6.4

CVSS3.1

CVE-2024-4036 - Sydney Toolbox <= 1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in all versions up to, and including, 1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, โ€ฆ

๐Ÿ“… Published: May 2, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-3588 - Getwid โ€“ Gutenberg Blocks <= 2.0.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripโ€ฆ

The Getwid โ€“ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticatโ€ฆ

๐Ÿ“… Published: May 2, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:21 p.m.

4.4

CVSS3.1

CVE-2024-2401 - Admin Page Spider <= 3.31 - Authenticated (Admin+) Stored Cross-Site Scripting

The Admin Page Spider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions โ€ฆ

๐Ÿ“… Published: May 2, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-1679 - Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce <= 3.4.โ€ฆ

The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template and javascript label fields in all versions up to, and including, 3.4.6 due to insufficient input sanitization and outpuโ€ฆ

๐Ÿ“… Published: May 2, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:20 p.m.

6.4

CVSS3.1

CVE-2024-4000 - WordPress Header Builder Plugin โ€“ Pearl <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Sโ€ฆ

The WordPress Header Builder Plugin โ€“ Pearl plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_hb' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possiblโ€ฆ

๐Ÿ“… Published: May 2, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-0613 - Delete Custom Fields <= 0.3.1 - Cross-Site Request Forgery to Post Meta Deletion

The Delete Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3.1. This is due to missing or incorrect nonce validation on the ajax_delete_field() function. This makes it possible for unauthenticated attackers to delete arbitrary pโ€ฆ

๐Ÿ“… Published: May 2, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-3606 - ProfileGrid โ€“ User Profiles, Memberships, Groups and Communities <= 5.8.3 - Missing Authorization

The ProfileGrid โ€“ User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This makes it possible for authenticated attaโ€ฆ

๐Ÿ“… Published: May 2, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-3550 - WP Shortcodes Plugin โ€” Shortcodes Ultimate <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Sitโ€ฆ

The WP Shortcodes Plugin โ€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible fโ€ฆ

๐Ÿ“… Published: May 2, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:21 p.m.

5.3

CVSS3.1

CVE-2024-0629 - 2Checkout Payment Gateway for WooCommerce <= 6.2 - Missing Authorization via sniff_ins

The 2Checkout Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sniff_ins function in all versions up to, and including, 6.2. This makes it possible for unauthenticated attackers to make changes to ordersโ€ฆ

๐Ÿ“… Published: May 2, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2024-4085 - Tabellen von faustball.com <= 2.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Tabellen von faustball.com plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level peโ€ฆ

๐Ÿ“… Published: May 2, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 10076 of 34,919
ยซ previous page ยป next page
Filters