6.1

CVSS3.1

CVE-2024-13711 - Pollin <= 1.01.1 - Reflected Cross-Site Scripting

The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts …

📅 Published: Feb. 19, 2025, 7:32 a.m. 🔄 Last Modified: April 8, 2026, 4:51 p.m.

6.4

CVSS3.1

CVE-2024-12522 - Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily <= 1.2.1 - Authenticated (Contributor+…

The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yayforms' shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes…

📅 Published: Feb. 19, 2025, 7:32 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

5.3

CVSS3.1

CVE-2024-13719 - PeproDev Ultimate Invoice <= 2.0.9 - Insecure Direct Object Reference to Unauthenticated Order Info…

The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view invoices for com…

📅 Published: Feb. 19, 2025, 7:32 a.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.

6.4

CVSS3.1

CVE-2024-13390 - ADFO – Custom data in admin dashboard <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scr…

The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adfo_list' shortcode in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib…

📅 Published: Feb. 19, 2025, 7:32 a.m. 🔄 Last Modified: April 8, 2026, 4:46 p.m.

4.9

CVSS3.1

CVE-2024-13712 - Pollin <= 1.01.1 - Authenticated (Admin+) SQL Injection

The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthentica…

📅 Published: Feb. 19, 2025, 7:32 a.m. 🔄 Last Modified: April 8, 2026, 4:44 p.m.

6.4

CVSS3.1

CVE-2024-13589 - YouTube Playlists with Schema <= 2.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt_grid' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut…

📅 Published: Feb. 19, 2025, 7:32 a.m. 🔄 Last Modified: April 8, 2026, 4:43 p.m.

6.5

CVSS3.1

CVE-2025-0865 - WP Media Category Management 2.0 - 2.3.3 - Cross-Site Request Forgery to Settings Update

The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3.3. This is due to missing or incorrect nonce validation on the wp_mcm_handle_action_settings() function. This makes it possible for unauthenticated attackers to alter plugin sett…

📅 Published: Feb. 19, 2025, 7:32 a.m. 🔄 Last Modified: Feb. 19, 2025, 9:18 p.m.

6.4

CVSS3.1

CVE-2024-13663 - Coaching Staffs <= 1.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' shortcode in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat…

📅 Published: Feb. 19, 2025, 7:32 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

5.1

CVSS4.0

CVE-2025-0633 - Heap Overflow in iniparser.c

Heap-based Buffer Overflow vulnerability in iniparser_dumpsection_ini() in iniparser allows attacker to read out of bound memory

📅 Published: Feb. 19, 2025, 7:01 a.m. 🔄 Last Modified: Feb. 19, 2025, 9:15 p.m.

3.5

CVSS3.1

CVE-2024-12173 - Master Slider < 3.10.5 - Editor+ Stored XSS

The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

📅 Published: Feb. 19, 2025, 6 a.m. 🔄 Last Modified: May 15, 2025, 8:48 p.m.
Total resulsts: 343948
Page 6166 of 34,395
« previous page » next page
Filters