8.8

CVSS3.1

CVE-2024-9195 - WHMPress - WHMCS Client Area <= 4.3-revision-3- Authenticated (Subscriber+) Arbitrary Options Update

The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the update_settings case in the /admin/ajax.php file in all versions up to, and including, 4.3-revision-3. This makes iโ€ฆ

๐Ÿ“… Published: Feb. 28, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:21 p.m.

6.4

CVSS3.1

CVE-2025-1662 - URL Media Uploader <= 1.0.0 - Authenticated (Author+) Server-Side Request Forgery via DNS Rebinding

The URL Media Uploader plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.0 via the 'url_media_uploader_url_upload' action. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrโ€ฆ

๐Ÿ“… Published: Feb. 28, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 2:15 a.m.

8.1

CVSS3.1

CVE-2025-1570 - Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Eโ€ฆ

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_generate_password_reset_pin_code() and reset_user_password() fโ€ฆ

๐Ÿ“… Published: Feb. 28, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 10:15 p.m.

5.9

CVSS3.1

CVE-2024-13638 - Order Attachments for WooCommerce <= 2.5.1 - Unauthenticated Sensitive Information Exposure Throughโ€ฆ

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uplโ€ฆ

๐Ÿ“… Published: Feb. 28, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:03 p.m.

7.2

CVSS3.1

CVE-2024-13831 - Tabs for WooCommerce <= 1.0.0 - Authentiated (Shop Manager+) PHP Object Injection in product_has_cuโ€ฆ

The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input in the 'product_has_custom_tabs' function. This makes it possible for authenticated attackers, with Shop Manager-level access and abโ€ฆ

๐Ÿ“… Published: Feb. 28, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:02 p.m.

9.8

CVSS3.1

CVE-2024-8425 - WooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File Upload

The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.9.2. This makes it possible for unautโ€ฆ

๐Ÿ“… Published: Feb. 28, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:22 p.m.

9.8

CVSS3.1

CVE-2024-9193 - WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update

The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.3-revision-0 via the whmpress_domain_search_ajax_extended_results() function. This makes it possible for unauthenticated attackers to include and execโ€ฆ

๐Ÿ“… Published: Feb. 28, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:56 p.m.

6.4

CVSS3.1

CVE-2024-9019 - SecuPress Free โ€” WordPress Security <= 2.2.5.3 - Authenticated (Contributor+) Stored Cross-Site Scrโ€ฆ

The SecuPress Free โ€” WordPress Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's secupress_check_ban_ips_form shortcode in all versions up to, and including, 2.2.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. Thiโ€ฆ

๐Ÿ“… Published: Feb. 28, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:22 p.m.

6.4

CVSS3.1

CVE-2024-13469 - Pricing Table by PickPlugins <= 1.12.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link in all versions up to, and including, 1.12.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-levelโ€ฆ

๐Ÿ“… Published: Feb. 28, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:52 p.m.

4.3

CVSS3.1

CVE-2024-13716 - Forex Calculators <= 1.3.7 - Missing Authorization to Authenticated (Subscriber+) Settings Update

The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_settings_callback() function in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with Subscriber-level access and โ€ฆ

๐Ÿ“… Published: Feb. 28, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:20 p.m.
Total resulsts: 349182
Page 6515 of 34,919
ยซ previous page ยป next page
Filters