6.4
CVE-2024-12449 - Video Share VOD โ Turnkey Video Site Builder Script <= 2.6.30 - Authenticated (Contributor+) Storedโฆ
The Video Share VOD โ Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_player_html' shortcode in all versions up to, and including, 2.6.30 due to insufficient input sanitization and output escaping on user supplied atโฆ
4.3
CVE-2024-12596 - LifterLMS โ WP LMS for eLearning, Online Courses, & Quizzes <= 7.8.5 - Missing Authorization to Autโฆ
The LifterLMS โ WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert' action in all versions up to, and including, 7.8.5. This makes it possible for authenticated attackers, with Subsโฆ
8.8
CVE-2024-12259 - CRM WordPress Plugin โ RepairBuddy <= 3.8120 - Missing Authorization to Account Takeover/Privilege โฆ
The CRM WordPress Plugin โ RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior to updating their email through the wc_update_user_data AJAXโฆ
6.1
CVE-2024-11254 - AMP for WP โ Accelerated Mobile Pages <= 1.1.1 - Reflected Cross-Site Scripting
The AMP for WP โ Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary webโฆ
7.5
CVE-2024-12025 - Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection
The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-json/collapsing-categories/v1/get REST API in all versions up to, and including, 3.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparationโฆ
8.1
CVE-2024-12432 - WPC Shop as a Customer for WooCommerce <= 1.2.8 - Authentication Bypass Due to Insufficiently Uniquโฆ
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_key' function not producing a sufficiently random value. This makes it possible for authenticated attaโฆ
6.4
CVE-2024-12513 - Contests by Rewards Fuel <= 2.0.65 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RF_CONTEST' shortcode in all versions up to, and including, 2.0.65 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authโฆ
6.4
CVE-2024-11881 - Easy Waveform Player <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywaveformplayer' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aโฆ
6.4
CVE-2024-12500 - Philantro โ Donations and Donor Management <= 5.2 - Authenticated (Contributor+) Stored Cross-Site โฆ
The Philantro โ Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it โฆ
6.4
CVE-2024-11748 - Taeggie Feed <= 0.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'taeggie-feed' shortcode in all versions up to, and including, 0.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated aโฆ