4.8

CVSS3.1

CVE-2024-8617 - Quiz Maker <= 6.5.9.8 - Admin+ Stored XSS

The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 4, 2025, 8:08 p.m.

4.8

CVSS3.1

CVE-2024-8542 - Everest Forms < 3.0.3.1 - Admin+ Stored XSS

The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 4, 2025, 8:08 p.m.

4.8

CVSS3.1

CVE-2024-8493 - The Events Calendar < 6.6.4 - Admin+ Stored XSS

The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 4, 2025, 8:08 p.m.

4.8

CVSS3.1

CVE-2024-8492 - Hustle < 7.8.5 - Admin+ Stored XSS

The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 12, 2025, 3:46 p.m.

4.8

CVSS3.1

CVE-2024-8426 - Pagelayer < 1.8.8 - Admin+ Stored XSS

The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: May 27, 2025, 7:52 p.m.

4.3

CVSS3.1

CVE-2024-8398 - Simple Nav Archives <= 2.1.3 - Settings Update via CSRF

The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 12, 2025, 3:43 p.m.

5.4

CVSS3.1

CVE-2024-8397 - GDPR Cookie Consent <= 2.6.0 - Unauthenticated Stored XSS

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious scrip…

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 12, 2025, 3:36 p.m.

6.5

CVSS3.1

CVE-2024-8286 - GDPR Cookie Consent <= 2.6.0 - Bulk Delete via CSRF

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 12, 2025, 3:34 p.m.

4.8

CVSS3.1

CVE-2024-8284 - Download Manager <= 3.2.98 - Admin+ Stored XSS

The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 12, 2025, 3:29 p.m.

4.3

CVSS3.1

CVE-2024-8245 - GamiPress - Reset User <= 1.0.0 - GamiPress User Data Removal via CSRF

The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 12, 2025, 3:25 p.m.
Total resulsts: 346556
Page 5125 of 34,656
Β« previous page Β» next page
Filters