cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-8484,https://securityvulnerability.io/vulnerability/CVE-2024-8484,SQL Injection Vulnerability in WordPress REST API,"A vulnerability exists in the REST API TO MiniProgram plugin for WordPress, affecting versions up to and including 4.7.1. This vulnerability is attributed to insufficient escaping of user-supplied input in the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint. As a consequence, unauthenticated attackers can inject additional SQL queries into the existing database queries, potentially leading to unauthorized access and extraction of sensitive data from the database.",Wordpress,Rest Api To Miniprogram,7.5,HIGH,0.004100000020116568,false,,false,false,true,true,false,false,2024-09-25T03:15:00.000Z,0 CVE-2024-8485,https://securityvulnerability.io/vulnerability/CVE-2024-8485,Privilege Escalation Vulnerability Affects WordPress Users,"The REST API TO MiniProgram plugin for WordPress exposes users to significant security risks due to a vulnerability that enables privilege escalation. This issue arises from inadequate validation of the 'openid' user-controlled key in the updateUserInfo() function, affecting all versions up to and including 4.7.1. As a consequence, unauthenticated attackers can manipulate the plugin to alter user accounts indiscriminately. This includes the potential to change email addresses to those ending in @weixin.com, which can subsequently facilitate password resets, compromising both regular and administrative accounts. The vulnerability raises awareness about the critical need for robust input validation and access controls in plugin development.",Wordpress,Rest Api To Miniprogram,9.8,CRITICAL,0.000910000002477318,false,,false,false,false,,false,false,2024-09-25T03:15:00.000Z,0 CVE-2023-0551,https://securityvulnerability.io/vulnerability/CVE-2023-0551,REST API TO MiniProgram <= 4.6.1 - Subscriber+ Attachment Deletion,"The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments",Wordpress,Rest Api To Miniprogram,5.4,MEDIUM,0.0006200000061653554,false,,false,false,false,,false,false,2023-08-16T12:15:00.000Z,0