Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High2
Medium0
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-06-20

CVE-2024-13617 - Aoa Downloadable Plugin

The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server

PLUGIN Aoa Downloadable

CVE-2024-13617

HIGH CVSS 8.6 2025-03-25
Threat Entry Updated 2025-06-20

CVE-2024-13618 - Aoa Downloadable Plugin

The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

PLUGIN Aoa Downloadable

CVE-2024-13618

HIGH CVSS 7.2 2025-03-25
Scroll to top