6.3

CVSS3.1

CVE-2025-0939 - MagicForm - WordPress Form Builder <= 1.6.2 - Missing Authorization

The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke those…

πŸ“… Published: Feb. 1, 2025, 6:41 a.m. πŸ”„ Last Modified: April 21, 2026, 10:30 p.m.

6.5

CVSS3.1

CVE-2024-13341 - MultiLoca - WooCommerce Multi Locations Inventory Management <= 4.1.11 - Authenticated (Subscriber+…

The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via the 'data-id' parameter in all versions up to, and including, 4.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existin…

πŸ“… Published: Feb. 1, 2025, 6:41 a.m. πŸ”„ Last Modified: April 8, 2026, 5:05 p.m.

5.4

CVSS3.1

CVE-2024-13099 - Widget4call <= 1.0.7 - Reflected XSS

The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“… Published: Feb. 1, 2025, 6 a.m. πŸ”„ Last Modified: May 7, 2025, 6:37 p.m.

5.4

CVSS3.1

CVE-2024-13098 - WP Email Newsletter <= 1.1 - Reflected XSS

The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“… Published: Feb. 1, 2025, 6 a.m. πŸ”„ Last Modified: May 7, 2025, 7:15 p.m.

5.4

CVSS3.1

CVE-2024-13097 - WP Finance <= 1.3.6 - Reflected XSS

The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“… Published: Feb. 1, 2025, 6 a.m. πŸ”„ Last Modified: May 12, 2025, 12:56 a.m.

4.6

CVSS3.1

CVE-2024-13096 - WP Finance <= 1.3.6 - Stored XSS via CSRF

The WP Finance WordPress plugin through 1.3.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

πŸ“… Published: Feb. 1, 2025, 6 a.m. πŸ”„ Last Modified: May 12, 2025, 1:01 a.m.

5.4

CVSS3.1

CVE-2024-12768 - Responsive iframe <= 1.2.0 - Contributor+ Stored XSS

The Responsive iframe WordPress plugin through 1.2.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

πŸ“… Published: Feb. 1, 2025, 6 a.m. πŸ”„ Last Modified: May 12, 2025, 1:04 a.m.

6.5

CVSS3.1

CVE-2025-0365 - Jupiterx Core <= 4.8.7 - Authenticated (Contributor+) Arbitrary File Read

The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7 via the inline SVG feature. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, wh…

πŸ“… Published: Feb. 1, 2025, 5:30 a.m. πŸ”„ Last Modified: April 21, 2026, 10:30 p.m.

8.8

CVSS3.1

CVE-2025-0366 - Jupiter X Core <= 4.8.7 - Authenticated (Contributor+) SVG Upload to Local File Inclusion (Remote C…

The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_svg() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrar…

πŸ“… Published: Feb. 1, 2025, 5:30 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

5.3

CVSS3.1

CVE-2024-12041 - Directorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12…

The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers …

πŸ“… Published: Feb. 1, 2025, 5:30 a.m. πŸ”„ Last Modified: April 8, 2026, 4:35 p.m.
Total resulsts: 349182
Page 6883 of 34,919
Β« previous page Β» next page
Filters