7.2
CVE-2024-4097 - Cost Calculator Builder Pro <= 3.1.67 - Unauthenticated Cross-Site Scripting via SVG Upload
The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 3.1.67 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary β¦
5.3
CVE-2024-0710 - GP Unique ID <= 1.5.5 - Unauthenticated Form Submission Unique ID Modification
The GP Unique ID plugin for WordPress is vulnerable to Unique ID Modification in all versions up to, and including, 1.5.5. This is due to insufficient input validation. This makes it possible for unauthenticated attackers to tamper with the generation of a unique ID on a form submission and replaceβ¦
4.4
CVE-2024-2324 - FileOrganizer and FileOrganizer Pro <= 1.0.6 - Authenticated Stored Cross-Site Scripting
The FileOrganizer β Manage WordPress and Website Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg file upload in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to β¦
8.8
CVE-2024-3849 - Click to Chat β HoliThemes <= 3.35 - Authenticated (Contributor+) Local File Inclusion
The Click to Chat β HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.35. This makes it possible for authenticated attackers, with contributor access or above, to include and execute arbitrary files on the server, allowing the execution ofβ¦
5.3
CVE-2024-3601 - Poll Maker β Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Email β¦
The Poll Maker β Best WordPress Poll Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_poll_create_author function in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to extract email aβ¦
5.5
CVE-2024-2752 - Where Did You Hear About Us Checkout Field for WooCommerce <= 1.3.1 - Authenticated (Shop Manager+)β¦
The Where Did You Hear About Us Checkout Field for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via order meta in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,β¦
6.5
CVE-2024-3553 - Tutor LMS <= 2.6.2 - Missing Authorization to Unauthenticated Limited Options Update
The Tutor LMS β eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the hide_notices function in all versions up to, and including, 2.6.2. This makes it possible for unauthenticated attackers to enable useβ¦
9.8
CVE-2024-2667 - InstaWP Connect β 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
The InstaWP Connect β 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This makes it possible for unauthenticatβ¦
5.4
CVE-2024-3340 - Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'colβ¦
The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gallery-slideshow' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possiβ¦
4.3
CVE-2024-3936 - The Post Grid β Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.6.1 - Missing Auβ¦
The The Post Grid β Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtTPGSaveSettings function in all versions up to, and including, 7.6.1. This makes it possible for autheβ¦