4.3

CVSS3.1

CVE-2024-11181 - Greenshift – animation and page builder blocks <= 9.9.9.3 - Authenticated (Contributor+) Post Discl…

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 9.9.9.3 via the 'wp_reusable_render' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticate…

πŸ“… Published: Dec. 12, 2024, 6:46 a.m. πŸ”„ Last Modified: April 8, 2026, 4:33 p.m.

6.4

CVSS3.1

CVE-2024-10784 - Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.126 - Authenticated (Cont…

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜Tile Gallery' widget in all versions up to, and including, 1.5.126 due to insufficient input sanitization and output escaping. This makes it possible for…

πŸ“… Published: Dec. 12, 2024, 6:46 a.m. πŸ”„ Last Modified: April 8, 2026, 4:32 p.m.

4.8

CVSS3.1

CVE-2024-9881 - LearnPress < 4.2.7.2 - Admin+ Stored XSS

The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: Dec. 12, 2024, 6 a.m. πŸ”„ Last Modified: May 7, 2025, 12:45 p.m.

4.8

CVSS3.1

CVE-2024-9641 - LuckyWP Table of Contents < 2.1.7 - Admin+ Stored XSS

The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: Dec. 12, 2024, 6 a.m. πŸ”„ Last Modified: May 7, 2025, 1:04 p.m.

4.8

CVSS3.1

CVE-2024-9428 - Popup Builder < 4.3.5 - Admin+ Stored XSS

The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: Dec. 12, 2024, 6 a.m. πŸ”„ Last Modified: May 7, 2025, 1:29 p.m.

5.4

CVSS3.1

CVE-2024-10637 - Kadence Blocks < 3.2.54 - Admin+ Stored XSS

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.54 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting a…

πŸ“… Published: Dec. 12, 2024, 6 a.m. πŸ”„ Last Modified: May 7, 2025, 1:19 p.m.

4.7

CVSS3.1

CVE-2024-10568 - Ajax Search Lite < 4.12.4 - Admin+ Stored XSS

The Ajax Search Lite WordPress plugin before 4.12.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: Dec. 12, 2024, 6 a.m. πŸ”„ Last Modified: May 17, 2025, 2:31 a.m.

4.8

CVSS3.1

CVE-2024-10518 - ProfilePress < 4.15.15 - Admin+ Stored XSS

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Membership Plan settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting …

πŸ“… Published: Dec. 12, 2024, 6 a.m. πŸ”„ Last Modified: May 17, 2025, 2:28 a.m.

4.8

CVSS3.1

CVE-2024-10517 - ProfilePress < 4.15.15 - Admin+ Stored XSS

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Drag & Drop Builder fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scriptin…

πŸ“… Published: Dec. 12, 2024, 6 a.m. πŸ”„ Last Modified: May 17, 2025, 2:28 a.m.

7.2

CVSS3.1

CVE-2024-10499 - AI-Engine < 2.6.5 - Admin+ SQLi

The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perform SQL injection attacks

πŸ“… Published: Dec. 12, 2024, 6 a.m. πŸ”„ Last Modified: May 17, 2025, 2:25 a.m.
Total resulsts: 343923
Page 6978 of 34,393
Β« previous page Β» next page
Filters