Author: Angelo Barbosa

CVE-2024-11452 | Chamber Dashboard Business Directory Plugin up to 3.3.8 on WordPress cross site scripting

A vulnerability has been found in Chamber Dashboard Business Directory Plugin up to 3.3.8 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Chamber Dashboard. The manipulation leads to cross site scripting. This vulnerability is known as CVE-2024-11452. The attack can be launched remotely. There is no exploit...

Read More

CVE-2024-10789 | WP User Profile Avatar up to 1.0.5 on WordPress Setting cross-site request forgery

A vulnerability, which was classified as problematic, was found in WP User Profile Avatar up to 1.0.5 on WordPress. Affected is an unknown function of the component Setting Handler. The manipulation leads to cross-site request forgery. This vulnerability is traded as CVE-2024-10789. It is possible to launch the attack remotely. There is no exploit...

Read More

CVE-2025-0502 | Crafter CMS up to 4.0.7/4.1.5 transmission of private resources into a new sphere (‘resource leak’)

A vulnerability, which was classified as problematic, has been found in Crafter CMS up to 4.0.7/4.1.5. This issue affects some unknown processing. The manipulation leads to transmission of private resources into a new sphere (‘resource leak’). The identification of this vulnerability is CVE-2025-0502. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More