4.3

CVSS3.1

CVE-2024-13374 - WP Table Manager <= 4.1.3 - Missing Authorization to Authenticated (Subscriber+) Directory Traversa…

The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitra…

📅 Published: Feb. 12, 2025, 5:28 a.m. 🔄 Last Modified: April 8, 2026, 4:36 p.m.

8.1

CVSS3.1

CVE-2024-13654 - ZoxPress - The All-In-One WordPress News Theme <= 2.12.0 - Missing Authorization to Authenticated (…

The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'reset_options' function in all versions up to, and including, 2.12.0. This makes it possible for a…

📅 Published: Feb. 12, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 5:33 p.m.

8.1

CVSS3.1

CVE-2024-13656 - Click Mag - Viral WordPress News Magazine/Blog Theme <= 3.6.0 - Missing Authorization to Authentica…

The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to, and including, 3.6.0. This makes …

📅 Published: Feb. 12, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 5:31 p.m.

6.4

CVSS3.1

CVE-2024-13658 - NGG Smart Image Search <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_nextgen_searchbox' shortcode in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib…

📅 Published: Feb. 12, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 5:27 p.m.

6.4

CVSS3.1

CVE-2024-13665 - Admire Extra <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Admire Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'space' shortcode in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…

📅 Published: Feb. 12, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 5:19 p.m.

8.8

CVSS3.1

CVE-2024-13653 - ZoxPress - The All-In-One WordPress News Theme <= 2.12.0 - Missing Authorization to Authenticated (…

The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' functions in all versions up to, and including, 2.12.0. Thi…

📅 Published: Feb. 12, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 7:20 p.m.

9.8

CVSS3.1

CVE-2024-13421 - Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to Administrator

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to registe…

📅 Published: Feb. 12, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 5:13 p.m.

4.3

CVSS3.1

CVE-2024-12164 - WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon <= 1.6 - Missing Authorization to …

The WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsslwp_reset_settings() function in all versions up to, and including, 1.6. This makes it possible for authenticated…

📅 Published: Feb. 12, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 5:04 p.m.

8.1

CVSS3.1

CVE-2024-13800 - Popup Plugin For WordPress - ConvertPlus <= 3.5.30 - Missing Authorization to Authenticated (Subscr…

The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_notice' AJAX endpoint in all versions up to, and including, 3.5.30. This makes it possible for authenticated attackers, w…

📅 Published: Feb. 12, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 4:54 p.m.

6.4

CVSS3.1

CVE-2024-11746 - Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin <= 1.…

The Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'product_brand' shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and outpu…

📅 Published: Feb. 12, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 4:49 p.m.
Total resulsts: 344911
Page 6343 of 34,492
« previous page » next page
Filters