5.3

CVSS3.1

CVE-2024-3585 - Send PDF for Contact Form 7 <= 1.0.2.3 - Missing Authorization

The Send PDF for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of form submissions due to a missing capability check on the hooks function in all versions up to, and including, 1.0.2.3. This makes it possible for unauthenticated attackers to download information about con…

πŸ“… Published: May 2, 2024, 4:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-3581 - MaxGalleria <= 6.4.2 - Missing Authorization

The MaxGalleria plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability check on the add_media_library_images_to_gallery function in all versions up to, and including, 6.4.2. This makes it possible for authenticated attackers, with subscriber access or above, to …

πŸ“… Published: May 2, 2024, 4:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2024-3023 - AnnounceKit <= 2.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting

The AnnounceKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a…

πŸ“… Published: May 2, 2024, 4:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2023-6962 - WP Meta SEO <= 4.5.12 - Information Exposure via Meta Description

The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta description. This makes it possible for unauthenticated attackers to disclose potentially sensitive information via the meta description of password-protect…

πŸ“… Published: May 2, 2024, 4:51 p.m. πŸ”„ Last Modified: April 8, 2026, 5:17 p.m.

7.1

CVSS3.1

CVE-2024-1945 - ARForms Form Builder <= 1.6.4 - Missing Authorization to Authenticated(Subscriber+) Arbitrary Optio…

The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'arflite_remove_preview_data' function in all versions up to, and including, 1.6.4. This makes it possible for …

πŸ“… Published: May 2, 2024, 4:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-33948 - WordPress TweetScroll Widget plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixel Industry TweetScroll Widget allows Stored XSS.This issue affects TweetScroll Widget: from n/a through 1.3.7.

πŸ“… Published: May 2, 2024, 4:47 p.m. πŸ”„ Last Modified: April 28, 2026, 4:09 p.m.

6.5

CVSS3.1

CVE-2024-33949 - WordPress Min and Max Purchase for WooCommerce plugin <= 2.0.0 - Cross Site Scripting (XSS) vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vark Min and Max Purchase for WooCommerce allows Stored XSS.This issue affects Min and Max Purchase for WooCommerce: from n/a through 2.0.0.

πŸ“… Published: May 2, 2024, 4:46 p.m. πŸ”„ Last Modified: April 28, 2026, 4:09 p.m.

5.9

CVSS3.1

CVE-2024-4433 - WordPress Simple Image Popup plugin <= 2.4.0 - Cross-Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr Digital Simple Image Popup allows Stored XSS.This issue affects Simple Image Popup: from n/a through 2.4.0.

πŸ“… Published: May 2, 2024, 3:37 p.m. πŸ”„ Last Modified: April 28, 2026, 4:10 p.m.

9.6

CVSS3.1

CVE-2024-4406 - Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability

Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the ta…

πŸ“… Published: May 2, 2024, 3:02 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 12:15 a.m.

9.6

CVSS3.1

CVE-2024-4405 - Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability

Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target …

πŸ“… Published: May 2, 2024, 3:02 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 12:16 a.m.
Total resulsts: 349182
Page 10087 of 34,919
Β« previous page Β» next page
Filters