8.8
CVE-2024-2047 - ElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Local File Inclusion in renderβ¦
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the render_raw function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files onβ¦
6.4
CVE-2024-1692 - BoldGrid Easy SEO β Simple and Effective SEO <= 1.6.13 - Authenticated(Contributor+) Stored Cross-Sβ¦
The BoldGrid Easy SEO β Simple and Effective SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the meta description field in all versions up to, and including, 1.6.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibβ¦
6.5
CVE-2024-29278 -
funboot v1.1 is vulnerable to Cross Site Scripting (XSS) via the title field in "create a message ."
9.8
CVE-2024-28288 -
Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulnerability. An attacker can use this vulnerability to log in to the device and disrupt the business of the enterprise.
0.0
CVE-2024-3103 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
7.1
CVE-2024-30431 - WordPress Mang Board WP plugin <= 1.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Reflected XSS.This issue affects Mang Board WP: from n/a through 1.8.0.
6.5
CVE-2024-30432 - WordPress B Slider plugin <= 1.1.12 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Slider - Slider for your block editor allows Stored XSS.This issue affects B Slider - Slider for your block editor: from n/a through 1.1.12.
6.5
CVE-2024-30433 - WordPress MultiVendorX Marketplace plugin <= 4.1.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX WC Marketplace allows Stored XSS.This issue affects WC Marketplace: from n/a through 4.1.3.
5.9
CVE-2024-30434 - WordPress WP-CRM System plugin <= 3.2.9 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-CRM System allows Stored XSS.This issue affects WP-CRM System: from n/a through 3.2.9.
7.1
CVE-2024-30435 - WordPress Nexter Blocks plugin <= 3.2.5 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor.This issue affects Nexter Blocks: from n/a through <= 3.2.5.