6.4

CVSS3.1

CVE-2024-13458 - WordPress SEO Friendly Accordion FAQ with AI assisted content generation <= 2.2.1 - Authenticated (…

The WordPress SEO Friendly Accordion FAQ with AI assisted content generation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'noticefaq' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user suppli…

📅 Published: Jan. 25, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 5 p.m.

6.4

CVSS3.1

CVE-2024-13599 - LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scr…

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.7.5 due to insufficient input sanitization and output escaping of a lesson name. This makes it possible for authenticated attackers, with LP Instructor-l…

📅 Published: Jan. 25, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 4:58 p.m.

6.4

CVSS3.1

CVE-2024-13548 - Power Ups for Elementor <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Power Ups for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'magic-button' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth…

📅 Published: Jan. 25, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 4:47 p.m.

6.5

CVSS3.1

CVE-2024-12885 - Connections Business Directory <= 10.4.66 - Authenticated (Admin+) Arbitrary Directory Deletion

The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory in all versions up to, and including, 10.4.66. This makes it possible for authenticated attackers, with Administ…

📅 Published: Jan. 25, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 4:42 p.m.

6.4

CVSS3.1

CVE-2024-12529 - brodos.net Onlineshop Plugin <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The brodos.net Onlineshop Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'BrodosCategory' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f…

📅 Published: Jan. 25, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 4:37 p.m.

6.1

CVSS3.1

CVE-2024-12076 - Target Video Easy Publish <= 3.8.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Target Video Easy Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.3. This is due to missing or incorrect nonce validation on the resync_carousel(), seek_snapshot(), uploaded_cc(), and remove_cc() functions. This makes it possibl…

📅 Published: Jan. 25, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 4:37 p.m.

6.4

CVSS3.1

CVE-2024-12512 - Ask Me Anything (Anonymously) <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ask Me Anything (Anonymously) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'askmeanythingpeople' shortcode in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib…

📅 Published: Jan. 25, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 4:35 p.m.

6.4

CVSS3.1

CVE-2024-12816 - NOTICE BOARD BY TOWKIR <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The NOTICE BOARD BY TOWKIR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'notice-board' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Jan. 25, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.

7.2

CVSS3.1

CVE-2024-12600 - Custom Product Tabs Lite for WooCommerce <= 1.9.0 - Authenticated (Shop Manager+) PHP Object Inject…

The Custom Product Tabs Lite for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.0 via deserialization of untrusted input from the 'frs_woo_product_tabs' parameter. This makes it possible for authenticated attackers, with Shop Manager…

📅 Published: Jan. 25, 2025, 6:40 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-10552 - Flexmls® IDX Plugin <= 3.14.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via API p…

The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘api_key’ and 'api_secret' parameters in all versions up to, and including, 3.14.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with …

📅 Published: Jan. 25, 2025, 6:40 a.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.
Total resulsts: 346802
Page 6724 of 34,681
« previous page » next page
Filters