7.2

CVSS3.1

CVE-2024-11465 - Custom Product Tabs for WooCommerce <= 1.8.5 - Authenticated (Shop Manager+) PHP Object Injection

The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input in the 'yikes_woo_products_tabs' post meta parameter. This makes it possible for authenticated attackers, with Shop Mโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:21 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:38 p.m.

6.1

CVSS3.1

CVE-2024-11434 - WP โ€“ Bulk SMS โ€“ by SMS.to <= 1.0.12 - Reflected Cross-Site Scripting

The WP โ€“ Bulk SMS โ€“ by SMS.to plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitraโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:21 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-11338 - PIXNET Plugin <= 2.9.10 - Authenticated (Subscriber+) Stored Cross-Site Scripting

The PIXNET Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtm' and 'venue' parameters in all versions up to, and including, 2.9.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-levelโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:21 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-12462 - YOGO Booking <= 1.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The YOGO Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yogo-calendar' shortcode in all versions up to, and including, 1.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated โ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:21 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.1

CVSS3.1

CVE-2024-10527 - Spacer <= 3.0.7 - Missing Authorization to Authenticated (Subscriber+) Limited Information Disclosuโ€ฆ

The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the motech_spacer_callback() function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view liโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:21 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-12049 - Woo Ukrposhta <= 1.17.11 - Reflected Cross-Site Scripting via order, post, and idd Parameters

The Woo Ukrposhta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order', 'post', and 'idd' parameters in all versions up to, and including, 1.17.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injeโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:21 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-11383 - CC Canadian Mortgage Calculator <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The CC Canadian Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cc-mortgage-canada' shortcode in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it posโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:21 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-12540 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54288. Reason: This candidate is a reservation duplicate of CVE-2024-54288. Notes: All CVE users should reference CVE-2024-54288 instead of this candidate. All references and descriptions in this candidate have been removed to prevโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 3:22 a.m. ๐Ÿ”„ Last Modified: Jan. 17, 2025, 5:15 p.m.

4.3

CVSS3.1

CVE-2024-12538 - Duplicate Post, Page and Any Custom Post <= 3.5.5 - Authenticated (Contributor+) Post Disclosure viโ€ฆ

The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.5 via the 'dpp_duplicate_as_draft' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to exโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 3:21 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-12022 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-52485. Reason: This candidate is a reservation duplicate of CVE-2024-52485. Notes: All CVE users should reference CVE-2024-52485 instead of this candidate. All references and descriptions in this candidate have been removed to prevโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 3:21 a.m. ๐Ÿ”„ Last Modified: Jan. 17, 2025, 5:15 p.m.
Total resulsts: 349182
Page 7265 of 34,919
ยซ previous page ยป next page
Filters