8.1

CVSS3.1

CVE-2024-11721 - Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Privilege Escalation

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.24.5. This is due to insufficient controls on the user role select field when utilizing the 'Role' field in a form. This makes it possible for unauthenticated attackerโ€ฆ

๐Ÿ“… Published: Dec. 14, 2024, 8:26 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:30 p.m.

7.2

CVSS3.1

CVE-2024-11720 - Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Stored Cross-Site Scripting

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms in all versions up to, and including, 3.24.5 due to insufficient input sanitization and output escaping on the new Taxonomy form. This makes it possible for unauthenticated attackโ€ฆ

๐Ÿ“… Published: Dec. 14, 2024, 8:26 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:58 p.m.

5.3

CVSS3.1

CVE-2024-11712 - WP Job Portal <= 2.2.2 - Missing Authorization to Unauthenticated Arbitrary Resume Download

The WP Job Portal โ€“ A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This makes it possible for โ€ฆ

๐Ÿ“… Published: Dec. 14, 2024, 6:45 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:31 p.m.

4.9

CVSS3.1

CVE-2024-11710 - WP Job Portal <= 2.2.2 - Authenticated (Admin+) SQL Injection

The WP Job Portal โ€“ A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'fieldfor', 'visibleParent' and 'id' parameters in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and โ€ฆ

๐Ÿ“… Published: Dec. 14, 2024, 6:45 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:03 p.m.

7.5

CVSS3.1

CVE-2024-11711 - WP Job Portal <= 2.2.1 - Unauthenticated SQL Injection

The WP Job Portal โ€“ A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'resumeid' parameter in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparatโ€ฆ

๐Ÿ“… Published: Dec. 14, 2024, 6:45 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:55 p.m.

4.9

CVSS3.1

CVE-2024-11714 - WP Job Portal <= 2.2.2 - Authenticated (Admin+) SQL Injection via getFieldsForVisibleCombobox()

The WP Job Portal โ€“ A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'ff' parameter of the getFieldsForVisibleCombobox() function in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied pโ€ฆ

๐Ÿ“… Published: Dec. 14, 2024, 6:45 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:52 p.m.

4.9

CVSS3.1

CVE-2024-11713 - WP Job Portal <= 2.2.2 - Authenticated (Admin+) SQL Injection via wpjobportal_deactivate()

The WP Job Portal โ€“ A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'page_id' parameter of the wpjobportal_deactivate() function in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied pโ€ฆ

๐Ÿ“… Published: Dec. 14, 2024, 6:45 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:51 p.m.

4.8

CVSS3.1

CVE-2024-11715 - WP Job Portal <= 2.2.2 - Missing Authorization to Limited Privilege Escalation

The WP Job Portal โ€“ A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the assignUserRole() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attโ€ฆ

๐Ÿ“… Published: Dec. 14, 2024, 6:45 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:48 p.m.

6.4

CVSS3.1

CVE-2024-12446 - Post to Pdf <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Post to Pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gmptp_single_post' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticatedโ€ฆ

๐Ÿ“… Published: Dec. 14, 2024, 6:45 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:42 p.m.

4.4

CVSS3.1

CVE-2024-12628 - bodi0โ€™s Easy Cache <= 0.8 - Authenticated (Admin+) Stored Cross-Site Scripting

The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' parameter in all versions up to, and including, 0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-leveโ€ฆ

๐Ÿ“… Published: Dec. 14, 2024, 6:45 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:34 p.m.
Total resulsts: 343761
Page 6920 of 34,377
ยซ previous page ยป next page
Filters