6.4

CVSS3.1

CVE-2024-3337 - Colibri Page Builder <= 1.0.272 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'col…

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_breadcrumb_element' shortcode in all versions up to, and including, 1.0.272 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-3197 - The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in the plugin's widgets in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-3891 - Happy Addons for Elementor <= 3.10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

7.2

CVSS3.1

CVE-2024-3715 - Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site …

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-3199 - The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor a…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

5.3

CVSS3.1

CVE-2024-3215 - Paid Memberships Pro <= 3.0.1 - Cross-Site Request Forgery

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the pmpro_update_level_group_order() function…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-4265 - Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.5.…

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 2.0.5.9 due to insufficient input sanitization and output escaping. This makes it…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-3517 - Shortcodes and extra features for Phlox theme <= 2.15.5 - Authenticated (Contributor+) Stored Cross…

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion Widget in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

9.8

CVSS3.1

CVE-2024-3729 - Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Man…

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible for unauthenticated attackers to manipulate the user processing forms, which can …

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

5.3

CVSS3.1

CVE-2024-0615 - Content Control <= 2.1.0 - Missing Authorization to Sensitive Information Exposure

The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.0 via the API. This makes it possible for unauthenticated attackers to ext…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 10077 of 34,919
« previous page » next page
Filters