The Woocommerce plugin has a vulnerability that makes it possible for authenticated users with contributor level and above to access products classified as private, draft or trashed....
The Elementor Website Builder plugin, much more than just a Page Builder for WordPress, is vulnerable to arbitrary file deletions and PHAR deserialization in versions up to and including 3.19.0....
The plugin is vulnerable to unauthorized access and data modification due to a type manipulation issue on the connect-app REST endpoint in all versions up to and including 2.8.7....