6.4
CVE-2024-4036 - Sydney Toolbox <= 1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in all versions up to, and including, 1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, โฆ
6.4
CVE-2024-3588 - Getwid โ Gutenberg Blocks <= 2.0.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripโฆ
The Getwid โ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticatโฆ
4.4
CVE-2024-2401 - Admin Page Spider <= 3.31 - Authenticated (Admin+) Stored Cross-Site Scripting
The Admin Page Spider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions โฆ
6.4
CVE-2024-1679 - Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce <= 3.4.โฆ
The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template and javascript label fields in all versions up to, and including, 3.4.6 due to insufficient input sanitization and outpuโฆ
6.4
CVE-2024-4000 - WordPress Header Builder Plugin โ Pearl <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Sโฆ
The WordPress Header Builder Plugin โ Pearl plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_hb' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possiblโฆ
6.1
CVE-2024-0613 - Delete Custom Fields <= 0.3.1 - Cross-Site Request Forgery to Post Meta Deletion
The Delete Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3.1. This is due to missing or incorrect nonce validation on the ajax_delete_field() function. This makes it possible for unauthenticated attackers to delete arbitrary pโฆ
4.3
CVE-2024-3606 - ProfileGrid โ User Profiles, Memberships, Groups and Communities <= 5.8.3 - Missing Authorization
The ProfileGrid โ User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This makes it possible for authenticated attaโฆ
6.4
CVE-2024-3550 - WP Shortcodes Plugin โ Shortcodes Ultimate <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Sitโฆ
The WP Shortcodes Plugin โ Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible fโฆ
5.3
CVE-2024-0629 - 2Checkout Payment Gateway for WooCommerce <= 6.2 - Missing Authorization via sniff_ins
The 2Checkout Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sniff_ins function in all versions up to, and including, 6.2. This makes it possible for unauthenticated attackers to make changes to ordersโฆ
4.4
CVE-2024-4085 - Tabellen von faustball.com <= 2.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
The Tabellen von faustball.com plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level peโฆ