6.1

CVSS3.1

CVE-2024-11331 - isee-products-extractor <= 2.1.3 - Reflected Cross-Site Scripting

The استخراج محصولات ووکامرس برای آیسی plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.3. This makes it possible for unauthenticated attackers to …

📅 Published: Dec. 20, 2024, 6:59 a.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.

6.4

CVSS3.1

CVE-2024-11784 - Sell Tickets Online – TicketSource Ticket Shop for WordPress <= 3.0.2 - Authenticated (Contributor+…

The Sell Tickets Online – TicketSource Ticket Shop for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ticketshop' shortcode in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping on user supplied attribut…

📅 Published: Dec. 20, 2024, 6:59 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-9619 - WP SHAPES <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The WP SHAPES plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inj…

📅 Published: Dec. 20, 2024, 6:59 a.m. 🔄 Last Modified: July 12, 2025, 11:06 p.m.

5.3

CVSS3.1

CVE-2024-11297 - Page Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.6 - Unauthenticated Content Restrict…

The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.6 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from pos…

📅 Published: Dec. 20, 2024, 6:59 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-12509 - Embed Twine <= 0.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Embed Twine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed_twine' shortcode in all versions up to, and including, 0.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

📅 Published: Dec. 20, 2024, 6:59 a.m. 🔄 Last Modified: April 8, 2026, 4:57 p.m.

6.1

CVSS3.1

CVE-2024-11812 - Wtyczka SeoPilot dla WP <= 3.3.091 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Wtyczka SeoPilot dla WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.091. This is due to missing or incorrect nonce validation on the SeoPilot_Admin_Options() function. This makes it possible for unauthenticated attackers to update s…

📅 Published: Dec. 20, 2024, 6:59 a.m. 🔄 Last Modified: April 8, 2026, 4:56 p.m.

9.8

CVSS3.1

CVE-2024-12571 - Store Locator <= 3.98.10 - Unauthenticated Local File Inclusion

The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the 'sl_engine' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execut…

📅 Published: Dec. 20, 2024, 6:59 a.m. 🔄 Last Modified: Dec. 20, 2024, 4:03 p.m.

6.4

CVSS3.1

CVE-2024-11411 - Spotlightr <= 0.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Spotlightr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotlightr-v' shortcode in all versions up to, and including, 0.1.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at…

📅 Published: Dec. 20, 2024, 6:59 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-11775 - Particle Background <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Particle Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'particleground' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen…

📅 Published: Dec. 20, 2024, 6:59 a.m. 🔄 Last Modified: April 8, 2026, 4:48 p.m.

4.3

CVSS3.1

CVE-2024-9503 - Maintenance & Coming Soon Redirect Animation <= 2.1.3 - Missing Authorization to Settings Update

The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wploti_add_whitelisted_roles_option', 'wploti_remove_whitelisted_roles_option', 'wploti_add_whitelisted_users_option', 'wploti_remove_w…

📅 Published: Dec. 20, 2024, 6:59 a.m. 🔄 Last Modified: April 8, 2026, 5:19 p.m.
Total resulsts: 343948
Page 6879 of 34,395
« previous page » next page
Filters