6.1

CVSS3.1

CVE-2024-12258 - WP Service Payment Form With Authorize.net <= 2.6.3 - Reflected Cross-Site Scripting

The WP Service Payment Form With Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 5:33 p.m.

6.1

CVSS3.1

CVE-2024-12260 - Ultimate Endpoints With Rest Api <= 2.2.2 - Reflected Cross-Site Scripting

The Ultimate Endpoints With Rest Api plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 5:32 p.m.

6.1

CVSS3.1

CVE-2024-12338 - Website Toolbox Community <= 2.0.1 - Reflected Cross-Site Scripting via websitetoolbox_username

The Website Toolbox Community plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘websitetoolbox_username’ parameter in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.

8.1

CVSS3.1

CVE-2024-10111 - OAuth Single Sign On – SSO (OAuth Client) <= 6.26.3 - Authentication Bypass

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.26.3. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.

6.4

CVSS3.1

CVE-2024-11901 - PowerBI Embed Reports <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

The PowerBI Embed Reports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MO_API_POWER_BI' shortcode in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.

6.1

CVSS3.1

CVE-2024-11417 - dejure.org Vernetzungsfunktion <= 1.97.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The dejure.org Vernetzungsfunktion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.97.5. This is due to missing or incorrect nonce validation on the djo_einstellungen_menue() function. This makes it possible for unauthenticated attackers to u…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.

9.8

CVSS3.1

CVE-2024-11015 - Sign In With Google <= 1.8.0 - Authentication Bypass in authenticate_user

The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.8.0. This is due to the 'authenticate_user' user function not implementing sufficient null value checks when setting the access token and user information. This makes it possi…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 5:15 p.m.

8.8

CVSS3.1

CVE-2024-11443 - de:branding <= 1.0.2 - Authenticated (Subscriber+) Arbitrary Options Update

The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the debranding_save() function in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with sub…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 5:13 p.m.

6.1

CVSS3.1

CVE-2024-11419 - Password for WP <= 1.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the get3_init_admin_page() function. This makes it possible for unauthenticated attackers to update settings and in…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-12461 - WP-Revive Adserver <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP-Revive Adserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprevive_async' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 4:57 p.m.
Total resulsts: 343935
Page 6984 of 34,394
« previous page » next page
Filters