri çıxarmazdan əvvəl sanitizasiya və escape etmir, üstəlik instructor roluna filtrsiz HTML saxlamaq imkanı verir. Bu, həmin istifadəçilərə administratorlar daxil olmaqla, təsirlənən səhifəni ziyarət edən istənilən şəxsə qarşı Stored XSS hücumu həyata keçirməyə imkan verir. Default single-site quraşdırmalarına aiddir; multisite işlədən və ya DISALLOW_UNFILTERED_HTML təyin edən saytlar təsirlənmir, çünki orada bu imtiyaz verilmir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the plugin's Google sign-in enabled is affected.
Plugin qəbul etdiyi Google identity token-lərinin auditoriyasını (audience) doğrulamır. Bu, autentifikasiyasız istifadəçilərə həmin token-in daşıdığı email ünvanına sahib istənilən istifadəçi kimi — administrator daxil olmaqla — autentifikasiya olmağa imkan verir. Plugin-in Google ilə giriş funksiyası aktiv olan hər sayt təsirlənir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the plugin's own interface denies them, and to retrieve every chart's configuration in a single request. The disclosed configuration can include the credentials of a remote data source a chart reads from.
Plugin öz qrafiklərinin konfiqurasiyasına girişi düzgün icazələndirmir. Bu, Contributor rolu və yuxarı hüquqlara malik istifadəçilərə saytdakı istənilən qrafikin — plugin-in öz interfeysinin belə göstərmədiyi qrafiklər daxil olmaqla — tam konfiqurasiyasını oxumağa, üstəlik tək bir sorğu ilə bütün qrafiklərin konfiqurasiyasını əldə etməyə imkan verir. Açıqlanan konfiqurasiya qrafikin oxuduğu uzaq data mənbəyinin kimlik məlumatlarını da ehtiva edə bilər.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The plugin writes a deny-all rule into its upload directories, so the disclosure only crosses a boundary on web servers that honour it, such as Apache — where it is ignored, as on a default nginx setup, the same files are already served at their direct URL and the endpoint exposes nothing further.
Plugin faylı təqdim etməzdən əvvəl sorğu göndərənin müştəri tərəfindən yüklənmiş fayla hüququ olub-olmadığını yoxlamır. Bu, faylın saxlanılan adını əldə edən autentifikasiyasız istifadəçilərə onu əldə etməyə imkan verir. Plugin yükləmə qovluqlarına "deny-all" qaydası yazır, ona görə açıqlama yalnız bu qaydaya əməl edən (Apache kimi) serverlərdə həqiqi sərhəd keçir — default nginx quraşdırmasında olduğu kimi qayda nəzərə alınmadıqda, həmin fayllar artıq öz birbaşa URL-lərində təqdim olunur və endpoint əlavə heç nə açıqlamır.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including password hashes when debug logging is enabled.
Plugin yazdığı debug log-a girişi məhdudlaşdırmır — bu log sabit və ictimai əlçatan bir ünvanda saxlanılır. Bu, debug logging aktiv olduqda autentifikasiyasız istifadəçilərə plugin-in verdiyi OAuth token-ləri və avtorizasiya kodlarını, həmçinin şifrə hash-ləri daxil olmaqla istifadəçi qeydlərini oxumağa imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not verify that a user owns the store they are acting on in one of its REST API routes, allowing any authenticated user, such as a subscriber, to overwrite any store's details and payout settings and to replace the record of who owns it.
Plugin öz REST API route-larından birində istifadəçinin əməliyyat apardığı mağazaya sahib olduğunu doğrulamır. Bu, subscriber daxil olmaqla istənilən autentifikasiya olunmuş istifadəçiyə istənilən mağazanın detallarını, ödəniş ayarlarını üzərinə yazmağa və mağazanın sahibliyi qeydini əvəz etməyə imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed portal session to cancel subscriptions belonging to other customers. Exploitation requires the attacker to know the target subscription's identifier, which is high-entropy and not enumerable through the plugin.
Plugin abunəliyi ləğv etməzdən əvvəl onun sorğu göndərən müştəri-portal sessiyasına bağlı müştəriyə aid olduğunu doğrulamır. Bu, təsdiqlənmiş portal sessiyasına sahib istifadəçiyə başqa müştərilərə aid abunəlikləri ləğv etməyə imkan verir. İstismar üçün hücumçu hədəf abunəliyin identifikatorunu bilməlidir — bu, yüksək entropiyalıdır və plugin vasitəsilə sadalana bilməz.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not validate that a client-supplied price identifier belongs to the item being purchased when it is added to the cart, allowing unauthenticated users to buy items at a lower price defined elsewhere on the site and complete an order at that price, resulting in financial loss for the site owner.
Plugin, məhsul səbətə əlavə edilərkən client tərəfindən göndərilən qiymət identifikatorunun alınan məhsula aid olduğunu doğrulamır. Bu, autentifikasiyasız istifadəçilərə saytda başqa yerdə təyin edilmiş daha aşağı qiymətlə məhsul almağa və sifarişi həmin qiymətlə tamamlamağa imkan verir, nəticədə sayt sahibi üçün maliyyə itkisi yaranır.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration.
Plugin qeydiyyat zamanı seçilən rolun həqiqətən qeydiyyat formasında təklif olunan rollardan biri olduğunu doğrulamır. Bu, autentifikasiyasız istifadəçilərə özlərini məhdud B2B müştəri qruplarına təyin etməyə və self-registration zamanı əl ilə hesab-təsdiq axınını keçməyə imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not validate a user-supplied HTML tag name in one of its Beaver Builder widgets before echoing it into the rendered markup, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when any visitor views the affected page.
Plugin öz Beaver Builder widget-lərindən birində istifadəçi tərəfindən göndərilən HTML tag adını render olunan markup-a çıxarmazdan əvvəl doğrulamır. Bu, contributor səviyyəsi və yuxarı hüquqlara malik istifadəçilərə təsirlənən səhifəni görən istənilən ziyarətçinin brauzerində icra olunan ixtiyari web skriptləri əlavə etməyə imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.
Plugin, rezervasiyanın təsdiq detallarını qaytaran endpoint-də heç bir icazə yoxlaması aparmır, üstəlik hər rezervasiya ardıcıl rəqəmsal identifikatorla ünvanlanır. Bu, autentifikasiyasız hücumçulara həmin identifikatoru sadalamaqla (enumerate) istənilən müştərinin adını, emailini, telefon nömrəsini, rezervasiya detallarını və ödəniş statusunu oxumağa imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →The plugin does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category.
Plugin, rezervasiya xidməti və kateqoriya qeydlərini qaytaran endpoint-lərdə heç bir icazə yoxlaması aparmır. Bu, autentifikasiyasız hücumçulara hər xidmət və kateqoriyada saxlanılan şəxsi daxili qeydləri oxumağa imkan verir.
View Report on WPScan →WPScan üzərindən hesabatı oxu →