6.4

CVSS3.1

CVE-2024-13732 - Responsive Blocks – WordPress Gutenberg Blocks <= 1.9.9 - Authenticated (Contributor+) Stored Cross…

The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘section_tag’ parameter in all versions up to, and including, 1.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac…

📅 Published: Jan. 30, 2025, 8:21 a.m. 🔄 Last Modified: April 8, 2026, 4:38 p.m.

6.4

CVSS3.1

CVE-2024-13470 - Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+)…

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

📅 Published: Jan. 30, 2025, 7:23 a.m. 🔄 Last Modified: April 8, 2026, 4:59 p.m.

6.4

CVSS3.1

CVE-2024-13642 - Stratum – Elementor Widgets <= 1.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting Vul…

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hotspot widget in all versions up to, and including, 1.4.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth…

📅 Published: Jan. 30, 2025, 6:41 a.m. 🔄 Last Modified: April 8, 2026, 5:02 p.m.

5.3

CVSS3.1

CVE-2024-13457 - Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposure

The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view order…

📅 Published: Jan. 30, 2025, 6:41 a.m. 🔄 Last Modified: April 8, 2026, 4:35 p.m.

4.3

CVSS3.1

CVE-2024-12709 - Bulk Me Now <= 2.0 - Message Deletion via CSRF

The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

📅 Published: Jan. 30, 2025, 6 a.m. 🔄 Last Modified: May 11, 2025, 11:49 p.m.

7.1

CVSS3.1

CVE-2024-12708 - Bulk Me Now <= 2.0 - Stored XSS via Shortcode

The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

📅 Published: Jan. 30, 2025, 6 a.m. 🔄 Last Modified: May 11, 2025, 11:43 p.m.

7.1

CVSS3.1

CVE-2024-12638 - Bulk Me Now <= 2.0 - Reflected XSS

The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

📅 Published: Jan. 30, 2025, 6 a.m. 🔄 Last Modified: May 11, 2025, 11:41 p.m.

7.1

CVSS3.1

CVE-2024-12400 - Tourmaster < 5.3.5 - Reflected XSS

The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

📅 Published: Jan. 30, 2025, 6 a.m. 🔄 Last Modified: June 9, 2025, 9:20 p.m.

6.5

CVSS3.1

CVE-2024-12163 - GoodLayers Core < 2.1.3 - Subscriber+ Stored XSS via SVG Upload

The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads.

📅 Published: Jan. 30, 2025, 6 a.m. 🔄 Last Modified: June 9, 2025, 9:19 p.m.

5.9

CVSS3.1

CVE-2024-10309 - Tracking Code Manager < 2.4.0 - Contributor+ Stored XSS

The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

📅 Published: Jan. 30, 2025, 6 a.m. 🔄 Last Modified: May 11, 2025, 11:38 p.m.
Total resulsts: 347249
Page 6720 of 34,725
« previous page » next page
Filters