6.4

CVSS3.1

CVE-2024-11894 - The Permalinker <= 1.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The The Permalinker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'permalink' shortcode in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a…

πŸ“… Published: Dec. 14, 2024, 4:23 a.m. πŸ”„ Last Modified: July 13, 2025, 9:07 p.m.

6.4

CVSS3.1

CVE-2024-11855 - Koalendar – Events & Appointments Booking Calendar <= 1.0.2 - Authenticated (Contributor+) Stored C…

The Koalendar – Events & Appointments Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜height’ parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack…

πŸ“… Published: Dec. 14, 2024, 4:23 a.m. πŸ”„ Last Modified: July 13, 2025, 11:14 a.m.

4.3

CVSS3.1

CVE-2024-12447 - Get Post Content Shortcode <= 0.4 - Insecure Direct Object Reference to Authenticated (Contributor+…

The Get Post Content Shortcode plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.4 via the 'post-content' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-l…

πŸ“… Published: Dec. 14, 2024, 4:23 a.m. πŸ”„ Last Modified: July 12, 2025, 10:44 p.m.

6.4

CVSS3.1

CVE-2024-12523 - States Map US <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The States Map US plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'states_map' shortcode in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at…

πŸ“… Published: Dec. 14, 2024, 4:23 a.m. πŸ”„ Last Modified: July 13, 2025, 9:07 p.m.

6.4

CVSS3.1

CVE-2024-12458 - Smart PopUp Blaster <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button' shortcode in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

πŸ“… Published: Dec. 14, 2024, 4:23 a.m. πŸ”„ Last Modified: July 12, 2025, 10:01 p.m.

6.1

CVSS3.1

CVE-2024-12411 - WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More <= 2.5.4 - Reflected Cross…

The WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for …

πŸ“… Published: Dec. 14, 2024, 4:23 a.m. πŸ”„ Last Modified: Dec. 16, 2024, 5:49 p.m.

6.4

CVSS3.1

CVE-2024-12448 - Posts and Products Views for WooCommerce <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Sc…

The Posts and Products Views for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'papvfwc_views' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p…

πŸ“… Published: Dec. 14, 2024, 4:23 a.m. πŸ”„ Last Modified: Dec. 16, 2024, 5:50 p.m.

6.4

CVSS3.1

CVE-2024-11883 - Connatix Video Embed <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Connatix Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cnx_script_code' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth…

πŸ“… Published: Dec. 14, 2024, 4:23 a.m. πŸ”„ Last Modified: July 12, 2025, 10:31 p.m.

6.4

CVSS3.1

CVE-2024-12517 - WooCommerce Cart Count Shortcode <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WooCommerce Cart Count Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cart_button' shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible …

πŸ“… Published: Dec. 14, 2024, 4:23 a.m. πŸ”„ Last Modified: Dec. 16, 2024, 5:50 p.m.

6.4

CVSS3.1

CVE-2024-11763 - Plezi <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Plezi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'plezi' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…

πŸ“… Published: Dec. 14, 2024, 4:23 a.m. πŸ”„ Last Modified: July 13, 2025, 11:15 a.m.
Total resulsts: 343048
Page 6851 of 34,305
Β« previous page Β» next page
Filters