4.8

CVSS3.1

CVE-2024-8426 - Pagelayer < 1.8.8 - Admin+ Stored XSS

The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: May 27, 2025, 7:52 p.m.

4.3

CVSS3.1

CVE-2024-8398 - Simple Nav Archives <= 2.1.3 - Settings Update via CSRF

The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 12, 2025, 3:43 p.m.

5.4

CVSS3.1

CVE-2024-8397 - GDPR Cookie Consent <= 2.6.0 - Unauthenticated Stored XSS

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious scrip…

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 12, 2025, 3:36 p.m.

6.5

CVSS3.1

CVE-2024-8286 - GDPR Cookie Consent <= 2.6.0 - Bulk Delete via CSRF

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 12, 2025, 3:34 p.m.

4.8

CVSS3.1

CVE-2024-8284 - Download Manager <= 3.2.98 - Admin+ Stored XSS

The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 12, 2025, 3:29 p.m.

4.3

CVSS3.1

CVE-2024-8245 - GamiPress - Reset User <= 1.0.0 - GamiPress User Data Removal via CSRF

The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: June 12, 2025, 3:25 p.m.

4.8

CVSS3.1

CVE-2024-8187 - Smart Post Show <= 3.0.0 - Editor+ Stored XSS

The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: May 27, 2025, 7:53 p.m.

6.1

CVSS3.1

CVE-2024-8095 - BabelZ – Google Translate Widget <= 1.1.5 - CSRF to Stored XSS

The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: May 27, 2025, 7:57 p.m.

6.5

CVSS3.1

CVE-2024-8094 - Ntz Antispam <= 2.0e - Settings Update via CSRF

The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: May 27, 2025, 7:58 p.m.

6.1

CVSS3.1

CVE-2024-8090 - JavaScript Logic <= 0.1 - CSRF to Stored XSS

The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

πŸ“… Published: May 15, 2025, 8:07 p.m. πŸ”„ Last Modified: May 27, 2025, 7:59 p.m.
Total resulsts: 349182
Page 5388 of 34,919
Β« previous page Β» next page
Filters