6.4

CVSS3.1

CVE-2024-10185 - StreamWeasels YouTube Integration <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scriptiโ€ฆ

The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-youtube-embed shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possiโ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, 11:01 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:48 p.m.

6.4

CVSS3.1

CVE-2024-10184 - SW Kick Integration - Blocks and Shortcodes for Embedding Kick Streams <= 1.1.1 - Authenticated (Coโ€ฆ

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-kick-embed shortcode in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible foโ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, 11:01 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:33 p.m.

5.4

CVSS3.1

CVE-2024-49679 - WordPress WPKoi Templates for Elementor plugin <= 3.1.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpkoithemes WPKoi Templates for Elementor wpkoi-templates-for-elementor allows Stored XSS.This issue affects WPKoi Templates for Elementor: from n/a through <= 3.1.0.

๐Ÿ“… Published: Oct. 29, 2024, 10:58 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 4:18 p.m.

5.4

CVSS3.1

CVE-2024-49692 - WordPress AffiliateX plugin <= 1.2.9 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCenter AffiliateX affiliatex allows Stored XSS.This issue affects AffiliateX: from n/a through <= 1.2.9.

๐Ÿ“… Published: Oct. 29, 2024, 10:57 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 4:18 p.m.

6.1

CVSS3.1

CVE-2024-50407 - WordPress Namaste! LMS plugin <= 2.6.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Namaste! LMS namaste-lms allows Reflected XSS.This issue affects Namaste! LMS: from n/a through <= 2.6.2.

๐Ÿ“… Published: Oct. 29, 2024, 10:56 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 4:19 p.m.

5.4

CVSS3.1

CVE-2024-50409 - WordPress Namaste! LMS plugin <= 2.6.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Namaste! LMS namaste-lms allows Stored XSS.This issue affects Namaste! LMS: from n/a through <= 2.6.2.

๐Ÿ“… Published: Oct. 29, 2024, 10:19 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 4:19 p.m.

5.4

CVSS3.1

CVE-2024-50410 - WordPress Namaste! LMS plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Namaste! LMS namaste-lms allows Stored XSS.This issue affects Namaste! LMS: from n/a through <= 2.6.4.

๐Ÿ“… Published: Oct. 29, 2024, 10:18 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 4:19 p.m.

9.8

CVSS3.1

CVE-2024-50550 - WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through <= 6.5.1.

๐Ÿ“… Published: Oct. 29, 2024, 9:57 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 4:19 p.m.

6.4

CVSS3.1

CVE-2024-10227 - affiliate-toolkit <= 3.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via atkp_prodโ€ฆ

The affiliate-toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atkp_product shortcode in all versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticateโ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, 9:31 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:03 p.m.

4.3

CVSS3.1

CVE-2024-10437 - WPC Smart Messages for WooCommerce <= 4.2.1 - Missing Authorization to Authenticated (Subscriber+) โ€ฆ

The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to unauthorized Smar Message activation/deactivation due to a missing capability check on the ajax_enable function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Subscribโ€ฆ

๐Ÿ“… Published: Oct. 29, 2024, 9:31 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:50 p.m.
Total resulsts: 343932
Page 7577 of 34,394
ยซ previous page ยป next page
Filters