6.4

CVSS3.1

CVE-2024-12449 - Video Share VOD โ€“ Turnkey Video Site Builder Script <= 2.6.30 - Authenticated (Contributor+) Storedโ€ฆ

The Video Share VOD โ€“ Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_player_html' shortcode in all versions up to, and including, 2.6.30 due to insufficient input sanitization and output escaping on user supplied atโ€ฆ

๐Ÿ“… Published: Dec. 18, 2024, 3:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:17 p.m.

4.3

CVSS3.1

CVE-2024-12596 - LifterLMS โ€“ WP LMS for eLearning, Online Courses, & Quizzes <= 7.8.5 - Missing Authorization to Autโ€ฆ

The LifterLMS โ€“ WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert' action in all versions up to, and including, 7.8.5. This makes it possible for authenticated attackers, with Subsโ€ฆ

๐Ÿ“… Published: Dec. 18, 2024, 3:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:06 p.m.

8.8

CVSS3.1

CVE-2024-12259 - CRM WordPress Plugin โ€“ RepairBuddy <= 3.8120 - Missing Authorization to Account Takeover/Privilege โ€ฆ

The CRM WordPress Plugin โ€“ RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior to updating their email through the wc_update_user_data AJAXโ€ฆ

๐Ÿ“… Published: Dec. 18, 2024, 3:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:03 p.m.

6.1

CVSS3.1

CVE-2024-11254 - AMP for WP โ€“ Accelerated Mobile Pages <= 1.1.1 - Reflected Cross-Site Scripting

The AMP for WP โ€“ Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary webโ€ฆ

๐Ÿ“… Published: Dec. 18, 2024, 3:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:55 p.m.

7.5

CVSS3.1

CVE-2024-12025 - Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection

The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-json/collapsing-categories/v1/get REST API in all versions up to, and including, 3.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparationโ€ฆ

๐Ÿ“… Published: Dec. 18, 2024, 3:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:33 p.m.

8.1

CVSS3.1

CVE-2024-12432 - WPC Shop as a Customer for WooCommerce <= 1.2.8 - Authentication Bypass Due to Insufficiently Uniquโ€ฆ

The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_key' function not producing a sufficiently random value. This makes it possible for authenticated attaโ€ฆ

๐Ÿ“… Published: Dec. 18, 2024, 3:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:33 p.m.

6.4

CVSS3.1

CVE-2024-12513 - Contests by Rewards Fuel <= 2.0.65 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RF_CONTEST' shortcode in all versions up to, and including, 2.0.65 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authโ€ฆ

๐Ÿ“… Published: Dec. 18, 2024, 2:24 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:21 p.m.

6.4

CVSS3.1

CVE-2024-11881 - Easy Waveform Player <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywaveformplayer' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aโ€ฆ

๐Ÿ“… Published: Dec. 18, 2024, 2:24 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:37 p.m.

6.4

CVSS3.1

CVE-2024-12500 - Philantro โ€“ Donations and Donor Management <= 5.2 - Authenticated (Contributor+) Stored Cross-Site โ€ฆ

The Philantro โ€“ Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it โ€ฆ

๐Ÿ“… Published: Dec. 18, 2024, 2:24 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:35 p.m.

6.4

CVSS3.1

CVE-2024-11748 - Taeggie Feed <= 0.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'taeggie-feed' shortcode in all versions up to, and including, 0.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated aโ€ฆ

๐Ÿ“… Published: Dec. 18, 2024, 2:08 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:57 p.m.
Total resulsts: 343926
Page 6902 of 34,393
ยซ previous page ยป next page
Filters