6.4

CVSS3.1

CVE-2024-1386 -

The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions 1.5.0 to 1.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-3677 - Ultimate 410 Gone Status Code <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ultimate 410 Gone Status Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 410 entries in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level …

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-1809 - Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) <= 5.2.3 - Missing A…

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possi…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.

6.4

CVSS3.1

CVE-2024-1805 - WPBakery Visual Composer <= 7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Butt…

The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.

8.2

CVSS3.1

CVE-2024-1567 - Royal Elementor Addons and Templates <= 1.3.94 - Unauthenticated Limited File Upload

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types s…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.

4.3

CVSS3.1

CVE-2024-2959 - SVS Pricing Tables <= 1.0.4 - Cross-Site Request Forgery to Pricing Table Edit/Creation

The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the savePricingTable() function. This makes it possible for unauthenticated attackers to create and edit prici…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-3489 - Exclusive Addons for Elementor <= 2.6.9.4 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Countdown Expired Title in all versions up to, and including, 2.6.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-1993 - Icon Widget <= 1.3.0 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

The Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2024-1677 - Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce <= 3.4.…

The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to an improper capability check on 42 separate AJAX functions in all versions up to, and incl…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.

5.3

CVSS3.1

CVE-2024-2043 - EleForms – All In One Form Integration including DB for Elementor <= 2.9.9.7 - Missing Authorizatio…

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when downloading form submissions in all versions up to, and including, 2.9.9.7. This makes it possible for unauthenticated attac…

📅 Published: May 2, 2024, 4:52 p.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.
Total resulsts: 349182
Page 10080 of 34,919
« previous page » next page
Filters