Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45233 risultati

VulnerabilitàAlta
CVE-2026-88847 - MasterStudy LMS < 3.7.50 - Subscriber+ Lesson Completion Record Creation

CVE ID :CVE-2026-88847 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create course progress records for courses they have no access to. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-88843 - MasterStudy LMS 3.5.29 - < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Widget

CVE ID :CVE-2026-88843 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute arbitrary local PHP files on the server. An equivalent path was corrected in an earlier release and this one was not, so the issue persists in versions the earlier advisory reports as fixed. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-88845 - MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo Import

CVE ID :CVE-2026-88845 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create published content on the site attributed to their own account. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-88846 - MasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Registration Disabled

CVE ID :CVE-2026-88846 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has been deliberately disabled. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-89002 - WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Campaign Item Preview

CVE ID :CVE-2026-89002 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Scripting attacks against higher-privileged users who review the campaign. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-89004 - WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclosure via IDOR

CVE ID :CVE-2026-89004 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including administrators. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-93661 - Events Manager < 7.4.5 - Contributor+ Arbitrary Ticket Overwrite via IDOR

CVE ID :CVE-2026-93661 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-89005 - WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Category

CVE ID :CVE-2026-89005 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the session of any higher-privileged user who later views the campaign. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-82195 - 10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion

CVE ID :CVE-2026-82195 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete it repeatedly, preventing an administrator from completing a legitimate connection. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-84151 - The Post Grid < 7.9.5 - Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-List Widening

CVE ID :CVE-2026-84151 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input elements that are normally stripped from their content, leading to HTML injection (phishing frames, CSS defacement and spoofed input forms) that renders to any visitor and to administrators reviewing the content. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-80338 - CMB2 < 2.13.0 - Subscriber+ Arbitrary Option Corruption via oEmbed Handler

CVE ID :CVE-2026-80338 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break core site settings and take the site offline. Exploitation requires the site's or another CMB2 WordPress plugin before 2.13.0 to have declared an oEmbed field, as the CMB2 WordPress plugin before 2.13.0 registers none of its own. The stored value is never attacker-controlled, so the issue does not lead to privilege escalation. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026
VulnerabilitàAlta
CVE-2026-80513 - wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields

CVE ID :CVE-2026-80513 Published : Sept. 24, 2026, 6:17 a.m. | 2 hours, 11 minutes ago Description :The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before 3.1.6 itself; if one is present via another installed wpForo Forum WordPress plugin before 3.1.6 or , this could lead to remote code execution, arbitrary file operations, or SQL injection. This is an incomplete fix of CVE-2026-49769. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE24 set 2026

Pagina 176 di 3770

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.