8.1

CVSS3.1

CVE-2024-56291 - WordPress PlainInventory – Inventory Management Plugin Plugin <= 3.1.6 - PHP Object Injection vulne…

Deserialization of Untrusted Data vulnerability in plainware PlainInventory z-inventory-manager allows Object Injection.This issue affects PlainInventory: from n/a through <= 3.1.6.

πŸ“… Published: Jan. 7, 2025, 10:49 a.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

5.9

CVSS3.1

CVE-2024-56292 - WordPress Email Reminders Plugin <= 2.0.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Email Reminders email-reminders allows Stored XSS.This issue affects Email Reminders: from n/a through <= 2.0.5.

πŸ“… Published: Jan. 7, 2025, 10:49 a.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

5.9

CVSS3.1

CVE-2024-56293 - WordPress AFI – The Easiest Integration Plugin <= 1.95.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nasir Ahmed Advanced Form Integration advanced-form-integration allows Stored XSS.This issue affects Advanced Form Integration: from n/a through <= 1.95.0.

πŸ“… Published: Jan. 7, 2025, 10:49 a.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

6.4

CVSS3.1

CVE-2024-56294 - WordPress Nexter Blocks plugin <= 4.0.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nexter Blocks: from n/a through <= 4.0.7.

πŸ“… Published: Jan. 7, 2025, 10:49 a.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

7.1

CVSS3.1

CVE-2024-56296 - WordPress Mang Board WP plugin <= 1.8.4 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kitae Park Mang Board WP mangboard allows Reflected XSS.This issue affects Mang Board WP: from n/a through <= 1.8.4.

πŸ“… Published: Jan. 7, 2025, 10:49 a.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

5.9

CVSS3.1

CVE-2024-56297 - WordPress Highlight plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Highlight highlight allows Stored XSS.This issue affects Highlight: from n/a through <= 2.0.2.

πŸ“… Published: Jan. 7, 2025, 10:49 a.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

5.9

CVSS3.1

CVE-2024-56298 - WordPress Pretty Simple Popup Builder Plugin <= 1.0.9 - Stored Cross Site Scripting (XSS) vulnerabi…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob @ 5 Star Plugins Pretty Simple Popup Builder pretty-simple-popup-builder allows Stored XSS.This issue affects Pretty Simple Popup Builder: from n/a through <= 1.0.9.

πŸ“… Published: Jan. 7, 2025, 10:49 a.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

7.1

CVSS3.1

CVE-2024-56299 - WordPress Notify Odoo plugin <= 1.0.0 - CSRF to Stored XSS vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pektsekye Notify Odoo notify-odoo allows Stored XSS.This issue affects Notify Odoo: from n/a through <= 1.0.0.

πŸ“… Published: Jan. 7, 2025, 10:49 a.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

7.5

CVSS3.1

CVE-2024-56300 - WordPress Post/Page Copying Tool plugin <= 2.0.0 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in wpspin Post/Page Copying Tool postpage-import-export-with-custom-fields-taxonomies allows Retrieve Embedded Sensitive Data.This issue affects Post/Page Copying Tool: from n/a through <= 2.0.0.

πŸ“… Published: Jan. 7, 2025, 10:49 a.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

6.5

CVSS3.1

CVE-2025-22261 - WordPress WP FullCalendar plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Stored XSS.This issue affects WP FullCalendar: from n/a through <= 1.5.

πŸ“… Published: Jan. 7, 2025, 10:49 a.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.
Total resulsts: 349182
Page 7251 of 34,919
Β« previous page Β» next page
Filters