6.4

CVSS3.1

CVE-2024-11229 - 코드엠샵 소셜톡 <= 1.1.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via add_plus_friends …

The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's add_plus_friends and add_plus_talk shortcodes in all versions up to, and including, 1.1.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f…

📅 Published: Nov. 23, 2024, 11:39 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-11631 - itsourcecode Tailoring Management System expedit.php sql injection

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /expedit.php. The manipulation of the argument expcat leads to sql injection. The attack may be initiated remotely. The exploit has been discl…

📅 Published: Nov. 23, 2024, 11:31 a.m. 🔄 Last Modified: Nov. 26, 2024, 3:55 p.m.

6.4

CVSS3.1

CVE-2024-11231 - 우커머스 네이버페이 <= 3.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via mnp_purchase Sho…

The 우커머스 네이버페이 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mnp_purchase shortcode in all versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac…

📅 Published: Nov. 23, 2024, 11:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-11034 - Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – P…

The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation plugin for WordPress is vulnerable to arbitrary shortcode execution via fire_contact_form AJAX action in all versions up to, and including, 1.4. This is due to the software al…

📅 Published: Nov. 23, 2024, 11:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-10519 - Wishlist for WooCommerce: Multi Wishlists Per Customer PRO 3.0.8 - 3.1.2 - Reflected Cross-Site Scr…

The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wtab' parameter in versions 3.0.8 to 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

📅 Published: Nov. 23, 2024, 9:39 a.m. 🔄 Last Modified: July 12, 2025, 12:29 a.m.

6.4

CVSS3.1

CVE-2024-11199 - Rescue Shortcodes <= 2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via rescue_prog…

The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rescue_progressbar shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti…

📅 Published: Nov. 23, 2024, 9:39 a.m. 🔄 Last Modified: April 8, 2026, 5:12 p.m.

6.4

CVSS3.1

CVE-2024-11227 - Memberlite Shortcodes <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via membe…

The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's memberlite_accordion shortcode in all versions up to, and including, 1.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for …

📅 Published: Nov. 23, 2024, 9:39 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-9659 - School Management <= 91.5.0 - Unauthenticated Arbitrary File Upload

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function in all versions up to, and including, 91.5.0. This makes it possible for unauthenticated attackers to upload…

📅 Published: Nov. 23, 2024, 7:38 a.m. 🔄 Last Modified: April 8, 2026, 5:35 p.m.

8.8

CVSS3.1

CVE-2024-9941 - WPGYM <= 67.1.0 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for authenticated attackers, with subscriber-level…

📅 Published: Nov. 23, 2024, 7:38 a.m. 🔄 Last Modified: April 8, 2026, 5:23 p.m.

9.8

CVSS3.1

CVE-2024-9942 - WPGYM <= 67.1.0 - Unauthenticated Arbitrary File Upload

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible for unauthenticated attackers to uploa…

📅 Published: Nov. 23, 2024, 7:38 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.
Total resulsts: 346616
Page 7460 of 34,662
« previous page » next page
Filters