9.8

CVSS3.1

CVE-2024-12822 - Media Manager for UserPro <= 3.12.0 - Missing Authorization to Unauthenticated Arbitrary Options Up…

The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the add_capto_img() function in all versions up to, and including, 3.11.0. This makes it possible for unauthenticated atta…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: Feb. 28, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2024-13596 - WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress <= 1.7.5 - Authenticated (Cont…

The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'survey' shortcode in all versions up to, and including, 1.7.5 due to insufficient escaping on the user supplied parameter and lack of sufficien…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: Jan. 31, 2025, 6:16 p.m.

6.1

CVSS3.1

CVE-2024-12299 - System Dashboard <= 2.8.15 - Reflected Cross-Site Scripting via Filename Parameter

The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web …

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: Jan. 31, 2025, 6:22 p.m.

6.4

CVSS3.1

CVE-2024-12451 - HTML5 chat <= 1.04 - Authenticated (Contributor+) Stored Cross-Site Scripting

The HTML5 chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'HTML5CHAT' shortcode in all versions up to, and including, 1.04 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: Jan. 31, 2025, 6:55 p.m.

4.3

CVSS3.1

CVE-2024-13715 - zStore Manager Basic <= 3.311 - Missing Authorization to Authenticated (Subscriber+) Cache Clearing

The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the zstore_clear_cache() function in all versions up to, and including, 3.311. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: Jan. 30, 2025, 6:53 p.m.

4.3

CVSS3.1

CVE-2024-8494 - Elementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contribut…

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.25.10 via the 'elementor-template' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensit…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: Jan. 30, 2025, 5:12 p.m.

6.1

CVSS3.1

CVE-2024-12177 - Ai Image Alt Text Generator for WP <= 1.0.2 - Reflected Cross-Site Scripting

The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: Jan. 31, 2025, 7:49 p.m.

6.4

CVSS3.1

CVE-2024-13670 - Music Sheet Viewer <= 4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Music Sheet Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pn_msv' shortcode in all versions up to, and including, 4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: Jan. 31, 2025, 5:56 p.m.

6.5

CVSS3.1

CVE-2024-12861 - W2S – Migrate WooCommerce to Shopify <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+…

The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.2.1 via the 'viw2s_view_log' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of ar…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: Jan. 31, 2025, 7:01 p.m.

8.1

CVSS3.1

CVE-2024-13646 - Single-user-chat <= 0.5 - Authenticated (Subscriber+) Limited Options Update

The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the 'single_user_chat_update_login' function in all versions up to, and including, 0.5. This makes it possible for authenticated attack…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: Jan. 31, 2025, 6:19 p.m.
Total resulsts: 343040
Page 6294 of 34,304
« previous page » next page
Filters