cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-13319,https://securityvulnerability.io/vulnerability/CVE-2024-13319,Reflected Cross-Site Scripting Vulnerability in Themify Builder Plugin for WordPress,"The Themify Builder plugin for WordPress is susceptible to a reflected cross-site scripting vulnerability. This flaw arises from using the add_query_arg function without adequate escaping, allowing unauthenticated attackers to craft URLs that can inject arbitrary web scripts. If a user is misled into clicking on a manipulated link, the script will execute in the context of their session, potentially leading to unauthorized actions or data exposure. This vulnerability is present in all versions up to and including 7.6.5.",Wordpress,Themify Builder,6.1,MEDIUM,0.0004600000102072954,false,,false,false,false,false,false,false,2025-01-22T07:29:40.540Z,0 CVE-2024-9385,https://securityvulnerability.io/vulnerability/CVE-2024-9385,Themify Builder Plugin Vulnerable to Reflected Cross-Site Scripting,"The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",Wordpress,Themify Builder,6.1,MEDIUM,0.00044999999227002263,false,,false,false,false,,false,false,2024-10-05T01:59:41.325Z,0 CVE-2024-7836,https://securityvulnerability.io/vulnerability/CVE-2024-7836,Unauthorized Post Duplication Vulnerability in Themify Builder Plugin,"The Themify Builder plugin for WordPress is susceptible to a security flaw that enables authenticated users, including those with Contributor-level permissions, to duplicate and access posts that should remain private or in draft form. This issue arises due to inadequate verification within the duplicate_page_ajaxify function in all versions up to and including 7.6.1. As a result, users may exploit this vulnerability to gain access to content created by other authors without proper authorization.",Wordpress,Themify Builder,4.3,MEDIUM,0.00044999999227002263,false,,false,false,false,,false,false,2024-08-22T02:02:03.277Z,0 CVE-2024-3032,https://securityvulnerability.io/vulnerability/CVE-2024-3032,Themify Builder Plugin Open Redirect Vulnerability,"Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue",Wordpress,Themify Builder,6.1,MEDIUM,0.0004600000102072954,false,,false,false,true,true,false,false,2024-06-13T06:00:02.512Z,0