6.4

CVSS3.1

CVE-2024-1533 - Shortcodes and extra features for Phlox theme <= 2.15.7 - Authenticated (Contributor+) Stored Cross…

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML Element in all versions up to, and including, 2.15.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with …

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.

5.3

CVSS3.1

CVE-2024-2109 - Booster Extension <= 1.2.0 - Basic Information Exposure via booster_extension_authorbox_shortcode_d…

The Booster Extension plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.0 via the 'booster_extension_authorbox_shortcode_display' function. This makes it possible for unauthenticated attackers to extract sensitive data including user emai…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-2765 - Ultimate Member <= 2.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL parameters in all versions up to, and including, 2.8.4 due to insufficient input sanitiz…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.5

CVSS3.1

CVE-2024-3295 - User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.…

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the profile_pic_remove function in versions up to, and including, 3.1.5. This makes it possible for un…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2023-7067 - ShopLentor <= 2.8.1 - Improper Authorization via woolentor_template_store

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woolentor_template_store' function in all versions up to, and inclu…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 5:04 p.m.

6.4

CVSS3.1

CVE-2024-4092 - Slider Revolution <= 6.7.7 - Authenticated (Author+) Stored Cross-Site Scripting via htmltag Parame…

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scri…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

4.4

CVSS3.1

CVE-2024-2967 - Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor <= 4.4.7 - …

The Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 4.4.7 due to insufficient input sanitization and output escaping. This makes it possi…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-2346 - FileBird – WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Insecu…

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via folder deletion due to missing validation on a user controlled key. This makes it possible for authenticated attackers…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-3724 - Happy Addons for Elementor <= 3.10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied at…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.1

CVSS3.1

CVE-2024-4133 - ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0…

The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.0.30. This is due to insufficient validation on the redirect url supplied via the redirect_to parameter. This …

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 10079 of 34,919
« previous page » next page
Filters