8.1

CVSS3.1

CVE-2024-10111 - OAuth Single Sign On – SSO (OAuth Client) <= 6.26.3 - Authentication Bypass

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.26.3. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 8, 2026, 7:19 p.m.

6.4

CVSS3.1

CVE-2024-11901 - PowerBI Embed Reports <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

The PowerBI Embed Reports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MO_API_POWER_BI' shortcode in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 8, 2026, 7:19 p.m.

6.1

CVSS3.1

CVE-2024-11417 - dejure.org Vernetzungsfunktion <= 1.97.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The dejure.org Vernetzungsfunktion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.97.5. This is due to missing or incorrect nonce validation on the djo_einstellungen_menue() function. This makes it possible for unauthenticated attackers to u…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 8, 2026, 7:19 p.m.

9.8

CVSS3.1

CVE-2024-11015 - Sign In With Google <= 1.8.0 - Authentication Bypass in authenticate_user

The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.8.0. This is due to the 'authenticate_user' user function not implementing sufficient null value checks when setting the access token and user information. This makes it possi…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 8, 2026, 5:15 p.m.

8.8

CVSS3.1

CVE-2024-11443 - de:branding <= 1.0.2 - Authenticated (Subscriber+) Arbitrary Options Update

The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the debranding_save() function in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with sub…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 8, 2026, 5:13 p.m.

6.1

CVSS3.1

CVE-2024-11419 - Password for WP <= 1.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the get3_init_admin_page() function. This makes it possible for unauthenticated attackers to update settings and in…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-12461 - WP-Revive Adserver <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP-Revive Adserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprevive_async' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 8, 2026, 4:57 p.m.

6.4

CVSS3.1

CVE-2024-11433 - Surbma | SalesAutopilot Shortcode <= 2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Surbma | SalesAutopilot Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sa-form' shortcode in all versions up to, and including, 2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-11914 - Gutenberg Blocks and Page Layouts – Attire Blocks <= 1.9.5 - Authenticated (Contributor+) Stored Cr…

The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attire-blocks/post-carousel' block in all versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for auth…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-11427 - Catch Popup <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Catch Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catch-popup' shortcode in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 8, 2026, 4:50 p.m.
Total resulsts: 343942
Page 6985 of 34,395
Β« previous page Β» next page
Filters