8.1

CVSS3.1

CVE-2024-13684 - Reset <= 1.6 - Cross-Site Request Forgery to Database Reset

The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the reset_db_page() function. This makes it possible for unauthenticated attackers to reset several tables in the database li…

📅 Published: Feb. 18, 2025, 4:21 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

6.4

CVSS3.1

CVE-2024-13578 - WP-BibTeX <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP-BibTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'WpBibTeX' shortcode in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker…

📅 Published: Feb. 18, 2025, 4:21 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

6.4

CVSS3.1

CVE-2025-0805 - Mortgage Calculator / Loan Calculator <= 1.5.20 - Authenticated (Contributor+) Stored Cross-Site Sc…

The Mortgage Calculator / Loan Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mlcalc' shortcode in all versions up to, and including, 1.5.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

📅 Published: Feb. 18, 2025, 4:21 a.m. 🔄 Last Modified: April 8, 2026, 4:38 p.m.

5.3

CVSS3.1

CVE-2024-13538 - BigBuy Dropshipping Connector for WooCommerce <= 2.0.0 - Unauthenticated Full Path Disclosute

The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.0. This is due the /vendor/cocur/slugify/bin/generate-default.php file being directly accessible and triggering an error. This makes it possible for…

📅 Published: Feb. 18, 2025, 4:21 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

6.4

CVSS3.1

CVE-2024-13581 - Simple Charts <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Simple Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simple_chart' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at…

📅 Published: Feb. 18, 2025, 4:21 a.m. 🔄 Last Modified: April 8, 2026, 4:35 p.m.

6.4

CVSS3.1

CVE-2024-13587 - Zigaform – Price Calculator & Cost Estimation Form Builder Lite <= 7.4.7 - Authenticated (Contribut…

The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_fvar' shortcode in all versions up to, and including, 7.4.7 due to insufficient input sanitization and output escaping on user supplied attrib…

📅 Published: Feb. 18, 2025, 4:21 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

6.1

CVSS3.1

CVE-2024-13522 - magayo Lottery Results <= 2.0.12 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.12. This is due to missing or incorrect nonce validation on the 'magayo-lottery-results' page. This makes it possible for unauthenticated attackers to update setting…

📅 Published: Feb. 18, 2025, 4:21 a.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.

6.1

CVSS3.1

CVE-2025-1390 - pam_cap: Fix potential configuration parsing error

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to sec…

📅 Published: Feb. 18, 2025, 2:34 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-13740 - ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Insecure Direct Object Reference t…

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key. This makes it possible for aut…

📅 Published: Feb. 18, 2025, 2:06 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

5.4

CVSS3.1

CVE-2024-13741 - ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Authenticated (Subscriber+) Limite…

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. This makes it possible for authenticated attackers, with Subscriber-level access and abov…

📅 Published: Feb. 18, 2025, 1:44 a.m. 🔄 Last Modified: April 8, 2026, 5:10 p.m.
Total resulsts: 348605
Page 6648 of 34,861
« previous page » next page
Filters