4.3

CVSS3.1

CVE-2024-13783 - FormCraft <= 3.9.11 - Missing Authorization to Plugin Data Export in formcraft-main.php

The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, and including, 3.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all plugin data…

📅 Published: Feb. 18, 2025, 11:10 a.m. 🔄 Last Modified: April 8, 2026, 5:33 p.m.

6.5

CVSS3.1

CVE-2024-13691 - Uncode <= 2.9.1.6 - Authenticated (Subscriber+) Arbitrary File Read in uncode_recordMedia

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary …

📅 Published: Feb. 18, 2025, 11:10 a.m. 🔄 Last Modified: April 8, 2026, 5:26 p.m.

5.4

CVSS3.1

CVE-2024-13667 - Uncode <= 2.9.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via mle-description

The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access …

📅 Published: Feb. 18, 2025, 11:10 a.m. 🔄 Last Modified: April 8, 2026, 5:03 p.m.

7.2

CVSS3.1

CVE-2025-0817 - FormCraft - Premium WordPress Form Builder <= 3.9.11 - Unauthenticated Stored Cross-Site Scripting …

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.9.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…

📅 Published: Feb. 18, 2025, 11:10 a.m. 🔄 Last Modified: April 22, 2026, 3 p.m.

7.5

CVSS3.1

CVE-2024-13681 - Uncode <= 2.9.1.6 - Unauthenticated Arbitrary File Read in uncode_admin_get_oembed

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and including, 2.9.1.6. This makes it possible for unauthenticated attackers to read arbitrary files on the server.

📅 Published: Feb. 18, 2025, 11:10 a.m. 🔄 Last Modified: April 8, 2026, 5:02 p.m.

0.0

CVE-2024-13636 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-24926. Reason: This candidate is a reservation duplicate of CVE-2024-24926. Notes: All CVE users should reference CVE-2024-24926 instead of this candidate. All references and descriptions in this candidate have been removed to prev…

📅 Published: Feb. 18, 2025, 11:10 a.m. 🔄 Last Modified: Feb. 24, 2025, 10:15 p.m.

7.2

CVSS3.1

CVE-2025-0521 - Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting

The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr…

📅 Published: Feb. 18, 2025, 11:10 a.m. 🔄 Last Modified: April 22, 2026, 1:30 p.m.

7.3

CVSS3.1

CVE-2024-13797 - PressMart - Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shor…

The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.16. This is due to the software allowing users to execute an action that does not properly validate a value before running do_sho…

📅 Published: Feb. 18, 2025, 11:10 a.m. 🔄 Last Modified: April 8, 2026, 4:42 p.m.

9.3

CVSS4.0

CVE-2025-1023 - SQL Injection in ChurchCRM newCountName Parameter via EditEventTypes.php

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. The newCountName parameter is directly concatenated into an SQL query without proper saniti…

📅 Published: Feb. 18, 2025, 9:45 a.m. 🔄 Last Modified: Feb. 21, 2025, 3:21 p.m.

8.4

CVSS4.0

CVE-2025-0981 - Session Hijacking via Stored Cross-Site Scripting (XSS) in ChurchCRM GroupEditor.php Description Fi…

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This allows admin users to inject malicious JavaScript in the description field, which captures the sessi…

📅 Published: Feb. 18, 2025, 9:33 a.m. 🔄 Last Modified: Feb. 21, 2025, 3:23 p.m.
Total resulsts: 349182
Page 6700 of 34,919
« previous page » next page
Filters